Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trivy integration #30

Merged
merged 39 commits into from
Oct 30, 2023
Merged

Trivy integration #30

merged 39 commits into from
Oct 30, 2023

Conversation

bomoko
Copy link
Contributor

@bomoko bomoko commented Sep 26, 2023

This PR introduces post SBOM generation processing.

In order to run trivy scans against incoming sboms one needs to ensure that PROBLEMS_FROM_SBOM=true and TRIVY_SERVER_ENDPOINT points to the address of a trivy server

This will then take any incoming SBOMS from insights remote, run them against the Trivy DB, and write any problems to the Lagoon Problems API for the target environment.

@bomoko bomoko requested a review from shreddedbacon October 23, 2023 20:11
@bomoko bomoko merged commit 8e13c64 into main Oct 30, 2023
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant