Skip to content

Commit

Permalink
Adapt old trivy function to new implementation; #136
Browse files Browse the repository at this point in the history
  • Loading branch information
robertauer committed Nov 28, 2024
1 parent e6736d9 commit f651b32
Showing 1 changed file with 4 additions and 18 deletions.
22 changes: 4 additions & 18 deletions vars/findVulnerabilitiesWithTrivy.groovy
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,8 @@ ArrayList call (Map args) {
if(args.containsKey('allowList'))
error "Arg allowList is deprecated, please use .trivyignore file"
def imageName = args.imageName
def trivyVersion = args.trivyVersion ? args.trivyVersion : '0.55.2'
def severityFlag = args.severity ? "--severity=${args.severity.join(',')}" : ''
def trivyVersion = args.trivyVersion ? args.trivyVersion : '0.57.1'
def severityFlag = args.severity ? "${args.severity.join(',')}" : ''
def additionalFlags = args.additionalFlags ? args.additionalFlags : ''
println(severityFlag)

Expand All @@ -27,7 +27,8 @@ ArrayList call (Map args) {

ArrayList getVulnerabilities(String trivyVersion, String severityFlag, String additionalFlags,String imageName) {
// this runs trivy and creates an output file with found vulnerabilities
runTrivyInDocker(trivyVersion, severityFlag, additionalFlags, imageName)
Trivy trivy = new Trivy(this, trivyVersion)
trivy.scanImage(imageName, severityFlag, TrivyScanStrategy.UNSTABLE, additionalFlags, "${env.WORKSPACE}/.trivy/trivyOutput.json")

def trivyOutput = readJSON file: "${env.WORKSPACE}/.trivy/trivyOutput.json"

Expand All @@ -42,21 +43,6 @@ ArrayList getVulnerabilities(String trivyVersion, String severityFlag, String ad

}




def runTrivyInDocker(String trivyVersion, severityFlag, additionalFlags, imageName) {
new Docker(this).image("aquasec/trivy:${trivyVersion}")
.mountJenkinsUser()
.mountDockerSocket()
.inside("-v ${env.WORKSPACE}/.trivy/.cache:/root/.cache/") {

sh "trivy image -f json -o .trivy/trivyOutput.json ${severityFlag} ${additionalFlags} ${imageName}"
}
}



static boolean validateArgs(Map args) {
return !(args == null || args.imageName == null || args.imageName == '')
}

0 comments on commit f651b32

Please sign in to comment.