Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/fluent-ci-templates/grype-pipeline
A ready-to-use CI/CD Pipeline for scanning vulnerabilities in your project with Grype.
https://github.com/fluent-ci-templates/grype-pipeline
Last synced: about 6 hours ago
JSON representation
A ready-to-use CI/CD Pipeline for scanning vulnerabilities in your project with Grype.
- Host: GitHub
- URL: https://github.com/fluent-ci-templates/grype-pipeline
- Owner: fluent-ci-templates
- License: mit
- Created: 2023-09-22T16:04:55.000Z (about 1 year ago)
- Default Branch: main
- Last Pushed: 2024-06-18T20:10:27.000Z (5 months ago)
- Last Synced: 2024-07-24T01:02:22.463Z (4 months ago)
- Language: TypeScript
- Homepage:
- Size: 148 KB
- Stars: 1
- Watchers: 1
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- Contributing: CONTRIBUTING.md
- License: LICENSE
- Code of conduct: CODE_OF_CONDUCT.md
Awesome Lists containing this project
README
# Grype Pipeline
[![fluentci pipeline](https://shield.fluentci.io/x/grype_pipeline)](https://pkg.fluentci.io/grype_pipeline)
![deno compatibility](https://shield.deno.dev/deno/^1.41)
[![dagger-min-version](https://shield.fluentci.io/dagger/v0.11.7)](https://dagger.io)
[![](https://jsr.io/badges/@fluentci/grype)](https://jsr.io/@fluentci/grype)
[![](https://img.shields.io/codecov/c/gh/fluent-ci-templates/grype-pipeline)](https://codecov.io/gh/fluent-ci-templates/grype-pipeline)
[![ci](https://github.com/fluent-ci-templates/grype-pipeline/actions/workflows/ci.yml/badge.svg)](https://github.com/fluent-ci-templates/grype-pipeline/actions/workflows/ci.yml)A ready-to-use CI/CD Pipeline for scanning vulnerabilities in your project with Grype.
## 🚀 Usage
Run the following command:
```bash
fluentci run grype_pipeline
```Or, if you want to use it as a template:
```bash
fluentci init -t grype
```This will create a `.fluentci` folder in your project.
Now you can run the pipeline with:
```bash
fluentci run .
```## 🧩 Dagger Module
Use as a [Dagger](https://dagger.io) Module:
```bash
dagger install github.com/fluent-ci-templates/grype-pipeline@main
```Call a function from the module:
```bash
dagger call scan --image hashicorp/terraform:1.6 --fail-on critical
```## 🛠️ Environment variables
| Variable | Description |
| ----------------------- | ------------------------------------------------- |
| GRYPE_IMAGE | The image to scan |
| GRYPE_DIR | The directory to scan |
| GRYPE_SBOM | The SBOM file to scan |
| GRYPE_VERSION | The version of Grype to use. Defaults to `latest` |
| GRYPE_FAIL_ON | Set the return code to 1 if a vulnerability is found with a severity >= the given severity. Possible values: `negligible`, `low`, `medium`, `high`, `critical` |## ✨ Jobs
| Job | Description |
| -------- | ---------------------------- |
| scan | Scan for vulnerabilities |```typescript
scan(
src: Directory | string,
image?: string,
failOn?: string
): Promise
```## 👨💻 Programmatic usage
You can also use this pipeline programmatically:
```ts
import { scan } from "jsr:@fluentci/grype";await scan(".");
```