fix(build): mirror the Trivy Java DB — jar-bearing builds failed closed at the scan gate (#72)
This commit is contained in:
9 files changed
+77
-30
No files matched your search
@@ -82,11 +82,16 @@ type JobParams struct {
|
||||
// --db-repository flag). Empty keeps Trivy's own default; see
|
||||
// build.Config.TrivyDBRepository for why an in-cluster install sets it.
|
||||
TrivyDBRepository string
|
||||
KanikoImage string
|
||||
TrivyImage string
|
||||
Deadline time.Duration
|
||||
CPULimit string
|
||||
MemLimit string
|
||||
// TrivyJavaDBRepository overrides Trivy's Java-DB source (the
|
||||
// --java-db-repository flag), fetched lazily when the image contains Java
|
||||
// artifacts; empty keeps Trivy's own default, which the build egress lock
|
||||
// denies — a jar-bearing image then fails the scan.
|
||||
TrivyJavaDBRepository string
|
||||
KanikoImage string
|
||||
TrivyImage string
|
||||
Deadline time.Duration
|
||||
CPULimit string
|
||||
MemLimit string
|
||||
}
|
||||
|
||||
// BuildJobName is the deterministic Job name for a build id.
|
||||
@@ -257,6 +262,9 @@ func BuildJob(p JobParams) (*batchv1.Job, error) {
|
||||
if p.TrivyDBRepository != "" {
|
||||
trivyArgs = append(trivyArgs, "--db-repository", p.TrivyDBRepository)
|
||||
}
|
||||
if p.TrivyJavaDBRepository != "" {
|
||||
trivyArgs = append(trivyArgs, "--java-db-repository", p.TrivyJavaDBRepository)
|
||||
}
|
||||
trivyArgs = append(trivyArgs, p.ImageRef)
|
||||
trivy := corev1.Container{
|
||||
Name: ContainerTrivy,
|
||||
|
||||
Reference in new issue
Block a user