Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b43daad0c3 | ||
|
|
dedfa59531 | ||
|
|
f96f79aa22 | ||
|
|
82ec0dd604 | ||
|
|
e5f43133f6 | ||
|
|
1a09192c0e | ||
|
|
1f0aa582c8 | ||
|
|
43849adf01 | ||
|
|
8bd2f9fbda | ||
|
|
cff3e9a7f6 | ||
|
|
ab15891596 | ||
|
|
cacfd7a243 | ||
|
|
1e0bef4613 | ||
|
|
9ab158e859 | ||
|
|
e55de85bee | ||
|
|
d63413b0a4 | ||
|
|
1db49f5326 | ||
|
|
12814ff8bc | ||
|
|
cb606dfdb0 | ||
|
|
0d7cf2ddfb | ||
|
|
5144f05a8d | ||
|
|
81b9a6f5ab | ||
|
|
503d3abc15 | ||
|
|
0105373003 | ||
|
|
bc615ae2d7 | ||
|
|
7b7aa264d8 | ||
|
|
63b6e4c61b | ||
|
|
49e970d7ac | ||
|
|
c666240787 | ||
|
|
e27605859b | ||
|
|
2b22459068 | ||
|
|
4b3b5f928b | ||
|
|
1a53202fc4 | ||
|
|
df3fb7d00b | ||
|
|
987beb8186 | ||
|
|
4b9b6fb4ef | ||
|
|
2b30463ddb | ||
|
|
d7a51817e8 | ||
|
|
9fbcc91008 | ||
|
|
40c4ca9e74 | ||
|
|
f39d29766a | ||
|
|
296212627a |
@@ -0,0 +1,28 @@
|
|||||||
|
name: "build"
|
||||||
|
on: [push, pull_request]
|
||||||
|
env:
|
||||||
|
TRIVY_VERSION: 0.42.0
|
||||||
|
BATS_LIB_PATH: '/usr/lib/'
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
name: build
|
||||||
|
runs-on: ubuntu-20.04
|
||||||
|
steps:
|
||||||
|
|
||||||
|
- name: Setup BATS
|
||||||
|
uses: mig4/setup-bats@v1
|
||||||
|
with:
|
||||||
|
bats-version: 1.7.0
|
||||||
|
|
||||||
|
- name: Setup Bats libs
|
||||||
|
uses: brokenpip3/setup-bats-libs@0.1.0
|
||||||
|
|
||||||
|
- name: Check out code
|
||||||
|
uses: actions/checkout@v1
|
||||||
|
|
||||||
|
- name: Install Trivy
|
||||||
|
run: |
|
||||||
|
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin v${{ env.TRIVY_VERSION }}
|
||||||
|
|
||||||
|
- name: Test
|
||||||
|
run: BATS_LIB_PATH=${{ env.BATS_LIB_PATH }} bats --recursive --timing .
|
||||||
@@ -1 +1,5 @@
|
|||||||
.idea/
|
.idea/
|
||||||
|
*.test
|
||||||
|
!test/data/*.test
|
||||||
|
trivyignores
|
||||||
|
.vscode/
|
||||||
+2
-2
@@ -1,5 +1,5 @@
|
|||||||
FROM aquasec/trivy:0.23.0
|
FROM ghcr.io/aquasecurity/trivy:0.42.0
|
||||||
COPY entrypoint.sh /
|
COPY entrypoint.sh /
|
||||||
RUN apk --no-cache add bash
|
RUN apk --no-cache add bash curl npm
|
||||||
RUN chmod +x /entrypoint.sh
|
RUN chmod +x /entrypoint.sh
|
||||||
ENTRYPOINT ["/entrypoint.sh"]
|
ENTRYPOINT ["/entrypoint.sh"]
|
||||||
|
|||||||
@@ -19,7 +19,7 @@
|
|||||||
|
|
||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
### Workflow
|
### Scan CI Pipeline
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
name: build
|
name: build
|
||||||
@@ -31,15 +31,13 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
- name: Build an image from Dockerfile
|
- name: Build an image from Dockerfile
|
||||||
run: |
|
run: |
|
||||||
docker build -t docker.io/my-organization/my-app:${{ github.sha }} .
|
docker build -t docker.io/my-organization/my-app:${{ github.sha }} .
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner
|
- name: Run Trivy vulnerability scanner
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
@@ -51,6 +49,78 @@ jobs:
|
|||||||
severity: 'CRITICAL,HIGH'
|
severity: 'CRITICAL,HIGH'
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Scan CI Pipeline (w/ Trivy Config)
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name: build
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
pull_request:
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
name: Build
|
||||||
|
runs-on: ubuntu-20.04
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- name: Run Trivy vulnerability scanner in fs mode
|
||||||
|
uses: aquasecurity/trivy-action@master
|
||||||
|
with:
|
||||||
|
scan-type: 'fs'
|
||||||
|
scan-ref: '.'
|
||||||
|
trivy-config: trivy.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
In this case `trivy.yaml` is a YAML configuration that is checked in as part of the repo. Detailed information is available on the Trivy website but an example is as follows:
|
||||||
|
```yaml
|
||||||
|
format: json
|
||||||
|
exit-code: 1
|
||||||
|
severity: CRITICAL
|
||||||
|
```
|
||||||
|
|
||||||
|
It is possible to define all options in the `trivy.yaml` file. Specifying individual options via the action are left for backward compatibility purposes. Defining the following is required as they cannot be defined with the config file:
|
||||||
|
- `scan-ref`: If using `fs, repo` scans.
|
||||||
|
- `image-ref`: If using `image` scan.
|
||||||
|
- `scan-type`: To define the scan type, e.g. `image`, `fs`, `repo`, etc.
|
||||||
|
|
||||||
|
#### Order of prerference for options
|
||||||
|
Trivy uses [Viper](https://github.com/spf13/viper) which has a defined precedence order for options. The order is as follows:
|
||||||
|
- GitHub Action flag
|
||||||
|
- Environment variable
|
||||||
|
- Config file
|
||||||
|
- Default
|
||||||
|
|
||||||
|
### Scanning a Tarball
|
||||||
|
```yaml
|
||||||
|
name: build
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
pull_request:
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
name: Build
|
||||||
|
runs-on: ubuntu-20.04
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- name: Generate tarball from image
|
||||||
|
run: |
|
||||||
|
docker pull <your-docker-image>
|
||||||
|
docker save -o vuln-image.tar <your-docker-image>
|
||||||
|
|
||||||
|
- name: Run Trivy vulnerability scanner in tarball mode
|
||||||
|
uses: aquasecurity/trivy-action@master
|
||||||
|
with:
|
||||||
|
input: /github/workspace/vuln-image.tar
|
||||||
|
severity: 'CRITICAL,HIGH'
|
||||||
|
```
|
||||||
|
|
||||||
### Using Trivy with GitHub Code Scanning
|
### Using Trivy with GitHub Code Scanning
|
||||||
If you have [GitHub code scanning](https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/about-code-scanning) available you can use Trivy as a scanning tool as follows:
|
If you have [GitHub code scanning](https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/about-code-scanning) available you can use Trivy as a scanning tool as follows:
|
||||||
```yaml
|
```yaml
|
||||||
@@ -63,10 +133,10 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Build an image from Dockerfile
|
- name: Build an image from Dockerfile
|
||||||
run: |
|
run: |
|
||||||
@@ -80,7 +150,7 @@ jobs:
|
|||||||
output: 'trivy-results.sarif'
|
output: 'trivy-results.sarif'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
@@ -98,10 +168,10 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Build an image from Dockerfile
|
- name: Build an image from Dockerfile
|
||||||
run: |
|
run: |
|
||||||
@@ -115,8 +185,8 @@ jobs:
|
|||||||
output: 'trivy-results.sarif'
|
output: 'trivy-results.sarif'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
if: always()
|
if: always()
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
@@ -137,10 +207,10 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner in repo mode
|
- name: Run Trivy vulnerability scanner in repo mode
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: aquasecurity/trivy-action@master
|
||||||
@@ -152,7 +222,7 @@ jobs:
|
|||||||
severity: 'CRITICAL'
|
severity: 'CRITICAL'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
@@ -171,10 +241,10 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner with rootfs command
|
- name: Run Trivy vulnerability scanner with rootfs command
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: aquasecurity/trivy-action@master
|
||||||
@@ -187,12 +257,12 @@ jobs:
|
|||||||
severity: 'CRITICAL'
|
severity: 'CRITICAL'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
|
|
||||||
### Using Trivy to scan Infrastucture as Code
|
### Using Trivy to scan Infrastructure as Code
|
||||||
It's also possible to scan your IaC repos with Trivy's built-in repo scan. This can be handy if you want to run Trivy as a build time check on each PR that gets opened in your repo. This helps you identify potential vulnerablites that might get introduced with each PR.
|
It's also possible to scan your IaC repos with Trivy's built-in repo scan. This can be handy if you want to run Trivy as a build time check on each PR that gets opened in your repo. This helps you identify potential vulnerablites that might get introduced with each PR.
