File tree Expand file tree Collapse file tree 2 files changed +3
-6
lines changed Expand file tree Collapse file tree 2 files changed +3
-6
lines changed Original file line number Diff line number Diff line change 7
7
# keystone_allowed_vulnerabilities:
8
8
# - CVE-2022-2447
9
9
#
10
- # barbican-api_allowed_vulnerabilities :
10
+ # barbican_api_allowed_vulnerabilities :
11
11
# - CVE-2023-31047
12
12
13
13
global_allowed_vulnerabilities :
Original file line number Diff line number Diff line change @@ -34,18 +34,15 @@ touch image-scan-output/clean-images.txt image-scan-output/dirty-images.txt
34
34
# generate a csv summary
35
35
for image in $images ; do
36
36
filename=$( basename $image | sed ' s/:/\./g' )
37
- imagename=$( echo $filename | cut -d " ." -f 1)
37
+ imagename=$( echo $filename | cut -d " ." -f 1 | sed ' s/-/_/g ' )
38
38
global_vulnerabilities=$( yq .global_allowed_vulnerabilities[] src/kayobe-config/etc/kayobe/trivy/allowed-vulnerabilities.yml)
39
39
image_vulnerabilities=$( yq .$imagename ' _allowed_vulnerabilities[]' src/kayobe-config/etc/kayobe/trivy/allowed-vulnerabilities.yml)
40
- rc=$?
41
40
touch .trivyignore
42
41
for vulnerability in $global_vulnerabilities ; do
43
42
echo $vulnerability >> .trivyignore
44
43
done
45
44
for vulnerability in $image_vulnerabilities ; do
46
- if [ $rc -eq 0 ]; then
47
- echo $vulnerability >> .trivyignore
48
- fi
45
+ echo $vulnerability >> .trivyignore
49
46
done
50
47
if $( trivy image \
51
48
--quiet \
You can’t perform that action at this time.
0 commit comments