Comments (8)
This has been published as ovotech/[email protected]
.
from circleci-orbs.
It works for me. Do you have a circleci config and logs you can share?
from circleci-orbs.
Hi, we're not doing to much fancy, but we are using a private repository.
jobs:
container_vulnerability_scan:
executor: clair/default
steps:
- checkout
- attach_workspace:
at: .
- run: *gcp-docker-login
- clair/scan:
image_file: "./gcr.image.version"
where the ./gcr.image.version contains the full /<repo>/<project>/<repo>:<tag>
. The default file path is really not a path that would normally be available in a normal linux installation - where does the report go in your testing?
from circleci-orbs.
The report gets stored as a circleci artifact. Do you also need to read it from the filesystem?
from circleci-orbs.
I have made a change so clair reports will be saved at /clair-reports/<image_name>.json
inside the build container (They will also be uploaded as circleci artifacts at the same path).
The image name includes any custom registry, e.g. /clair-reports/361339499037.dkr.ecr.eu-west-1.amazonaws.com/pe-orbs:latest
.
Can you test if this works for your use case using orb version ovotech/clair-scanner@dev:report-path-fix
?
from circleci-orbs.
@danielflookovo it now works. We would be okey with a static filename, probably we'd just parse and post the result to slack or something like that. Would it be possible to support the input parameter though, with the current functionality as the default?
from circleci-orbs.
The specified image_file
can have multiple images listed, each with a separate report. A static filename doesn't make much sense there.
from circleci-orbs.
@danielflookovo ok, I see your point.
from circleci-orbs.
Related Issues (20)
- Terraform Orb - Provide a working directory parameter HOT 1
- Terraform Orb - Allow multiple var_file parameters HOT 3
- [terraform] Support lock-timeout option HOT 1
- [terraform] Support arbitrary arguments HOT 2
- [terraform] terrraform/apply doesn't work if no github credentials set and auto-approve is set to false
- [terraform] No error on failed github comment
- Dockerhub authentication
- Make "out" param optional
- Init/apply is broken for remote backends HOT 1
- terraform version check fails for TF 0.13.5 HOT 2
- Update terraform orb for 0.14 HOT 2
- ovotech/[email protected] issue HOT 1
- Terraform Orb: Github comment contains logs of refreshing state HOT 4
- terraform/default executor: Refreshing state included in plan HOT 1
- ovotech/terraform-v2@2 being broken HOT 4
- Please help with example config for Azure remote backend
- helm-ci support for dependencies
- Plan comparison fails for move actions HOT 1
- Authenticate with GCP with OIDC token
- optionally specify fmt-check step name
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from circleci-orbs.