fix(build): mirror the Trivy Java DB — jar-bearing builds failed closed at the scan gate (#72)

This commit is contained in:
Lemon-miaow committed 2026-09-24 03:11:01 +08:00
1 parent 6e47730501
commit b14bacbfc6
9 files changed
+77 -30

No files matched your search

+13 -5
View File
@@ -82,11 +82,16 @@ type JobParams struct {
// --db-repository flag). Empty keeps Trivy's own default; see
// build.Config.TrivyDBRepository for why an in-cluster install sets it.
TrivyDBRepository string
KanikoImage string
TrivyImage string
Deadline time.Duration
CPULimit string
MemLimit string
// TrivyJavaDBRepository overrides Trivy's Java-DB source (the
// --java-db-repository flag), fetched lazily when the image contains Java
// artifacts; empty keeps Trivy's own default, which the build egress lock
// denies — a jar-bearing image then fails the scan.
TrivyJavaDBRepository string
KanikoImage string
TrivyImage string
Deadline time.Duration
CPULimit string
MemLimit string
}
// BuildJobName is the deterministic Job name for a build id.
@@ -257,6 +262,9 @@ func BuildJob(p JobParams) (*batchv1.Job, error) {
if p.TrivyDBRepository != "" {
trivyArgs = append(trivyArgs, "--db-repository", p.TrivyDBRepository)
}
if p.TrivyJavaDBRepository != "" {
trivyArgs = append(trivyArgs, "--java-db-repository", p.TrivyJavaDBRepository)
}
trivyArgs = append(trivyArgs, p.ImageRef)
trivy := corev1.Container{
Name: ContainerTrivy,