Skip to content

Commit

Permalink
Bump trivy to resolve CVEs
Browse files Browse the repository at this point in the history
  • Loading branch information
sfowl committed Oct 9, 2024
1 parent 2c1c1b6 commit d30249c
Showing 1 changed file with 2 additions and 6 deletions.
8 changes: 2 additions & 6 deletions containerize/Containerfile
Original file line number Diff line number Diff line change
Expand Up @@ -26,11 +26,6 @@ RUN mkdir -p /opt/firefox /tmp/firefox && \
RUN curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" && \
install -o root -g root -m 0755 kubectl /usr/local/bin/kubectl

## Trivy (https://github.com/aquasecurity/trivy/)
# Use install.sh to easily specify a particular version & implicitely verify integrity
RUN curl -LO --create-dirs --output-dir /tmp/trivy/ https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh && \
bash /tmp/trivy/install.sh -b /tmp/trivy/ v0.49.1

## redocly (https://github.com/Redocly/redocly-cli)
RUN mkdir -p /tmp/redocly/node_modules && npm install --prefix /tmp/redocly @redocly/[email protected]

Expand All @@ -40,9 +35,10 @@ FROM registry.access.redhat.com/ubi9-minimal
COPY --from=deps /opt/zap /opt/zap
COPY --from=deps /opt/firefox /opt/firefox
COPY --from=deps /usr/local/bin/kubectl /usr/local/bin/kubectl
COPY --from=deps /tmp/trivy/trivy /usr/local/bin/trivy
COPY --from=deps /tmp/redocly/node_modules /opt/redocly/node_modules

RUN rpm -ivh https://github.com/aquasecurity/trivy/releases/download/v0.54.1/trivy_0.54.1_Linux-64bit.rpm

ENV PATH $PATH:/opt/zap/:/opt/rapidast/:/opt/firefox/

## RapiDAST
Expand Down

0 comments on commit d30249c

Please sign in to comment.