trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Backend: pants.backend.experimental.helm.lint.trivy
Config section: [trivy]
Basic options
args
--trivy-args="[<shell_str>, <shell_str>, ...]"PANTS_TRIVY_ARGS[trivy]
args = [
<shell_str>,
<shell_str>,
...,
]
[]Arguments to pass directly to Trivy, e.g. --trivy-args='--scanners vuln'.
severity
--trivy-severity="['<str>', '<str>', ...]"PANTS_TRIVY_SEVERITY[trivy]
severity = [
'<str>',
'<str>',
...,
]
[]Severities of security issues to be displayed (UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL)
skip
--[no-]trivy-skipPANTS_TRIVY_SKIP[trivy]
skip = <bool>
FalseIf true, don't use Trivy when running pants lint.
Advanced options
config
--trivy-config=<file_option>PANTS_TRIVY_CONFIG[trivy]
config = <file_option>
NonePath to the Trivy config file.
Setting this option will disable config discovery for the config file. Use this option if the config is located in a non-standard location.
config_discovery
--[no-]trivy-config-discoveryPANTS_TRIVY_CONFIG_DISCOVERY[trivy]
config_discovery = <bool>
TrueIf true, Pants will include all relevant config files during runs.
Use [trivy].config instead if your config is in a non-standard location
extra_env_vars
--trivy-extra-env-vars="['<str>', '<str>', ...]"PANTS_TRIVY_EXTRA_ENV_VARS[trivy]
extra_env_vars = [
'<str>',
'<str>',
...,
]
[]Additional environment variables that would be made available to all Terraform processes.
known_versions
--trivy-known-versions="['<str>', '<str>', ...]"PANTS_TRIVY_KNOWN_VERSIONS[trivy]
known_versions = [
'<str>',
'<str>',
...,
]
[ "0.69.2|linux_arm64 |c73b97699c317b0d25532b3f188564b4e29d13d5472ce6f8eb078082546a6481|43702248", "0.69.2|linux_x86_64|affa59a1e37d86e4b8ab2cd02f0ab2e63d22f1bf9cf6a7aa326c884e25e26ce3|48327305", "0.69.2|macos_arm64 |320c0e6af90b5733b9326da0834240e944c6f44091e50019abdf584237ff4d0c|45881045", "0.69.2|macos_x86_64|41f6eac3ebe3a00448a16f08038b55ce769fe2d5128cb0d64bdf282cdad4831a|49275481" ]
Known versions to verify downloads against.
Each element is a pipe-separated string of version|platform|sha256|length or
version|platform|sha256|length|url_override, where:
versionis the version stringplatformis one of[linux_arm64,linux_x86_64,macos_arm64,macos_x86_64]sha256is the 64-character hex representation of the expected sha256 digest of the download file, as emitted byshasum -a 256lengthis the expected length of the download file in bytes, as emitted bywc -c- (Optional)
url_overrideis a specific url to use instead of the normally generated url for this version
E.g., 3.1.2|macos_x86_64|6d0f18cd84b918c7b3edd0203e75569e0c7caecb1367bbbe409b44e28514f5be|42813.
and 3.1.2|macos_arm64 |aca5c1da0192e2fd46b7b55ab290a92c5f07309e7b0ebf4e45ba95731ae98291|50926|https://example.mac.org/bin/v3.1.2/mac-aarch64-v3.1.2.tgz.
Values are space-stripped, so pipes can be indented for readability if necessary.
url_platform_mapping
--trivy-url-platform-mapping="{'key1': val1, 'key2': val2, ...}"PANTS_TRIVY_URL_PLATFORM_MAPPING[trivy.url_platform_mapping]
key1 = val1
key2 = val2
...
{
"linux_arm64": "Linux-ARM64",
"linux_x86_64": "Linux-64bit",
"macos_arm64": "macOS-ARM64",
"macos_x86_64": "macOS-64bit"
}A dictionary mapping platforms to strings to be used when generating the URL to download the tool.
In --url-template, anytime the {platform} string is used, Pants will determine the current platform, and substitute {platform} with the respective value from your dictionary.
For example, if you define {"macos_x86_64": "apple-darwin", "linux_x86_64": "unknown-linux"}, and run Pants on Linux with an intel architecture, then {platform} will be substituted in the --url-template option with unknown-linux.
url_template
--trivy-url-template=<str>PANTS_TRIVY_URL_TEMPLATE[trivy]
url_template = <str>
https://github.com/aquasecurity/trivy/releases/download/v{version}/trivy_{version}_{platform}.tar.gzURL to download the tool, either as a single binary file or a compressed file (e.g. zip file). You can change this to point to your own hosted file, e.g. to work with proxies or for access via the filesystem through a file:$abspath URL (e.g. file:/this/is/absolute, possibly by templating the buildroot in a config file).
Use {version} to have the value from --version substituted, and {platform} to have a value from --url-platform-mapping substituted in, depending on the current platform. For example, https://github.com/.../protoc-{version}-{platform}.zip.
use_unsupported_version
--trivy-use-unsupported-version=<UnsupportedVersionUsage>PANTS_TRIVY_USE_UNSUPPORTED_VERSION[trivy]
use_unsupported_version = <UnsupportedVersionUsage>
error, warningdefault:
errorWhat action to take in case the requested version of Trivy is not supported.
Supported Trivy versions: unspecified
version
--trivy-version=<str>PANTS_TRIVY_VERSION[trivy]
version = <str>
0.69.2Use this version of Trivy.
Deprecated options
None
Related subsystems
None