| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Testing against a recent version of the juiceshop from dockerhub Signed-off-by: Sebastian <sebastian.franz@iteratec.com>
Signed-off-by: Sebastian <sebastian.franz@iteratec.com>
Signed-off-by: Sebastian <sebastian.franz@iteratec.com>
There was a problem hiding this comment.
I'm not quite sure how volatile this test is because of new discovered vulnerabilities. What do you think @J12934 , @rseedorff ?
Sorry, something went wrong.
|
Yeah good point, might be better to have it be a "at least this amount of findings" check, as its bound to go up in the future. |
Sorry, something went wrong.
This should ensure a more stable test result due to the older version Signed-off-by: Sebastian <sebastian.franz@iteratec.com>
This will not let the tests failed when new vulnerabilities are found Signed-off-by: Sebastian <sebastian.franz@iteratec.com>
| Back | FazBrowse Home | New Git URL |
Description
Upon merging, this PR will add integration tests for the trivy security scanner.
This will close #623.
Contrary to what has been discussed there, downloading the database for trivy during the integration tests does not seem to be an issue. The tests took only about 35s.
Successful download of the database has also been stated in the trivy logs.
If the tests prove to be unstable, however, it could be considered to add an offline version of the trivy database as described here. This would pose the need for a scanner dockerfile created by us instead of the official image, where a version of the database would be included. Integration tests could be run with the "--skip-update" flag afterwards.
Checklist