Known to work with Dagger v0.9.5 and v0.9.8.
Check containers for vulnerabilities using Grype from your Dagger pipelines.
Check the given container image for vulnerabilities:
dagger call -m github.com/lukemarsden/dagger-grype test-container-image --image "alpine:latest"
Call the TestContainer
method on this module with your container object (e.g. *Container
in golang) as the only argument.
This allows you to test a container without first pushing it to a container registry.
Internally, this module exports the container image as a tarball and passes that tarball to grype.