24
24
25
25
VERSION=${1}
26
26
GO_ARCH=" $( go env GOARCH) "
27
+ DB_MIRROR=" public.ecr.aws/aquasecurity/trivy-db"
27
28
28
29
REPO_ROOT=$( git rev-parse --show-toplevel)
29
30
" ${REPO_ROOT} /hack/ensure-trivy.sh" " ${VERSION} "
@@ -35,13 +36,13 @@ make REGISTRY=gcr.io/k8s-staging-cluster-api PULL_POLICY=IfNotPresent TAG=dev do
35
36
make clean-release-git
36
37
37
38
# Scan the images
38
- " ${TRIVY} " image -q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/clusterctl-" ${GO_ARCH} " :dev && R1=$? || R1=$?
39
- " ${TRIVY} " image -q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/test-extension-" ${GO_ARCH} " :dev && R2=$? || R2=$?
40
- " ${TRIVY} " image -q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/kubeadm-control-plane-controller-" ${GO_ARCH} " :dev && R3=$? || R3=$?
41
- " ${TRIVY} " image -q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/kubeadm-bootstrap-controller-" ${GO_ARCH} " :dev && R4=$? || R4=$?
42
- " ${TRIVY} " image -q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/cluster-api-controller-" ${GO_ARCH} " :dev && R5=$? || R5=$?
43
- " ${TRIVY} " image -q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/capd-manager-" ${GO_ARCH} " :dev && R6=$? || R6=$?
44
- " ${TRIVY} " image -q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/capim-manager-" ${GO_ARCH} " :dev && R7=$? || R7=$?
39
+ " ${TRIVY} " image --db-repository= " ${DB_MIRROR} " - q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/clusterctl-" ${GO_ARCH} " :dev && R1=$? || R1=$?
40
+ " ${TRIVY} " image --db-repository= " ${DB_MIRROR} " - q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/test-extension-" ${GO_ARCH} " :dev && R2=$? || R2=$?
41
+ " ${TRIVY} " image --db-repository= " ${DB_MIRROR} " - q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/kubeadm-control-plane-controller-" ${GO_ARCH} " :dev && R3=$? || R3=$?
42
+ " ${TRIVY} " image --db-repository= " ${DB_MIRROR} " - q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/kubeadm-bootstrap-controller-" ${GO_ARCH} " :dev && R4=$? || R4=$?
43
+ " ${TRIVY} " image --db-repository= " ${DB_MIRROR} " - q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/cluster-api-controller-" ${GO_ARCH} " :dev && R5=$? || R5=$?
44
+ " ${TRIVY} " image --db-repository= " ${DB_MIRROR} " - q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/capd-manager-" ${GO_ARCH} " :dev && R6=$? || R6=$?
45
+ " ${TRIVY} " image --db-repository= " ${DB_MIRROR} " - q --exit-code 1 --ignore-unfixed --severity MEDIUM,HIGH,CRITICAL gcr.io/k8s-staging-cluster-api/capim-manager-" ${GO_ARCH} " :dev && R7=$? || R7=$?
45
46
46
47
echo " "
47
48
BRed=' \033[1;31m'
0 commit comments