|
||||||
|
|
||||||
If you have [GitHub code scanning](https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/about-code-scanning) available you can use Trivy as a scanning tool as follows:
|
If you have [GitHub code scanning](https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/about-code-scanning) available you can use Trivy as a scanning tool as follows:
|
||||||
@@ -206,27 +276,65 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner in IaC mode
|
- name: Run Trivy vulnerability scanner in IaC mode
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
scan-type: 'config'
|
scan-type: 'config'
|
||||||
hide-progress: false
|
hide-progress: false
|
||||||
format: 'table'
|
format: 'sarif'
|
||||||
|
output: 'trivy-results.sarif'
|
||||||
exit-code: '1'
|
exit-code: '1'
|
||||||
ignore-unfixed: true
|
ignore-unfixed: true
|
||||||
severity: 'CRITICAL,HIGH'
|
severity: 'CRITICAL,HIGH'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Using Trivy to generate SBOM
|
||||||
|
It's possible for Trivy to generate an [SBOM](https://www.aquasec.com/cloud-native-academy/supply-chain-security/sbom/) of your dependencies and submit them to a consumer like [GitHub Dependency Graph](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph).
|
||||||
|
|
||||||
|
The [sending of an SBOM to GitHub](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/using-the-dependency-submission-api) feature is only available if you currently have GitHub Dependency Graph [enabled in your repo](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/configuring-the-dependency-graph#enabling-and-disabling-the-dependency-graph-for-a-private-repository).
|
||||||
|
|
||||||
|
In order to send results to GitHub Dependency Graph, you will need to create a [GitHub PAT](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/creating-a-personal-access-token) or use the [GitHub installation access token](https://docs.github.com/en/actions/security-guides/automatic-token-authentication) (also known as `GITHUB_TOKEN`):
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
name: Pull Request
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
|
||||||
|
## GITHUB_TOKEN authentication, add only if you're not going to use a PAT
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
name: Checks
|
||||||
|
runs-on: ubuntu-20.04
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- name: Run Trivy in GitHub SBOM mode and submit results to Dependency Graph
|
||||||
|
uses: aquasecurity/trivy-action@master
|
||||||
|
with:
|
||||||
|
scan-type: 'fs'
|
||||||
|
format: 'github'
|
||||||
|
output: 'dependency-results.sbom.json'
|
||||||
|
image-ref: '.'
|
||||||
|
github-pat: ${{ secrets.GITHUB_TOKEN }} # or ${{ secrets.github_pat_name }} if you're using a PAT
|
||||||
|
```
|
||||||
|
|
||||||
### Using Trivy to scan your private registry
|
### Using Trivy to scan your private registry
|
||||||
It's also possible to scan your private registry with Trivy's built-in image scan. All you have to do is set ENV vars.
|
It's also possible to scan your private registry with Trivy's built-in image scan. All you have to do is set ENV vars.
|
||||||
|
|
||||||
@@ -243,11 +351,11 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner
|
- name: Run Trivy vulnerability scanner
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
@@ -256,10 +364,10 @@ jobs:
|
|||||||
output: 'trivy-results.sarif'
|
output: 'trivy-results.sarif'
|
||||||
env:
|
env:
|
||||||
TRIVY_USERNAME: Username
|
TRIVY_USERNAME: Username
|
||||||
TRIVY_PASSWORD: Password
|
TRIVY_PASSWORD: Password
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
@@ -279,11 +387,11 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner
|
- name: Run Trivy vulnerability scanner
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
@@ -296,7 +404,7 @@ jobs:
|
|||||||
AWS_DEFAULT_REGION: us-west-2
|
AWS_DEFAULT_REGION: us-west-2
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
@@ -315,11 +423,11 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner
|
- name: Run Trivy vulnerability scanner
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
@@ -330,7 +438,7 @@ jobs:
|
|||||||
GOOGLE_APPLICATION_CREDENTIAL: /path/to/credential.json
|
GOOGLE_APPLICATION_CREDENTIAL: /path/to/credential.json
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
@@ -348,11 +456,11 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner
|
- name: Run Trivy vulnerability scanner
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
@@ -361,10 +469,10 @@ jobs:
|
|||||||
output: 'trivy-results.sarif'
|
output: 'trivy-results.sarif'
|
||||||
env:
|
env:
|
||||||
TRIVY_USERNAME: Username
|
TRIVY_USERNAME: Username
|
||||||
TRIVY_PASSWORD: Password
|
TRIVY_PASSWORD: Password
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
```
|
```
|
||||||
@@ -375,25 +483,31 @@ jobs:
|
|||||||
|
|
||||||
Following inputs can be used as `step.with` keys:
|
Following inputs can be used as `step.with` keys:
|
||||||
|
|
||||||
| Name | Type | Default | Description |
|
| Name | Type | Default | Description |
|
||||||
|------------------|---------|------------------------------------|-----------------------------------------------|
|
|-------------------|---------|------------------------------------|-------------------------------------------------------------------------------------------------|
|
||||||
| `scan-type` | String | `image` | Scan type, e.g. `image` or `fs`|
|
| `scan-type` | String | `image` | Scan type, e.g. `image` or `fs` |
|
||||||
| `input` | String | | Tar reference, e.g. `alpine-latest.tar` |
|
| `input` | String | | Tar reference, e.g. `alpine-latest.tar` |
|
||||||
| `image-ref` | String | | Image reference, e.g. `alpine:3.10.2` |
|
| `image-ref` | String | | Image reference, e.g. `alpine:3.10.2` |
|
||||||
| `scan-ref` | String | `/github/workspace/` | Scan reference, e.g. `/github/workspace/` or `.`|
|
| `scan-ref` | String | `/github/workspace/` | Scan reference, e.g. `/github/workspace/` or `.` |
|
||||||
| `format` | String | `table` | Output format (`table`, `json`, `sarif`) |
|
| `format` | String | `table` | Output format (`table`, `json`, `sarif`, `github`) |
|
||||||
| `template` | String | | Output template (`@/contrib/gitlab.tpl`, `@/contrib/junit.tpl`)|
|
| `template` | String | | Output template (`@/contrib/gitlab.tpl`, `@/contrib/junit.tpl`) |
|
||||||
| `output` | String | | Save results to a file |
|
| `output` | String | | Save results to a file |
|
||||||
| `exit-code` | String | `0` | Exit code when specified vulnerabilities are found |
|
| `exit-code` | String | `0` | Exit code when specified vulnerabilities are found |
|
||||||
| `ignore-unfixed` | Boolean | false | Ignore unpatched/unfixed vulnerabilities |
|
| `ignore-unfixed` | Boolean | false | Ignore unpatched/unfixed vulnerabilities |
|
||||||
| `vuln-type` | String | `os,library` | Vulnerability types (os,library) |
|
| `vuln-type` | String | `os,library` | Vulnerability types (os,library) |
|
||||||
| `severity` | String | `UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL` | Severities of vulnerabilities to scanned for and displayed |
|
| `severity` | String | `UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL` | Severities of vulnerabilities to scanned for and displayed |
|
||||||
| `skip-dirs` | String | | Comma separated list of directories where traversal is skipped |
|
| `skip-dirs` | String | | Comma separated list of directories where traversal is skipped |
|
||||||
| `skip-files` | String | | Comma separated list of files where traversal is skipped |
|
| `skip-files` | String | | Comma separated list of files where traversal is skipped |
|
||||||
| `cache-dir` | String | | Cache directory |
|
| `cache-dir` | String | | Cache directory |
|
||||||
| `timeout` | String | `2m0s` | Scan timeout duration |
|
| `timeout` | String | `5m0s` | Scan timeout duration |
|
||||||
| `ignore-policy` | String | | Filter vulnerabilities with OPA rego language |
|
| `ignore-policy` | String | | Filter vulnerabilities with OPA rego language |
|
||||||
| `list-all-pkgs` | String | | Output all packages regardless of vulnerability |
|
| `hide-progress` | String | `true` | Suppress progress bar |
|
||||||
|
| `list-all-pkgs` | String | | Output all packages regardless of vulnerability |
|
||||||
|
| `scanners` | String | `vuln,secret` | comma-separated list of what security issues to detect (`vuln`,`secret`,`config`) |
|
||||||
|
| `trivyignores` | String | | comma-separated list of relative paths in repository to one or more `.trivyignore` files |
|
||||||
|
| `trivy-config` | String | | Path to trivy.yaml config |
|
||||||
|
| `github-pat` | String | | Authentication token to enable sending SBOM scan results to GitHub Dependency Graph. Can be either a GitHub Personal Access Token (PAT) or GITHUB_TOKEN |
|
||||||
|
| `limit-severities-for-sarif` | Boolean | false | By default *SARIF* format enforces output of all vulnerabilities regardless of configured severities. To override this behavior set this parameter to **true** |
|
||||||
|
|
||||||
[release]: https://github.com/aquasecurity/trivy-action/releases/latest
|
[release]: https://github.com/aquasecurity/trivy-action/releases/latest
|
||||||
[release-img]: https://img.shields.io/github/release/aquasecurity/trivy-action.svg?logo=github
|
[release-img]: https://img.shields.io/github/release/aquasecurity/trivy-action.svg?logo=github
|
||||||
|
|||||||
+27
-3
@@ -20,7 +20,6 @@ inputs:
|
|||||||
exit-code:
|
exit-code:
|
||||||
description: 'exit code when vulnerabilities were found'
|
description: 'exit code when vulnerabilities were found'
|
||||||
required: false
|
required: false
|
||||||
default: '0'
|
|
||||||
ignore-unfixed:
|
ignore-unfixed:
|
||||||
description: 'ignore unfixed vulnerabilities'
|
description: 'ignore unfixed vulnerabilities'
|
||||||
required: false
|
required: false
|
||||||
@@ -38,7 +37,7 @@ inputs:
|
|||||||
required: false
|
required: false
|
||||||
default: 'table'
|
default: 'table'
|
||||||
template:
|
template:
|
||||||
description: 'use an existing template for rendering output (@/contrib/sarif.tpl, @/contrib/gitlab.tpl, @/contrib/junit.tpl'
|
description: 'use an existing template for rendering output (@/contrib/gitlab.tpl, @/contrib/junit.tpl, @/contrib/html.tpl)'
|
||||||
required: false
|
required: false
|
||||||
default: ''
|
default: ''
|
||||||
output:
|
output:
|
||||||
@@ -68,11 +67,31 @@ inputs:
|
|||||||
hide-progress:
|
hide-progress:
|
||||||
description: 'hide progress output'
|
description: 'hide progress output'
|
||||||
required: false
|
required: false
|
||||||
default: 'true'
|
|
||||||
list-all-pkgs:
|
list-all-pkgs:
|
||||||
description: 'output all packages regardless of vulnerability'
|
description: 'output all packages regardless of vulnerability'
|
||||||
required: false
|
required: false
|
||||||
default: 'false'
|
default: 'false'
|
||||||
|
scanners:
|
||||||
|
description: 'comma-separated list of what security issues to detect'
|
||||||
|
required: false
|
||||||
|
default: ''
|
||||||
|
trivyignores:
|
||||||
|
description: 'comma-separated list of relative paths in repository to one or more .trivyignore files'
|
||||||
|
required: false
|
||||||
|
default: ''
|
||||||
|
artifact-type:
|
||||||
|
description: 'input artifact type (image, fs, repo, archive) for SBOM generation'
|
||||||
|
required: false
|
||||||
|
github-pat:
|
||||||
|
description: 'GitHub Personal Access Token (PAT) for submitting SBOM to GitHub Dependency Snapshot API'
|
||||||
|
required: false
|
||||||
|
trivy-config:
|
||||||
|
description: 'path to trivy.yaml config'
|
||||||
|
required: false
|
||||||
|
limit-severities-for-sarif:
|
||||||
|
description: 'limit severities for SARIF format'
|
||||||
|
required: false
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: 'docker'
|
using: 'docker'
|
||||||
image: "Dockerfile"
|
image: "Dockerfile"
|
||||||
@@ -95,3 +114,8 @@ runs:
|
|||||||
- '-p ${{ inputs.hide-progress }}'
|
- '-p ${{ inputs.hide-progress }}'
|
||||||
- '-q ${{ inputs.skip-files }}'
|
- '-q ${{ inputs.skip-files }}'
|
||||||
- '-r ${{ inputs.list-all-pkgs }}'
|
- '-r ${{ inputs.list-all-pkgs }}'
|
||||||
|
- '-s ${{ inputs.scanners }}'
|
||||||
|
- '-t ${{ inputs.trivyignores }}'
|
||||||
|
- '-u ${{ inputs.github-pat }}'
|
||||||
|
- '-v ${{ inputs.trivy-config }}'
|
||||||
|
- '-z ${{ inputs.limit-severities-for-sarif }}'
|
||||||
|
|||||||
+68
-12
@@ -1,6 +1,6 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
set -e
|
set -e
|
||||||
while getopts "a:b:c:d:e:f:g:h:i:j:k:l:m:n:o:p:q:r:" o; do
|
while getopts "a:b:c:d:e:f:g:h:i:j:k:l:m:n:o:p:q:r:s:t:u:v:z:" o; do
|
||||||
case "${o}" in
|
case "${o}" in
|
||||||
a)
|
a)
|
||||||
export scanType=${OPTARG}
|
export scanType=${OPTARG}
|
||||||
@@ -56,20 +56,38 @@ while getopts "a:b:c:d:e:f:g:h:i:j:k:l:m:n:o:p:q:r:" o; do
|
|||||||
r)
|
r)
|
||||||
export listAllPkgs=${OPTARG}
|
export listAllPkgs=${OPTARG}
|
||||||
;;
|
;;
|
||||||
|
s)
|
||||||
|
export scanners=${OPTARG}
|
||||||
|
;;
|
||||||
|
t)
|
||||||
|
export trivyIgnores=${OPTARG}
|
||||||
|
;;
|
||||||
|
u)
|
||||||
|
export githubPAT=${OPTARG}
|
||||||
|
;;
|
||||||
|
v)
|
||||||
|
export trivyConfig=${OPTARG}
|
||||||
|
;;
|
||||||
|
z)
|
||||||
|
export limitSeveritiesForSARIF=${OPTARG}
|
||||||
|
;;
|
||||||
esac
|
esac
|
||||||
done
|
done
|
||||||
|
|
||||||
|
|
||||||
scanType=$(echo $scanType | tr -d '\r')
|
scanType=$(echo $scanType | tr -d '\r')
|
||||||
export artifactRef="${imageRef}"
|
export artifactRef="${imageRef}"
|
||||||
if [ "${scanType}" = "fs" ] || [ "${scanType}" = "config" ] || [ "${scanType}" = "rootfs" ];then
|
if [ "${scanType}" = "repo" ] || [ "${scanType}" = "fs" ] || [ "${scanType}" = "config" ] || [ "${scanType}" = "rootfs" ];then
|
||||||
artifactRef=$(echo $scanRef | tr -d '\r')
|
artifactRef=$(echo $scanRef | tr -d '\r')
|
||||||
fi
|
fi
|
||||||
input=$(echo $input | tr -d '\r')
|
input=$(echo $input | tr -d '\r')
|
||||||
if [ $input ]; then
|
if [ $input ]; then
|
||||||
artifactRef="--input $input"
|
artifactRef="--input $input"
|
||||||
fi
|
fi
|
||||||
|
#trim leading spaces for boolean params
|
||||||
ignoreUnfixed=$(echo $ignoreUnfixed | tr -d '\r')
|
ignoreUnfixed=$(echo $ignoreUnfixed | tr -d '\r')
|
||||||
hideProgress=$(echo $hideProgress | tr -d '\r')
|
hideProgress=$(echo $hideProgress | tr -d '\r')
|
||||||
|
limitSeveritiesForSARIF=$(echo $limitSeveritiesForSARIF | tr -d '\r')
|
||||||
|
|
||||||
GLOBAL_ARGS=""
|
GLOBAL_ARGS=""
|
||||||
if [ $cacheDir ];then
|
if [ $cacheDir ];then
|
||||||
@@ -78,6 +96,7 @@ fi
|
|||||||
|
|
||||||
SARIF_ARGS=""
|
SARIF_ARGS=""
|
||||||
ARGS=""
|
ARGS=""
|
||||||
|
format=$(echo $format | xargs)
|
||||||
if [ $format ];then
|
if [ $format ];then
|
||||||
ARGS="$ARGS --format $format"
|
ARGS="$ARGS --format $format"
|
||||||
fi
|
fi
|
||||||
@@ -86,15 +105,20 @@ if [ $template ] ;then
|
|||||||
fi
|
fi
|
||||||
if [ $exitCode ];then
|
if [ $exitCode ];then
|
||||||
ARGS="$ARGS --exit-code $exitCode"
|
ARGS="$ARGS --exit-code $exitCode"
|
||||||
|
SARIF_ARGS="$SARIF_ARGS --exit-code $exitCode"
|
||||||
fi
|
fi
|
||||||
if [ "$ignoreUnfixed" == "true" ] && [ "$scanType" != "config" ];then
|
if [ "$ignoreUnfixed" == "true" ] && [ "$scanType" != "config" ];then
|
||||||
ARGS="$ARGS --ignore-unfixed"
|
ARGS="$ARGS --ignore-unfixed"
|
||||||
SARIF_ARGS="$SARIF_ARGS --ignore-unfixed"
|
SARIF_ARGS="$SARIF_ARGS --ignore-unfixed"
|
||||||
fi
|
fi
|
||||||
if [ $vulnType ] && [ "$scanType" != "config" ];then
|
if [ $vulnType ] && [ "$scanType" != "config" ] && [ "$scanType" != "sbom" ];then
|
||||||
ARGS="$ARGS --vuln-type $vulnType"
|
ARGS="$ARGS --vuln-type $vulnType"
|
||||||
SARIF_ARGS="$SARIF_ARGS --vuln-type $vulnType"
|
SARIF_ARGS="$SARIF_ARGS --vuln-type $vulnType"
|
||||||
fi
|
fi
|
||||||
|
if [ $scanners ];then
|
||||||
|
ARGS="$ARGS --scanners $scanners"
|
||||||
|
SARIF_ARGS="$SARIF_ARGS --scanners $scanners"
|
||||||
|
fi
|
||||||
if [ $severity ];then
|
if [ $severity ];then
|
||||||
ARGS="$ARGS --severity $severity"
|
ARGS="$ARGS --severity $severity"
|
||||||
fi
|
fi
|
||||||
@@ -108,8 +132,23 @@ if [ $skipDirs ];then
|
|||||||
SARIF_ARGS="$SARIF_ARGS --skip-dirs $i"
|
SARIF_ARGS="$SARIF_ARGS --skip-dirs $i"
|
||||||
done
|
done
|
||||||
fi
|
fi
|
||||||
|
if [ $trivyIgnores ];then
|
||||||
|
for f in $(echo $trivyIgnores | tr "," "\n")
|
||||||
|
do
|
||||||
|
if [ -f "$f" ]; then
|
||||||
|
echo "Found ignorefile '${f}':"
|
||||||
|
cat "${f}"
|
||||||
|
cat "${f}" >> ./trivyignores
|
||||||
|
else
|
||||||
|
echo "ERROR: cannot find ignorefile '${f}'."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
ARGS="$ARGS --ignorefile ./trivyignores"
|
||||||
|
fi
|
||||||
if [ $timeout ];then
|
if [ $timeout ];then
|
||||||
ARGS="$ARGS --timeout $timeout"
|
ARGS="$ARGS --timeout $timeout"
|
||||||
|
SARIF_ARGS="$SARIF_ARGS --timeout $timeout"
|
||||||
fi
|
fi
|
||||||
if [ $ignorePolicy ];then
|
if [ $ignorePolicy ];then
|
||||||
ARGS="$ARGS --ignore-policy $ignorePolicy"
|
ARGS="$ARGS --ignore-policy $ignorePolicy"
|
||||||
@@ -130,17 +169,34 @@ if [ "$skipFiles" ];then
|
|||||||
done
|
done
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo "Running trivy with options: ${ARGS}" "${artifactRef}"
|
trivyConfig=$(echo $trivyConfig | tr -d '\r')
|
||||||
echo "Global options: " "${GLOBAL_ARGS}"
