Skip to content

Conversation

@droguljic
Copy link
Contributor

The command scans Docker image for vulnerabilities and secrets. Under the hood uses Grype for the vulnerability scan and Trivy for the secret scan.
Sources image from the Docker daemon of the tarball file from disk.

The command scans Docker image for vulnerabilities and secrets.
Under the hood uses Grype for the vulnerability scan and Trivy
for the secret scan.
Sources image from the Docker daemon of the tarball file from disk.
@droguljic droguljic self-assigned this May 22, 2025
@droguljic droguljic merged commit 34505ef into master May 22, 2025
20 checks passed
@droguljic droguljic deleted the feat/assess-image branch May 22, 2025 14:54
droguljic added a commit that referenced this pull request May 22, 2025
The command scans Docker image for vulnerabilities and secrets.
Under the hood uses Grype for the vulnerability scan and Trivy
for the secret scan.
Sources image from the Docker daemon of the tarball file from disk.
@droguljic droguljic changed the title feat: add "assess_image" command feat: add assess_image command May 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants