## Summary
Add an officially supported
FIPS-compliant
container image variant for
twistlock-job-runner
used by Harness STO, so regulated environments can run Prisma/Twistlock scans while meeting compliance requirements.
## Problem / Why it matters
Many organizations operating under
FIPS compliance
cannot use non-FIPS images in CI/CD scanning workflows. Today, the lack of a supported FIPS-compliant
twistlock-job-runner
blocks adoption of STO in regulated environments and prevents upgrades to newer runner versions required for feature improvements and accuracy parity.
## Desired outcome
* A
supported FIPS-compliant
twistlock-job-runner
image (or equivalent) is published and maintained.
* Clear documentation on:
* Supported tags/versions
* How to enable/use the FIPS image in STO pipelines
* Compatibility notes and support policy
Created by Pedro Mastelaro
·