|
# To make sure that uploda GitHub Dependency Snapshot succeeds, disable the script that fails first.
|
||||||
trivy $GLOBAL_ARGS ${scanType} $ARGS ${artifactRef}
|
set +e
|
||||||
returnCode=$?
|
if [ "${format}" == "sarif" ] && [ "${limitSeveritiesForSARIF}" != "true" ]; then
|
||||||
|
# SARIF is special. We output all vulnerabilities,
|
||||||
# SARIF is special. We output all vulnerabilities,
|
# regardless of severity level specified in this report.
|
||||||
# regardless of severity level specified in this report.
|
# This is a feature, not a bug :)
|
||||||
# This is a feature, not a bug :)
|
|
||||||
if [[ "${format}" == "sarif" ]]; then
|
|
||||||
echo "Building SARIF report with options: ${SARIF_ARGS}" "${artifactRef}"
|
echo "Building SARIF report with options: ${SARIF_ARGS}" "${artifactRef}"
|
||||||
trivy --quiet ${scanType} --format sarif --output ${output} $SARIF_ARGS ${artifactRef}
|
trivy --quiet ${scanType} --format sarif --output ${output} $SARIF_ARGS ${artifactRef}
|
||||||
|
elif [ $trivyConfig ]; then
|
||||||
|
echo "Running Trivy with trivy.yaml config from: " $trivyConfig
|
||||||
|
trivy --config $trivyConfig ${ARGS} ${scanType} ${artifactRef}
|
||||||
|
returnCode=$?
|
||||||
|
else
|
||||||
|
echo "Running trivy with options: trivy ${scanType} ${ARGS}" "${artifactRef}"
|
||||||
|
echo "Global options: " "${GLOBAL_ARGS}"
|
||||||
|
trivy $GLOBAL_ARGS ${scanType} ${ARGS} ${artifactRef}
|
||||||
|
returnCode=$?
|
||||||
|
fi
|
||||||
|
|
||||||
|
set -e
|
||||||
|
if [[ "${format}" == "github" ]]; then
|
||||||
|
if [[ "$(echo $githubPAT | xargs)" != "" ]]; then
|
||||||
|
printf "\n Uploading GitHub Dependency Snapshot"
|
||||||
|
curl -H 'Accept: application/vnd.github+json' -H "Authorization: token $githubPAT" 'https://api.github.com/repos/'$GITHUB_REPOSITORY'/dependency-graph/snapshots' -d @./$(echo $output | xargs)
|
||||||
|
else
|
||||||
|
printf "\n Failing GitHub Dependency Snapshot. Missing github-pat"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
exit $returnCode
|
exit $returnCode
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# test data #1 for trivy-ignores option
|
||||||
|
CVE-2020-25576
|
||||||
|
CVE-2019-15551
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
# test data #2 for trivy-ignores option
|
||||||
|
CVE-2019-15554
|
||||||
@@ -0,0 +1,134 @@
|
|||||||
|
{
|
||||||
|
"version": "2.1.0",
|
||||||
|
"$schema": "https://json.schemastore.org/sarif-2.1.0.json",
|
||||||
|
"runs": [
|
||||||
|
{
|
||||||
|
"tool": {
|
||||||
|
"driver": {
|
||||||
|
"fullName": "Trivy Vulnerability Scanner",
|
||||||
|
"informationUri": "https://github.com/aquasecurity/trivy",
|
||||||
|
"name": "Trivy",
|
||||||
|
"rules": [
|
||||||
|
{
|
||||||
|
"id": "DS002",
|
||||||
|
"name": "Misconfiguration",
|
||||||
|
"shortDescription": {
|
||||||
|
"text": "Image user should not be \u0026#39;root\u0026#39;"
|
||||||
|
},
|
||||||
|
"fullDescription": {
|
||||||
|
"text": "Running containers with \u0026#39;root\u0026#39; user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a \u0026#39;USER\u0026#39; statement to the Dockerfile."
|
||||||
|
},
|
||||||
|
"defaultConfiguration": {
|
||||||
|
"level": "error"
|
||||||
|
},
|
||||||
|
"helpUri": "https://avd.aquasec.com/misconfig/ds002",
|
||||||
|
"help": {
|
||||||
|
"text": "Misconfiguration DS002\nType: Dockerfile Security Check\nSeverity: HIGH\nCheck: Image user should not be 'root'\nMessage: Specify at least 1 USER command in Dockerfile with non-root user as argument\nLink: [DS002](https://avd.aquasec.com/misconfig/ds002)\nRunning containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.",
|
||||||
|
"markdown": "**Misconfiguration DS002**\n| Type | Severity | Check | Message | Link |\n| --- | --- | --- | --- | --- |\n|Dockerfile Security Check|HIGH|Image user should not be 'root'|Specify at least 1 USER command in Dockerfile with non-root user as argument|[DS002](https://avd.aquasec.com/misconfig/ds002)|\n\nRunning containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile."
|
||||||
|
},
|
||||||
|
"properties": {
|
||||||
|
"precision": "very-high",
|
||||||
|
"security-severity": "8.0",
|
||||||
|
"tags": [
|
||||||
|
"misconfiguration",
|
||||||
|
"security",
|
||||||
|
"HIGH"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "DS026",
|
||||||
|
"name": "Misconfiguration",
|
||||||
|
"shortDescription": {
|
||||||
|
"text": "No HEALTHCHECK defined"
|
||||||
|
},
|
||||||
|
"fullDescription": {
|
||||||
|
"text": "You should add HEALTHCHECK instruction in your docker container images to perform the health check on running containers."
|
||||||
|
},
|
||||||
|
"defaultConfiguration": {
|
||||||
|
"level": "note"
|
||||||
|
},
|
||||||
|
"helpUri": "https://avd.aquasec.com/misconfig/ds026",
|
||||||
|
"help": {
|
||||||
|
"text": "Misconfiguration DS026\nType: Dockerfile Security Check\nSeverity: LOW\nCheck: No HEALTHCHECK defined\nMessage: Add HEALTHCHECK instruction in your Dockerfile\nLink: [DS026](https://avd.aquasec.com/misconfig/ds026)\nYou should add HEALTHCHECK instruction in your docker container images to perform the health check on running containers.",
|
||||||
|
"markdown": "**Misconfiguration DS026**\n| Type | Severity | Check | Message | Link |\n| --- | --- | --- | --- | --- |\n|Dockerfile Security Check|LOW|No HEALTHCHECK defined|Add HEALTHCHECK instruction in your Dockerfile|[DS026](https://avd.aquasec.com/misconfig/ds026)|\n\nYou should add HEALTHCHECK instruction in your docker container images to perform the health check on running containers."
