-
Hello,
We're facing issues with the [Using Trivy to scan your Git repo](https://github.com/aquasecurity/trivy-action?tab=readme-ov-file#using-trivy-to-scan-your-git-repo) setup, the action is worki…
uRhos updated
2 weeks ago
-
### Skill Name
Snyk
### Why?
It's a popular code security and vulnerability scanning tool.
### Reference Image
![snyk-seeklogo com](https://user-images.githubusercontent.com/26021114/184650832-b…
-
I previously reported this behavior in https://github.com/goharbor/harbor/issues/15406, but the issue was close for being stale.
I'm sorry to say that the issue is still present under v2.9.0 (below…
-
### Description
A suggestion is to use [trivy](https://github.com/aquasecurity/trivy) it's free and works pretty well.
Running it locally like so: `trivy fs --severity HIGH,CRITICAL --exit-code …
-
**Describe the bug**
When it comes to vulnerability management documentation, we only talk about Trivy, which does "offline" scanning of images at rest in Harbor. But we also do "online" scanning o…
-
grype is reporting the installed consul version as v0.0.0, regardless of the actual version installed
Tested with a docker image which has consul v1.17.3 installed:
```
234156@mypod-0:/> /usr/bin…
-
### Describe what should be investigated or refactored
We should add continuous scanning of image dependencies in UDS Software Factory package repositories to check for both CVEs and license changes.…
-
# Summary
Propose to switch the official image from alpine based to [wolfi](https://github.com/wolfi-dev/os)-based image.
Wolfi is a distroless OS by Chainguard. Similar to Google's distroless p…
-
## Description
The translation functionality should be expanded to cover a wider spectrum of solutions.
Using the translation schema as a baseline:
```json
{
"target": [
"Platform 1",
"Plat…
-
### Task Topic
Other
### Task Description
Configure repository security and analysis using GitHub Secuirty Settings
## Tasks
- [ ] Private vulnerability reporting
- [ ] Dependency graph
- […