File tree Expand file tree Collapse file tree 20 files changed +659
-103
lines changed
Expand file tree Collapse file tree 20 files changed +659
-103
lines changed Original file line number Diff line number Diff line change 2020 - docker scout recommendations
2121 - docker scout repo
2222 - docker scout version
23+ - docker scout vex
2324 - docker scout watch
2425clink :
2526 - docker_scout_attestation.yaml
3738 - docker_scout_recommendations.yaml
3839 - docker_scout_repo.yaml
3940 - docker_scout_version.yaml
41+ - docker_scout_vex.yaml
4042 - docker_scout_watch.yaml
4143options :
4244 - option : debug
Original file line number Diff line number Diff line change 11command : docker scout attestation
22aliases : docker scout attestation, docker scout attest
3- short : Manage attestations on image indexes
4- long : Manage attestations on image indexes
3+ short : Manage attestations on images
4+ long : Manage attestations on images
55pname : docker scout
66plink : docker_scout.yaml
77cname :
88 - docker scout attestation add
9+ - docker scout attestation get
10+ - docker scout attestation list
911clink :
1012 - docker_scout_attestation_add.yaml
13+ - docker_scout_attestation_get.yaml
14+ - docker_scout_attestation_list.yaml
1115inherited_options :
1216 - option : debug
1317 value_type : bool
Original file line number Diff line number Diff line change 1+ command : docker scout attestation get
2+ aliases : docker scout attestation get, docker scout attest get
3+ short : Get attestation for image
4+ long : The docker scout attestation get command gets attestations for images.
5+ usage : docker scout attestation get OPTIONS IMAGE [DIGEST]
6+ pname : docker scout attestation
7+ plink : docker_scout_attestation.yaml
8+ options :
9+ - option : key
10+ value_type : string
11+ default_value : https://registry.scout.docker.com/keyring/dhi/latest.pub
12+ description : Signature key to use for verification
13+ deprecated : false
14+ hidden : false
15+ experimental : false
16+ experimentalcli : false
17+ kubernetes : false
18+ swarm : false
19+ - option : org
20+ value_type : string
21+ description : Namespace of the Docker organization
22+ deprecated : false
23+ hidden : false
24+ experimental : false
25+ experimentalcli : false
26+ kubernetes : false
27+ swarm : false
28+ - option : output
29+ shorthand : o
30+ value_type : string
31+ description : Write the report to a file
32+ deprecated : false
33+ hidden : false
34+ experimental : false
35+ experimentalcli : false
36+ kubernetes : false
37+ swarm : false
38+ - option : platform
39+ value_type : string
40+ description : Platform of image to analyze
41+ deprecated : false
42+ hidden : false
43+ experimental : false
44+ experimentalcli : false
45+ kubernetes : false
46+ swarm : false
47+ - option : predicate
48+ value_type : bool
49+ default_value : " false"
50+ description : Get in-toto predicate only dropping the subject
51+ deprecated : false
52+ hidden : false
53+ experimental : false
54+ experimentalcli : false
55+ kubernetes : false
56+ swarm : false
57+ - option : predicate-type
58+ value_type : string
59+ description : Predicate-type for attestation
60+ deprecated : false
61+ hidden : false
62+ experimental : false
63+ experimentalcli : false
64+ kubernetes : false
65+ swarm : false
66+ - option : ref
67+ value_type : string
68+ description : |-
69+ Reference to use if the provided tarball contains multiple references.
