离线更新k8s环境下的trivy漏洞库方法 #25
Replies: 2 comments
-
后面我在本地安装trivy cli扫描镜像时如果镜像中有Jar文件,除了文中提到的漏洞库(Vulnerability db)外,还要有Java索引库(Java index db)
下载Java索引库: TRIVY_TEMP_DIR=$(mktemp -d)
docker run --rm -v $TRIVY_TEMP_DIR:/root/.cache/ aquasec/trivy image --download-java-db-only
tar -cf ./javadb.tar.gz -C $TRIVY_TEMP_DIR trivy/java-db
rm -rf $TRIVY_TEMP_DIR 漏洞库db文件和metadata.json放在 |
Beta Was this translation helpful? Give feedback.
0 replies
-
play-with-docker如果无法ssh登录,需要生成ed25519类型的密钥对
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
离线更新k8s环境下的trivy漏洞库方法
本文记录的是如何在离线环境下快速更新trivy.db,解决国内下载东西网络慢的问题,以及如何将文件拷贝进容器。这两个小技巧比较实用,以供未来参考。
https://ladybug.top/posts/CloudNative/update-trivy-vulnerability-library-in-offline-k8s-environment.html
Beta Was this translation helpful? Give feedback.
All reactions