|
||||||
|
},
|
||||||
|
"properties": {
|
||||||
|
"precision": "very-high",
|
||||||
|
"security-severity": "2.0",
|
||||||
|
"tags": [
|
||||||
|
"misconfiguration",
|
||||||
|
"security",
|
||||||
|
"LOW"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"version": "0.42.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"results": [
|
||||||
|
{
|
||||||
|
"ruleId": "DS002",
|
||||||
|
"ruleIndex": 0,
|
||||||
|
"level": "error",
|
||||||
|
"message": {
|
||||||
|
"text": "Artifact: Dockerfile\nType: dockerfile\nVulnerability DS002\nSeverity: HIGH\nMessage: Specify at least 1 USER command in Dockerfile with non-root user as argument\nLink: [DS002](https://avd.aquasec.com/misconfig/ds002)"
|
||||||
|
},
|
||||||
|
"locations": [
|
||||||
|
{
|
||||||
|
"physicalLocation": {
|
||||||
|
"artifactLocation": {
|
||||||
|
"uri": "Dockerfile",
|
||||||
|
"uriBaseId": "ROOTPATH"
|
||||||
|
},
|
||||||
|
"region": {
|
||||||
|
"startLine": 1,
|
||||||
|
"startColumn": 1,
|
||||||
|
"endLine": 1,
|
||||||
|
"endColumn": 1
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"message": {
|
||||||
|
"text": "Dockerfile"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ruleId": "DS026",
|
||||||
|
"ruleIndex": 1,
|
||||||
|
"level": "note",
|
||||||
|
"message": {
|
||||||
|
"text": "Artifact: Dockerfile\nType: dockerfile\nVulnerability DS026\nSeverity: LOW\nMessage: Add HEALTHCHECK instruction in your Dockerfile\nLink: [DS026](https://avd.aquasec.com/misconfig/ds026)"
|
||||||
|
},
|
||||||
|
"locations": [
|
||||||
|
{
|
||||||
|
"physicalLocation": {
|
||||||
|
"artifactLocation": {
|
||||||
|
"uri": "Dockerfile",
|
||||||
|
"uriBaseId": "ROOTPATH"
|
||||||
|
},
|
||||||
|
"region": {
|
||||||
|
"startLine": 1,
|
||||||
|
"startColumn": 1,
|
||||||
|
"endLine": 1,
|
||||||
|
"endColumn": 1
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"message": {
|
||||||
|
"text": "Dockerfile"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"columnKind": "utf16CodeUnits",
|
||||||
|
"originalUriBaseIds": {
|
||||||
|
"ROOTPATH": {
|
||||||
|
"uri": "file:///"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{
|
||||||
|
"SchemaVersion": 2,
|
||||||
|
"ArtifactName": ".",
|
||||||
|
"ArtifactType": "filesystem",
|
||||||
|
"Metadata": {
|
||||||
|
"ImageConfig": {
|
||||||
|
"architecture": "",
|
||||||
|
"created": "0001-01-01T00:00:00Z",
|
||||||
|
"os": "",
|
||||||
|
"rootfs": {
|
||||||
|
"type": "",
|
||||||
|
"diff_ids": null
|
||||||
|
},
|
||||||
|
"config": {}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"Results": [
|
||||||
|
{
|
||||||
|
"Target": "Dockerfile",
|
||||||
|
"Class": "config",
|
||||||
|
"Type": "dockerfile",
|
||||||
|
"MisconfSummary": {
|
||||||
|
"Successes": 24,
|
||||||
|
"Failures": 2,
|
||||||
|
"Exceptions": 0
|
||||||
|
},
|
||||||
|
"Misconfigurations": [
|
||||||
|
{
|
||||||
|
"Type": "Dockerfile Security Check",
|
||||||
|
"ID": "DS002",
|
||||||
|
"AVDID": "AVD-DS-0002",
|
||||||
|
"Title": "Image user should not be 'root'",
|
||||||
|
"Description": "Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.",
|
||||||
|
"Message": "Specify at least 1 USER command in Dockerfile with non-root user as argument",
|
||||||
|
"Namespace": "builtin.dockerfile.DS002",
|
||||||
|
"Query": "data.builtin.dockerfile.DS002.deny",
|
||||||
|
"Resolution": "Add 'USER \u003cnon root user name\u003e' line to the Dockerfile",
|
||||||
|
"Severity": "HIGH",
|
||||||
|
"PrimaryURL": "https://avd.aquasec.com/misconfig/ds002",
|
||||||
|
"References": [
|
||||||
|
"https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
|
||||||
|
"https://avd.aquasec.com/misconfig/ds002"
|
||||||
|
],
|
||||||
|
"Status": "FAIL",
|
||||||
|
"Layer": {},
|
||||||
|
"CauseMetadata": {
|
||||||
|
"Provider": "Dockerfile",
|
||||||
|
"Service": "general",
|
||||||
|
"Code": {
|
||||||
|
"Lines": null
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"Type": "Dockerfile Security Check",
|
||||||
|
"ID": "DS026",
|
||||||
|
"AVDID": "AVD-DS-0026",
|
||||||
|
"Title": "No HEALTHCHECK defined",
|
||||||
|
"Description": "You should add HEALTHCHECK instruction in your docker container images to perform the health check on running containers.",
|
||||||
|
"Message": "Add HEALTHCHECK instruction in your Dockerfile",
|
||||||
|
"Namespace": "builtin.dockerfile.DS026",
|
||||||
|
"Query": "data.builtin.dockerfile.DS026.deny",
|
||||||
|
"Resolution": "Add HEALTHCHECK instruction in Dockerfile",
|
||||||
|
"Severity": "LOW",
|
||||||
|
"PrimaryURL": "https://avd.aquasec.com/misconfig/ds026",
|
||||||
|
"References": [
|
||||||
|
"https://blog.aquasec.com/docker-security-best-practices",
|
||||||
|
"https://avd.aquasec.com/misconfig/ds026"
|
||||||
|
],
|
||||||
|
"Status": "FAIL",
|
||||||
|
"Layer": {},
|
||||||
|
"CauseMetadata": {
|
||||||
|
"Provider": "Dockerfile",
|
||||||
|
"Service": "general",
|
||||||
|
"Code": {
|
||||||
|
"Lines": null
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{
|
||||||
|
"SchemaVersion": 2,
|
||||||
|
"ArtifactName": ".",
|
||||||
|
"ArtifactType": "filesystem",
|
||||||
|
"Metadata": {
|
||||||
|
"ImageConfig": {
|
||||||
|
"architecture": "",
|
||||||
|
"created": "0001-01-01T00:00:00Z",
|
||||||
|
"os": "",
|
||||||
|
"rootfs": {
|
||||||
|
"type": "",
|
||||||
|
"diff_ids": null
|
||||||
|
},
|
||||||
|
"config": {}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"Results": [
|
||||||
|
{
|
||||||
|
"Target": "Dockerfile",
|
||||||
|
"Class": "config",
|
||||||
|
"Type": "dockerfile",
|
||||||
|
"MisconfSummary": {
|
||||||
|
"Successes": 24,
|
||||||
|
"Failures": 2,
|
||||||
|
"Exceptions": 0
|
||||||
|
},
|
||||||
|
"Misconfigurations": [
|
||||||
|
{
|
||||||
|
"Type": "Dockerfile Security Check",
|
||||||
|
"ID": "DS002",
|
||||||
|
"AVDID": "AVD-DS-0002",
|
||||||
|
"Title": "Image user should not be 'root'",
|
||||||
|
"Description": "Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.",
|
||||||
|
"Message": "Specify at least 1 USER command in Dockerfile with non-root user as argument",
|
||||||
|
"Namespace": "builtin.dockerfile.DS002",
|
||||||
|
"Query": "data.builtin.dockerfile.DS002.deny",
|
||||||
|
"Resolution": "Add 'USER \u003cnon root user name\u003e' line to the Dockerfile",
|
||||||
|
"Severity": "HIGH",
|
||||||
|
"PrimaryURL": "https://avd.aquasec.com/misconfig/ds002",
|
||||||
|
"References": [
|
||||||
|
"https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
|
||||||
|
"https://avd.aquasec.com/misconfig/ds002"
|
||||||
|
],
|
||||||
|
"Status": "FAIL",
|
||||||
|
"Layer": {},
|
||||||
|
"CauseMetadata": {
|
||||||
|
"Provider": "Dockerfile",
|
||||||
|
"Service": "general",
|
||||||
|
"Code": {
|
||||||
|
"Lines": null
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"Type": "Dockerfile Security Check",
|
||||||
|
"ID": "DS026",
|
||||||
|
"AVDID": "AVD-DS-0026",
|
||||||
|
"Title": "No HEALTHCHECK defined",
|
||||||
|
"Description": "You should add HEALTHCHECK instruction in your docker container images to perform the health check on running containers.",
|
||||||
|
"Message": "Add HEALTHCHECK instruction in your Dockerfile",
|
||||||
|
"Namespace": "builtin.dockerfile.DS026",
|
||||||
|
"Query": "data.builtin.dockerfile.DS026.deny",
|
||||||
|
"Resolution": "Add HEALTHCHECK instruction in Dockerfile",
|
||||||
|
"Severity": "LOW",
|
||||||
|
"PrimaryURL": "https://avd.aquasec.com/misconfig/ds026",
|
||||||
|
"References": [
|
||||||
|
"https://blog.aquasec.com/docker-security-best-practices",
|
||||||
|
"https://avd.aquasec.com/misconfig/ds026"
|
||||||
|
],
|
||||||
|
"Status": "FAIL",
|
||||||
|
"Layer": {},
|
||||||
|
"CauseMetadata": {
|
||||||
|
"Provider": "Dockerfile",
|
||||||
|
"Service": "general",
|
||||||
|
"Code": {
|
||||||
|
"Lines": null
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,77 @@
|
|||||||
|
{
|
||||||
|
"version": "2.1.0",
|
||||||
|
"$schema": "https://json.schemastore.org/sarif-2.1.0.json",
|
||||||
|
"runs": [
|
||||||
|
{
|
||||||
|
"tool": {
|
||||||
|
"driver": {
|
||||||
|
"fullName": "Trivy Vulnerability Scanner",
|
||||||
|
"informationUri": "https://github.com/aquasecurity/trivy",
|
||||||
|
"name": "Trivy",
|
||||||
|
"rules": [
|
||||||
|
{
|
||||||
|
"id": "CVE-2021-36159",
|
||||||
|
"name": "OsPackageVulnerability",
|
||||||
|
"shortDescription": {
|
||||||
|
"text": "CVE-2021-36159"
|
||||||
|
},
|
||||||
|
"fullDescription": {
|
||||||
|
"text": "libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It does not check if the line ends prematurely. If it does, the for-loop condition checks for the \u0026#39;\\0\u0026#39; terminator one byte too late."
