Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
#1838 Use trivy to generate CycloneDX SBOMs
Add a new ScanType to trivy, that allows generating CycloneDX SBOMs from
container images. This is part of work to integrate an SBOM workflow
into the secureCodeBox. At the moment the SBOMs are only generated and
uploaded to storage, nothing else happens to them.

Note that this is a different result type than the other trivy scans,
this uses "sbom-cyclonedx", therefore the normal trivy parser will not
run for these scans.

Signed-off-by: Lukas Fischer <lukas.fischer@iteratec.com>
  • Loading branch information
Lukas Fischer
Lukas Fischer committed Sep 18, 2023
commit 2ad6589bf4726fe9e33fbc233c73441ce223069e
7 changes: 7 additions & 0 deletions scanners/trivy/examples/image-sbom-juice-shop/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
<!--
SPDX-FileCopyrightText: the secureCodeBox authors

SPDX-License-Identifier: Apache-2.0
-->

This example shows how to generate a CycloneDX SBOM from a container image using the `trivy image` scanner with CycloneDX output with the secureCodeBox.
12 changes: 12 additions & 0 deletions scanners/trivy/examples/image-sbom-juice-shop/scan.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# SPDX-FileCopyrightText: the secureCodeBox authors
#
# SPDX-License-Identifier: Apache-2.0

apiVersion: "execution.securecodebox.io/v1"
kind: Scan
metadata:
name: "trivy-image-sbom-juice-shop"
spec:
scanType: "trivy-image-sbom"
parameters:
- "bkimminich/juice-shop:v15.0.0"
52 changes: 51 additions & 1 deletion scanners/trivy/templates/trivy-scan-type.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -297,4 +297,54 @@ spec:
serviceAccountName: trivy-k8s
volumes:
{{- toYaml .Values.scanner.extraVolumes | nindent 12 }}

---
apiVersion: "execution.securecodebox.io/v1"
kind: ScanType
metadata:
name: "trivy-image-sbom{{ .Values.scanner.nameAppend | default ""}}"
spec:
extractResults:
type: sbom-cyclonedx
Comment thread
o1oo11oo marked this conversation as resolved.
Outdated
location: "/home/securecodebox/sbom-cyclonedx.json"
jobTemplate:
spec:
{{- if .Values.scanner.ttlSecondsAfterFinished }}
ttlSecondsAfterFinished: {{ .Values.scanner.ttlSecondsAfterFinished }}
{{- end }}
backoffLimit: {{ .Values.scanner.backoffLimit }}
{{- if .Values.scanner.activeDeadlineSeconds }}
activeDeadlineSeconds: {{ .Values.scanner.activeDeadlineSeconds }}
{{- end }}
template:
spec:
restartPolicy: OnFailure
affinity:
{{- toYaml .Values.scanner.affinity | nindent 12 }}
tolerations:
{{- toYaml .Values.scanner.tolerations | nindent 12 }}
containers:
- name: trivy
image: "{{ .Values.scanner.image.repository }}:{{ .Values.scanner.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.scanner.image.pullPolicy }}
command:
- "trivy"
- "image"
# Suppress progress bar, as it pollutes non interactive terminal logs
- "--no-progress"
- "--format"
- "cyclonedx"
- "--output"
- "/home/securecodebox/sbom-cyclonedx.json"
resources:
{{- toYaml .Values.scanner.resources | nindent 16 }}
securityContext:
{{- toYaml .Values.scanner.securityContext | nindent 16 }}
env:
{{- toYaml .Values.scanner.env | nindent 16 }}
volumeMounts:
{{- toYaml .Values.scanner.extraVolumeMounts | nindent 16 }}
{{- if .Values.scanner.extraContainers }}
{{- toYaml .Values.scanner.extraContainers | nindent 12 }}
{{- end }}
volumes:
{{- toYaml .Values.scanner.extraVolumes | nindent 12 }}