From a2a152747e6486b9a4e5003bacdb2f7feeae6347 Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Tue, 1 Feb 2022 06:05:02 +0000 Subject: [PATCH 1/2] chore(deps): update dependency aquasecurity/trivy to v0.23.0 --- container-scan.gitlab-ci.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/container-scan.gitlab-ci.yml b/container-scan.gitlab-ci.yml index b7cb198..0b3c380 100644 --- a/container-scan.gitlab-ci.yml +++ b/container-scan.gitlab-ci.yml @@ -2,7 +2,7 @@ image: $MAVEN_IMAGE stage: test variables: - TRIVY_VERSION: 0.22.0 + TRIVY_VERSION: 0.23.0 EXITCODE: 1 TRIVY_EXTRA_ARGS: "--no-progress --ignore-unfixed" before_script: @@ -23,7 +23,7 @@ image: $GRADLE_IMAGE stage: test variables: - TRIVY_VERSION: 0.22.0 + TRIVY_VERSION: 0.23.0 EXITCODE: 1 PROJECT_DIR: $CI_PROJECT_DIR/build TRIVY_EXTRA_ARGS: "--no-progress --ignore-unfixed" @@ -48,7 +48,7 @@ name: gcr.io/kaniko-project/executor:debug entrypoint: [ "" ] variables: - TRIVY_VERSION: 0.22.0 + TRIVY_VERSION: 0.23.0 PROJECT_DIR: $CI_PROJECT_DIR DOCKERFILE_LOCATION: $CI_PROJECT_DIR/Dockerfile CONTEXT_LOCATION: $CI_PROJECT_DIR From 1c7b10e1091a6b70355d4fa107f31f40d214bffa Mon Sep 17 00:00:00 2001 From: Marcel Feix Date: Fri, 4 Feb 2022 14:20:08 +0100 Subject: [PATCH 2/2] chore(Image Scann): correction on scanning with trivy. --- container-scan.gitlab-ci.yml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/container-scan.gitlab-ci.yml b/container-scan.gitlab-ci.yml index 0b3c380..f4738ee 100644 --- a/container-scan.gitlab-ci.yml +++ b/container-scan.gitlab-ci.yml @@ -10,8 +10,8 @@ - tar zxvf trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz script: - mvn $MAVEN_CLI_OPTS compile jib:buildTar -DskipTests - - ./trivy --timeout 15m --cache-dir .trivycache/ $TRIVY_EXTRA_ARGS --exit-code 0 --cache-dir .trivycache/ --severity HIGH,CRITICAL --no-progress --format template --template "@contrib/junit.tpl" -o junit-report.xml --input target/jib-image.tar - - ./trivy --timeout 15m --cache-dir .trivycache/ $TRIVY_EXTRA_ARGS --exit-code $EXITCODE --cache-dir .trivycache/ --severity HIGH,CRITICAL --no-progress --input target/jib-image.tar + - ./trivy --cache-dir .trivycache/ image --timeout 15m $TRIVY_EXTRA_ARGS --exit-code 0 --severity HIGH,CRITICAL --format template --template "@contrib/junit.tpl" -o junit-report.xml --input target/jib-image.tar + - ./trivy --cache-dir .trivycache/ image --timeout 15m $TRIVY_EXTRA_ARGS --exit-code $EXITCODE --severity HIGH,CRITICAL --input target/jib-image.tar cache: paths: - .trivycache/ @@ -33,8 +33,8 @@ - tar zxvf trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz script: - ./gradlew jibBuildTar -DskipTests - - ./trivy --timeout 15m --cache-dir .trivycache/ $TRIVY_EXTRA_ARGS --exit-code 0 --cache-dir .trivycache/ --severity HIGH,CRITICAL --no-progress --format template --template "@contrib/junit.tpl" -o junit-report.xml --input $PROJECT_DIR/jib-image.tar - - ./trivy --timeout 15m --cache-dir .trivycache/ $TRIVY_EXTRA_ARGS --exit-code $EXITCODE --cache-dir .trivycache/ --severity HIGH,CRITICAL --no-progress --input $PROJECT_DIR/jib-image.tar + - ./trivy --cache-dir .trivycache/ image --timeout 15m $TRIVY_EXTRA_ARGS --exit-code 0 --severity HIGH,CRITICAL --format template --template "@contrib/junit.tpl" -o junit-report.xml --input $PROJECT_DIR/jib-image.tar + - ./trivy --cache-dir .trivycache/ image --timeout 15m $TRIVY_EXTRA_ARGS --exit-code $EXITCODE --severity HIGH,CRITICAL --input $PROJECT_DIR/jib-image.tar cache: paths: - .trivycache/ @@ -59,8 +59,8 @@ - tar zxvf trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz script: - /kaniko/executor --context $CONTEXT_LOCATION --dockerfile $DOCKERFILE_LOCATION --cache-dir cache/image --tarPath image.tar --no-push --destination image --skip-tls-verify - - ./trivy --timeout 15m --cache-dir .trivycache/ $TRIVY_EXTRA_ARGS --exit-code 0 --cache-dir .trivycache/ --severity HIGH,CRITICAL --format template --template "@contrib/junit.tpl" -o junit-report.xml --input image.tar - - ./trivy --timeout 15m --cache-dir .trivycache/ $TRIVY_EXTRA_ARGS --exit-code $EXITCODE --cache-dir .trivycache/ --severity HIGH,CRITICAL --input image.tar + - ./trivy --cache-dir .trivycache/ image --timeout 15m $TRIVY_EXTRA_ARGS --exit-code 0 --severity HIGH,CRITICAL --format template --template "@contrib/junit.tpl" -o junit-report.xml --input image.tar + - ./trivy --cache-dir .trivycache/ image --timeout 15m $TRIVY_EXTRA_ARGS --exit-code $EXITCODE --severity HIGH,CRITICAL --input image.tar cache: paths: - .trivycache/