|
||||||
|
},
|
||||||
|
"defaultConfiguration": {
|
||||||
|
"level": "error"
|
||||||
|
},
|
||||||
|
"helpUri": "https://avd.aquasec.com/nvd/cve-2021-36159",
|
||||||
|
"help": {
|
||||||
|
"text": "Vulnerability CVE-2021-36159\nSeverity: CRITICAL\nPackage: apk-tools\nFixed Version: 2.10.7-r0\nLink: [CVE-2021-36159](https://avd.aquasec.com/nvd/cve-2021-36159)\nlibfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It does not check if the line ends prematurely. If it does, the for-loop condition checks for the '\\0' terminator one byte too late.",
|
||||||
|
"markdown": "**Vulnerability CVE-2021-36159**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|CRITICAL|apk-tools|2.10.7-r0|[CVE-2021-36159](https://avd.aquasec.com/nvd/cve-2021-36159)|\n\nlibfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It does not check if the line ends prematurely. If it does, the for-loop condition checks for the '\\0' terminator one byte too late."
|
||||||
|
},
|
||||||
|
"properties": {
|
||||||
|
"precision": "very-high",
|
||||||
|
"security-severity": "9.1",
|
||||||
|
"tags": [
|
||||||
|
"vulnerability",
|
||||||
|
"security",
|
||||||
|
"CRITICAL"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"version": "0.42.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"results": [
|
||||||
|
{
|
||||||
|
"ruleId": "CVE-2021-36159",
|
||||||
|
"ruleIndex": 0,
|
||||||
|
"level": "error",
|
||||||
|
"message": {
|
||||||
|
"text": "Package: apk-tools\nInstalled Version: 2.10.6-r0\nVulnerability CVE-2021-36159\nSeverity: CRITICAL\nFixed Version: 2.10.7-r0\nLink: [CVE-2021-36159](https://avd.aquasec.com/nvd/cve-2021-36159)"
|
||||||
|
},
|
||||||
|
"locations": [
|
||||||
|
{
|
||||||
|
"physicalLocation": {
|
||||||
|
"artifactLocation": {
|
||||||
|
"uri": "library/alpine",
|
||||||
|
"uriBaseId": "ROOTPATH"
|
||||||
|
},
|
||||||
|
"region": {
|
||||||
|
"startLine": 1,
|
||||||
|
"startColumn": 1,
|
||||||
|
"endLine": 1,
|
||||||
|
"endColumn": 1
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"columnKind": "utf16CodeUnits",
|
||||||
|
"originalUriBaseIds": {
|
||||||
|
"ROOTPATH": {
|
||||||
|
"uri": "file:///"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,89 @@
|
|||||||
|
|
||||||
|
knqyf263/vuln-image:1.2.3 (alpine 3.7.1)
|
||||||
|
========================================
|
||||||
|
Total: 19 (CRITICAL: 19)
|
||||||
|
|
||||||
|
┌─────────────┬────────────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────────┐
|
||||||
|
│ Library │ Vulnerability │ Severity │ Installed Version │ Fixed Version │ Title │
|
||||||
|
├─────────────┼────────────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ curl │ CVE-2018-14618 │ CRITICAL │ 7.61.0-r0 │ 7.61.1-r0 │ curl: NTLM password overflow via integer overflow │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-14618 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16839 │ │ │ 7.61.1-r1 │ curl: Integer overflow leading to heap-based buffer overflow │
|
||||||
|
│ │ │ │ │ │ in Curl_sasl_create_plain_message() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16839 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16840 │ │ │ │ curl: Use-after-free when closing "easy" handle in │
|
||||||
|
│ │ │ │ │ │ Curl_close() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16840 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16842 │ │ │ │ curl: Heap-based buffer over-read in the curl tool warning │
|
||||||
|
│ │ │ │ │ │ formatting │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16842 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-3822 │ │ │ 7.61.1-r2 │ curl: NTLMv2 type-3 header stack buffer overflow │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-3822 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-5481 │ │ │ 7.61.1-r3 │ curl: double free due to subsequent call of realloc() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-5481 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-5482 │ │ │ │ curl: heap buffer overflow in function tftp_receive_packet() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-5482 │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ git │ CVE-2018-17456 │ │ 2.15.2-r0 │ 2.15.3-r0 │ git: arbitrary code execution via .gitmodules │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-17456 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-1353 │ │ │ 2.15.4-r0 │ git: NTFS protections inactive when running Git in the │
|
||||||
|
│ │ │ │ │ │ Windows Subsystem for... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-1353 │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ libbz2 │ CVE-2019-12900 │ │ 1.0.6-r6 │ 1.0.6-r7 │ bzip2: out-of-bounds write in function BZ2_decompress │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-12900 │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ libcurl │ CVE-2018-16839 │ │ 7.61.1-r0 │ 7.61.1-r1 │ curl: Integer overflow leading to heap-based buffer overflow │
|
||||||
|
│ │ │ │ │ │ in Curl_sasl_create_plain_message() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16839 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16840 │ │ │ │ curl: Use-after-free when closing "easy" handle in │
|
||||||
|
│ │ │ │ │ │ Curl_close() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16840 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16842 │ │ │ │ curl: Heap-based buffer over-read in the curl tool warning │
|
||||||
|
│ │ │ │ │ │ formatting │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16842 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-3822 │ │ │ 7.61.1-r2 │ curl: NTLMv2 type-3 header stack buffer overflow │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-3822 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-5481 │ │ │ 7.61.1-r3 │ curl: double free due to subsequent call of realloc() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-5481 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-5482 │ │ │ │ curl: heap buffer overflow in function tftp_receive_packet() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-5482 │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ musl │ CVE-2019-14697 │ │ 1.1.18-r3 │ 1.1.18-r4 │ musl libc through 1.1.23 has an x87 floating-point stack │
|
||||||
|
│ │ │ │ │ │ adjustment im ...... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-14697 │
|
||||||
|
├─────────────┤ │ │ │ │ │
|
||||||
|
│ musl-utils │ │ │ │ │ │
|
||||||
|
│ │ │ │ │ │ │
|
||||||
|
│ │ │ │ │ │ │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ sqlite-libs │ CVE-2019-8457 │ │ 3.21.0-r1 │ 3.25.3-r1 │ sqlite: heap out-of-bound read in function rtreenode() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-8457 │
|
||||||
|
└─────────────┴────────────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────────┘
|
||||||
|
|
||||||
|
rust-app/Cargo.lock (cargo)
|
||||||
|
===========================
|
||||||
|
Total: 2 (CRITICAL: 2)
|
||||||
|
|
||||||
|
┌──────────┬────────────────┬──────────┬───────────────────┬───────────────┬─────────────────────────────────────────────────────────────┐
|
||||||
|
│ Library │ Vulnerability │ Severity │ Installed Version │ Fixed Version │ Title │
|
||||||
|
├──────────┼────────────────┼──────────┼───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
|
||||||
|
│ openssl │ CVE-2018-20997 │ CRITICAL │ 0.8.3 │ 0.10.9 │ Use after free in openssl │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-20997 │
|
||||||
|
├──────────┼────────────────┤ ├───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
|
||||||
|
│ smallvec │ CVE-2021-25900 │ │ 0.6.9 │ 1.6.1, 0.6.14 │ An issue was discovered in the smallvec crate before 0.6.14 │
|
||||||
|
│ │ │ │ │ │ and 1.x... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-25900 │
|
||||||
|
└──────────┴────────────────┴──────────┴───────────────────┴───────────────┴─────────────────────────────────────────────────────────────┘
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
|
||||||
|
knqyf263/vuln-image:1.2.3 (alpine 3.7.1)
|
||||||
|
========================================
|
||||||
|
Total: 19 (CRITICAL: 19)
|
||||||
|
|
||||||
|
┌─────────────┬────────────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────────┐
|
||||||
|
│ Library │ Vulnerability │ Severity │ Installed Version │ Fixed Version │ Title │
|
||||||
|
├─────────────┼────────────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ curl │ CVE-2018-14618 │ CRITICAL │ 7.61.0-r0 │ 7.61.1-r0 │ curl: NTLM password overflow via integer overflow │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-14618 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16839 │ │ │ 7.61.1-r1 │ curl: Integer overflow leading to heap-based buffer overflow │
|
||||||
|
│ │ │ │ │ │ in Curl_sasl_create_plain_message() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16839 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16840 │ │ │ │ curl: Use-after-free when closing "easy" handle in │
|
||||||
|
│ │ │ │ │ │ Curl_close() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16840 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16842 │ │ │ │ curl: Heap-based buffer over-read in the curl tool warning │
|
||||||
|
│ │ │ │ │ │ formatting │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16842 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-3822 │ │ │ 7.61.1-r2 │ curl: NTLMv2 type-3 header stack buffer overflow │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-3822 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-5481 │ │ │ 7.61.1-r3 │ curl: double free due to subsequent call of realloc() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-5481 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-5482 │ │ │ │ curl: heap buffer overflow in function tftp_receive_packet() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-5482 │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ git │ CVE-2018-17456 │ │ 2.15.2-r0 │ 2.15.3-r0 │ git: arbitrary code execution via .gitmodules │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-17456 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-1353 │ │ │ 2.15.4-r0 │ git: NTFS protections inactive when running Git in the │
|
||||||
|
│ │ │ │ │ │ Windows Subsystem for... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-1353 │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ libbz2 │ CVE-2019-12900 │ │ 1.0.6-r6 │ 1.0.6-r7 │ bzip2: out-of-bounds write in function BZ2_decompress │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-12900 │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ libcurl │ CVE-2018-16839 │ │ 7.61.1-r0 │ 7.61.1-r1 │ curl: Integer overflow leading to heap-based buffer overflow │
|
||||||
|
│ │ │ │ │ │ in Curl_sasl_create_plain_message() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16839 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16840 │ │ │ │ curl: Use-after-free when closing "easy" handle in │
|
||||||
|
│ │ │ │ │ │ Curl_close() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16840 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2018-16842 │ │ │ │ curl: Heap-based buffer over-read in the curl tool warning │
|
||||||
|
│ │ │ │ │ │ formatting │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-16842 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-3822 │ │ │ 7.61.1-r2 │ curl: NTLMv2 type-3 header stack buffer overflow │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-3822 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-5481 │ │ │ 7.61.1-r3 │ curl: double free due to subsequent call of realloc() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-5481 │
|
||||||
|
│ ├────────────────┤ │ │ ├──────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-5482 │ │ │ │ curl: heap buffer overflow in function tftp_receive_packet() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-5482 │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ musl │ CVE-2019-14697 │ │ 1.1.18-r3 │ 1.1.18-r4 │ musl libc through 1.1.23 has an x87 floating-point stack │
|
||||||
|
│ │ │ │ │ │ adjustment im ...... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-14697 │
|
||||||
|
├─────────────┤ │ │ │ │ │
|
||||||
|
│ musl-utils │ │ │ │ │ │
|
||||||
|
│ │ │ │ │ │ │
|
||||||
|
│ │ │ │ │ │ │
|
||||||
|
├─────────────┼────────────────┤ ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
|
||||||
|
│ sqlite-libs │ CVE-2019-8457 │ │ 3.21.0-r1 │ 3.25.3-r1 │ sqlite: heap out-of-bound read in function rtreenode() │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-8457 │
|
||||||
|
└─────────────┴────────────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────────┘
|
||||||
|
|
||||||
|
rust-app/Cargo.lock (cargo)
|
||||||
|
===========================
|
||||||
|
Total: 5 (CRITICAL: 5)
|
||||||
|
|
||||||
|
┌───────────┬────────────────┬──────────┬───────────────────┬───────────────┬─────────────────────────────────────────────────────────────┐
|
||||||
|
│ Library │ Vulnerability │ Severity │ Installed Version │ Fixed Version │ Title │
|
||||||
|
├───────────┼────────────────┼──────────┼───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
|
||||||
|
│ openssl │ CVE-2018-20997 │ CRITICAL │ 0.8.3 │ 0.10.9 │ Use after free in openssl │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-20997 │
|
||||||
|
├───────────┼────────────────┤ ├───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
|
||||||
|
│ rand_core │ CVE-2020-25576 │ │ 0.4.0 │ 0.3.1, 0.4.2 │ An issue was discovered in the rand_core crate before 0.4.2 │
|
||||||
|
│ │ │ │ │ │ for Rust.... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2020-25576 │
|
||||||
|
├───────────┼────────────────┤ ├───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
|
||||||
|
│ smallvec │ CVE-2019-15551 │ │ 0.6.9 │ 0.6.10 │ An issue was discovered in the smallvec crate before 0.6.10 │
|
||||||
|
│ │ │ │ │ │ for Rust.... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-15551 │
|
||||||
|
│ ├────────────────┤ │ │ ├─────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2019-15554 │ │ │ │ An issue was discovered in the smallvec crate before 0.6.10 │
|
||||||
|
│ │ │ │ │ │ for Rust.... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-15554 │
|
||||||
|
│ ├────────────────┤ │ ├───────────────┼─────────────────────────────────────────────────────────────┤
|
||||||
|
│ │ CVE-2021-25900 │ │ │ 1.6.1, 0.6.14 │ An issue was discovered in the smallvec crate before 0.6.14 │
|
||||||
|
│ │ │ │ │ │ and 1.x... │
|
||||||
|
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-25900 │
|
||||||
|
└───────────┴────────────────┴──────────┴───────────────────┴───────────────┴─────────────────────────────────────────────────────────────┘
|
||||||
@@ -0,0 +1,77 @@
|
|||||||
|
{
|
||||||
|
"SchemaVersion": 2,
|
||||||
|
"ArtifactName": "https://github.com/krol3/demo-trivy/",
|
||||||
|
"ArtifactType": "repository",
|
||||||
|
"Metadata": {
|
||||||
|
"ImageConfig": {
|
||||||
|
"architecture": "",
|
||||||
|
"created": "0001-01-01T00:00:00Z",
|
||||||
|
"os": "",
|
||||||
|
"rootfs": {
|
||||||
|
"type": "",
|
||||||
|
"diff_ids": null
|
||||||
|
},
|
||||||
|
"config": {}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"Results": [
|
||||||
|
{
|
||||||
|
"Target": "env",
|
||||||
|
"Class": "secret",
|
||||||
|
"Secrets": [
|
||||||
|
{
|
||||||
|
"RuleID": "github-pat",
|
||||||
|
"Category": "GitHub",
|
||||||
|
"Severity": "CRITICAL",
|
||||||
|
"Title": "GitHub Personal Access Token",
|
||||||
|
"StartLine": 5,
|
||||||
|
"EndLine": 5,
|
||||||
|
"Code": {
|
||||||
|
"Lines": [
|
||||||
|
{
|
||||||
|
"Number": 3,
|
||||||
|
"Content": "export AWS_ACCESS_KEY_ID=1234567",
|
||||||
|
"IsCause": false,
|
||||||
|
"Annotation": "",
|
||||||
|
"Truncated": false,
|
||||||
|
"Highlighted": "export AWS_ACCESS_KEY_ID=1234567",
|
||||||
|
"FirstCause": false,
|
||||||
|
"LastCause": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"Number": 4,
|
||||||
|
"Content": "",
|
||||||
|
"IsCause": false,
|
||||||
|
"Annotation": "",
|
||||||
|
"Truncated": false,
|
||||||
|
"FirstCause": false,
|
||||||
|
"LastCause": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"Number": 5,
|
||||||
|
"Content": "export GITHUB_PAT=****************************************",
|
||||||
|
"IsCause": true,
|
||||||
|
"Annotation": "",
|
||||||
|
"Truncated": false,
|
||||||
|
"Highlighted": "export GITHUB_PAT=****************************************",
|
||||||
|
"FirstCause": true,
|
||||||
|
"LastCause": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"Number": 6,
|
||||||
|
"Content": "",
|
||||||
|
"IsCause": false,
|
||||||
|
"Annotation": "",
|
||||||
|
"Truncated": false,
|
||||||
|
"FirstCause": false,
|
||||||
|
"LastCause": false
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"Match": "export GITHUB_PAT=****************************************",
|
||||||
|
"Layer": {}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
vulnerability:
|
||||||
|
type: os
|
||||||
|
output: yamlconfig.test
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
format: json
|
||||||
|
severity: CRITICAL
|
||||||
|
vulnerability:
|
||||||
|
type: os
|
||||||
|
output: yamlconfig.test
|
||||||
@@ -0,0 +1,105 @@
|
|||||||
|
{
|
||||||
|
"SchemaVersion": 2,
|
||||||
|
"ArtifactName": "alpine:3.10",
|
||||||
|
"ArtifactType": "container_image",
|
||||||
|
"Metadata": {
|
||||||
|
"OS": {
|
||||||
|
"Family": "alpine",
|
||||||
|
"Name": "3.10.9",
|
||||||
|
"EOSL": true
|
||||||
|
},
|
||||||
|
"ImageID": "sha256:e7b300aee9f9bf3433d32bc9305bfdd22183beb59d933b48d77ab56ba53a197a",
|
||||||
|
"DiffIDs": [
|
||||||
|
"sha256:9fb3aa2f8b8023a4bebbf92aa567caf88e38e969ada9f0ac12643b2847391635"
|
||||||
|
],
|
||||||
|
"RepoTags": [
|
||||||
|
"alpine:3.10"
|
||||||
|
],
|
||||||
|
"RepoDigests": [
|
||||||
|
"alpine@sha256:451eee8bedcb2f029756dc3e9d73bab0e7943c1ac55cff3a4861c52a0fdd3e98"
|
||||||
|
],
|
||||||
|
"ImageConfig": {
|
||||||
|
"architecture": "amd64",
|
||||||
|
"container": "fdb7e80e3339e8d0599282e606c907aa5881ee4c668a68136119e6dfac6ce3a4",
|
||||||
|
"created": "2021-04-14T19:20:05.338397761Z",
|
||||||
|
"docker_version": "19.03.12",
|
||||||
|
"history": [
|
||||||
|
{
|
||||||
|
"created": "2021-04-14T19:20:04.987219124Z",
|
||||||
|
"created_by": "/bin/sh -c #(nop) ADD file:c5377eaa926bf412dd8d4a08b0a1f2399cfd708743533b0aa03b53d14cb4bb4e in / "
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"created": "2021-04-14T19:20:05.338397761Z",
|
||||||
|
"created_by": "/bin/sh -c #(nop) CMD [\"/bin/sh\"]",
|
||||||
|
"empty_layer": true
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"os": "linux",
|
||||||
|
"rootfs": {
|
||||||
|
"type": "layers",
|
||||||
|
"diff_ids": [
|
||||||
|
"sha256:9fb3aa2f8b8023a4bebbf92aa567caf88e38e969ada9f0ac12643b2847391635"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"config": {
|
||||||
|
"Cmd": [
|
||||||
|
"/bin/sh"
|
||||||
|
],
|
||||||
|
"Env": [
|
||||||
|
"PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
|
||||||
|
],
|
||||||
|
"Image": "sha256:eb2080c455e94c22ae35b3aef9e078c492a00795412e026e4d6b41ef64bc7dd8"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"Results": [
|
||||||
|
{
|
||||||
|
"Target": "alpine:3.10 (alpine 3.10.9)",
|
||||||
|
"Class": "os-pkgs",
|
||||||
|
"Type": "alpine",
|
||||||
|
"Vulnerabilities": [
|
||||||
|
{
|
||||||
|
"VulnerabilityID": "CVE-2021-36159",
|
||||||
|
"PkgID": "apk-tools@2.10.6-r0",
|
||||||
|
"PkgName": "apk-tools",
|
||||||
|
"InstalledVersion": "2.10.6-r0",
|
||||||
|
"FixedVersion": "2.10.7-r0",
|
||||||
|
"Layer": {
|
||||||
|
"Digest": "sha256:396c31837116ac290458afcb928f68b6cc1c7bdd6963fc72f52f365a2a89c1b5",
|
||||||
|
"DiffID": "sha256:9fb3aa2f8b8023a4bebbf92aa567caf88e38e969ada9f0ac12643b2847391635"
|
||||||
|
},
|
||||||
|
"SeveritySource": "nvd",
|
||||||
|
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-36159",
|
||||||
|
"DataSource": {
|
||||||
|
"ID": "alpine",
|
||||||
|
"Name": "Alpine Secdb",
|
||||||
|
"URL": "https://secdb.alpinelinux.org/"
|
||||||
|
},
|
||||||
|
"Description": "libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It does not check if the line ends prematurely. If it does, the for-loop condition checks for the '\\0' terminator one byte too late.",
|
||||||
|
"Severity": "CRITICAL",
|
||||||
|
"CweIDs": [
|
||||||
|
"CWE-125"
|
||||||
|
],
|
||||||
|
"CVSS": {
|
||||||
|
"nvd": {
|
||||||
|
"V2Vector": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
|
||||||
|
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
|
||||||
|
"V2Score": 6.4,
|
||||||
|
"V3Score": 9.1
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"References": [
|
||||||
|
"https://github.com/freebsd/freebsd-src/commits/main/lib/libfetch",
|
||||||
|
"https://gitlab.alpinelinux.org/alpine/apk-tools/-/issues/10749",
|
||||||
|
"https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E",
|
||||||
|
"https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E",
|
||||||
|
"https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E",
|
||||||
|
"https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E"
|
||||||
|
],
|
||||||
|
"PublishedDate": "2021-08-03T14:15:00Z",
|
||||||
|
"LastModifiedDate": "2021-10-18T12:19:00Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,91 @@
|
|||||||
|
#!/usr/bin/env bats
|
||||||
|
bats_load_library bats-support
|
||||||
|
bats_load_library bats-assert
|
||||||
|
bats_load_library bats-file
|
||||||
|
|
||||||
|
@test "trivy repo with securityCheck secret only" {
|
||||||
|
# trivy repo --format json --output repo.test --scanners=secret https://github.com/krol3/demo-trivy/
|
||||||
|
run ./entrypoint.sh '-b json' '-h repo.test' '-s secret' '-a repo' '-j https://github.com/krol3/demo-trivy/'
|
||||||
|
run diff repo.test ./test/data/repo.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal repo.test ./test/data/repo.test
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy image" {
|
||||||
|
# trivy image --severity CRITICAL --output image.test knqyf263/vuln-image:1.2.3
|
||||||
|
run ./entrypoint.sh '-a image' '-i knqyf263/vuln-image:1.2.3' '-h image.test' '-g CRITICAL'
|
||||||
|
run diff image.test ./test/data/image.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal image.test ./test/data/image.test
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy config sarif report" {
|
||||||
|
# trivy config --format sarif --output config-sarif.test .
|
||||||
|
run ./entrypoint.sh '-a config' '-b sarif' '-h config-sarif.test' '-j .'
|
||||||
|
run diff config-sarif.test ./test/data/config-sarif.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal config-sarif.test ./test/data/config-sarif.test
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy config" {
|
||||||
|
# trivy config --format json --output config.test .
|
||||||
|
run ./entrypoint.sh '-a config' '-b json' '-j .' '-h config.test'
|
||||||
|
run diff config.test ./test/data/config.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal config.test ./test/data/config.test
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy rootfs" {
|
||||||
|
# trivy rootfs --output rootfs.test .
|
||||||
|
run ./entrypoint.sh '-a rootfs' '-j .' '-h rootfs.test'
|
||||||
|
run diff rootfs.test ./test/data/rootfs.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal rootfs.test ./test/data/rootfs.test
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy fs" {
|
||||||
|
# trivy fs --output fs.test .
|
||||||
|
run ./entrypoint.sh '-a fs' '-j .' '-h fs.test'
|
||||||
|
run diff fs.test ./test/data/fs.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal fs.test ./test/data/fs.test
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy fs with securityChecks option" {
|
||||||
|
# trivy fs --format json --scanners=vuln,config --output fs-scheck.test .
|
||||||
|
run ./entrypoint.sh '-a fs' '-b json' '-j .' '-s vuln,config,secret' '-h fs-scheck.test'
|
||||||
|
run diff fs-scheck.test ./test/data/fs-scheck.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal fs-scheck.test ./test/data/fs-scheck.test
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
@test "trivy image with trivyIgnores option" {
|
||||||
|
# cat ./test/data/.trivyignore1 ./test/data/.trivyignore2 > ./trivyignores ; trivy image --severity CRITICAL --output image-trivyignores.test --ignorefile ./trivyignores knqyf263/vuln-image:1.2.3
|
||||||
|
run ./entrypoint.sh '-a image' '-i knqyf263/vuln-image:1.2.3' '-h image-trivyignores.test' '-g CRITICAL' '-t ./test/data/.trivyignore1,./test/data/.trivyignore2'
|
||||||
|
run diff image-trivyignores.test ./test/data/image-trivyignores.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal image-trivyignores.test ./test/data/image-trivyignores.test
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy image with sbom output" {
|
||||||
|
# trivy image --format github knqyf263/vuln-image:1.2.3
|
||||||
|
run ./entrypoint.sh "-a image" "-b github" "-i knqyf263/vuln-image:1.2.3"
|
||||||
|
assert_output --partial '"package_url": "pkg:apk/ca-certificates@20171114-r0",' # TODO: Output contains time, need to mock
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy image with trivy.yaml config" {
|
||||||
|
# trivy --config=./test/data/trivy.yaml image alpine:3.10
|
||||||
|
run ./entrypoint.sh "-v ./test/data/trivy.yaml" "-a image" "-i alpine:3.10"
|
||||||
|
run diff yamlconfig.test ./test/data/yamlconfig.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal yamlconfig.test ./test/data/yamlconfig.test
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "trivy image with trivy.yaml config and args" {
|
||||||
|
# trivy --config=./test/data/trivy-reduced.yaml image alpine:3.10
|
||||||
|
run ./entrypoint.sh "-v ./test/data/trivy-reduced.yaml" "-a image" "-i alpine:3.10" "-b json" "-g CRITICAL"
|
||||||
|
run diff yamlconfig.test ./test/data/yamlconfig.test
|
||||||
|
echo "$output"
|
||||||
|
assert_files_equal yamlconfig.test ./test/data/yamlconfig.test
|
||||||
|
}
|
||||||
+2
-2
@@ -7,7 +7,7 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-20.04
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v2
|
||||||
@@ -29,6 +29,6 @@ jobs:
|
|||||||
severity: 'CRITICAL,HIGH'
|
severity: 'CRITICAL,HIGH'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/upload-sarif@v1
|
uses: github/codeql-action/upload-sarif@v2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
|
|||||||
Reference in New Issue
Block a user