70+ Can only be used with archive
71+ deprecated : false
72+ hidden : false
73+ experimental : false
74+ experimentalcli : false
75+ kubernetes : false
76+ swarm : false
77+ - option : skip-tlog
78+ value_type : bool
79+ default_value : " false"
80+ description : Skip signature verification against public transaction log
81+ deprecated : false
82+ hidden : false
83+ experimental : false
84+ experimentalcli : false
85+ kubernetes : false
86+ swarm : false
87+ - option : verify
88+ value_type : bool
89+ default_value : " false"
90+ description : Verify the signature on the attestation
91+ deprecated : false
92+ hidden : false
93+ experimental : false
94+ experimentalcli : false
95+ kubernetes : false
96+ swarm : false
97+ inherited_options :
98+ - option : debug
99+ value_type : bool
100+ default_value : " false"
101+ description : Debug messages
102+ deprecated : false
103+ hidden : true
104+ experimental : false
105+ experimentalcli : false
106+ kubernetes : false
107+ swarm : false
108+ - option : verbose-debug
109+ value_type : bool
110+ default_value : " false"
111+ description : Verbose debug
112+ deprecated : false
113+ hidden : true
114+ experimental : false
115+ experimentalcli : false
116+ kubernetes : false
117+ swarm : false
118+ deprecated : false
119+ experimental : false
120+ experimentalcli : true
121+ kubernetes : false
122+ swarm : false
123+
Original file line number Diff line number Diff line change 1+ command : docker scout attestation list
2+ aliases : docker scout attestation list, docker scout attest list
3+ short : List attestations for image
4+ long : The docker scout attestation list command lists attestations for images.
5+ usage : docker scout attestation list OPTIONS IMAGE
6+ pname : docker scout attestation
7+ plink : docker_scout_attestation.yaml
8+ options :
9+ - option : format
10+ value_type : string
11+ default_value : list
12+ description : |-
13+ Output format:
14+ - list: list of attestations of the image
15+ - json: json representation of the attestation list (default "json")
16+ deprecated : false
17+ hidden : false
18+ experimental : false
19+ experimentalcli : false
20+ kubernetes : false
21+ swarm : false
22+ - option : org
23+ value_type : string
24+ description : Namespace of the Docker organization
25+ deprecated : false
26+ hidden : false
27+ experimental : false
28+ experimentalcli : false
29+ kubernetes : false
30+ swarm : false
31+ - option : output
32+ shorthand : o
33+ value_type : string
34+ description : Write the report to a file
35+ deprecated : false
36+ hidden : false
37+ experimental : false
38+ experimentalcli : false
39+ kubernetes : false
40+ swarm : false
41+ - option : platform
42+ value_type : string
43+ description : Platform of image to analyze
44+ deprecated : false
45+ hidden : false
46+ experimental : false
47+ experimentalcli : false
48+ kubernetes : false
49+ swarm : false
50+ - option : predicate-type
51+ value_type : string
52+ description : Predicate-type for attestations
53+ deprecated : false
54+ hidden : false
55+ experimental : false
56+ experimentalcli : false
57+ kubernetes : false
58+ swarm : false
59+ - option : ref
60+ value_type : string
61+ description : |-
62+ Reference to use if the provided tarball contains multiple references.
63+ Can only be used with archive
64+ deprecated : false
65+ hidden : false
66+ experimental : false
67+ experimentalcli : false
68+ kubernetes : false
69+ swarm : false
70+ inherited_options :
71+ - option : debug
72+ value_type : bool
73+ default_value : " false"
74+ description : Debug messages
75+ deprecated : false
76+ hidden : true
77+ experimental : false
78+ experimentalcli : false
79+ kubernetes : false
80+ swarm : false
81+ - option : verbose-debug
82+ value_type : bool
83+ default_value : " false"
84+ description : Verbose debug
85+ deprecated : false
86+ hidden : true
87+ experimental : false
88+ experimentalcli : false
89+ kubernetes : false
90+ swarm : false
91+ deprecated : false
92+ experimental : false
93+ experimentalcli : true
94+ kubernetes : false
95+ swarm : false
96+
Original file line number Diff line number Diff line change @@ -95,6 +95,17 @@ options:
9595 experimentalcli : false
9696 kubernetes : false
9797 swarm : false
98+ - option : ignore-suppressed
99+ value_type : bool
100+ default_value : " false"
101+ description : |
102+ Filter CVEs found in Scout exceptions based on the specified exception scope
103+ deprecated : false
104+ hidden : false
105+ experimental : false
106+ experimentalcli : false
107+ kubernetes : false
108+ swarm : false
98109 - option : ignore-unchanged
99110 value_type : bool
100111 default_value : " false"
@@ -177,6 +188,16 @@ options:
177188 experimentalcli : false
178189 kubernetes : false
179190 swarm : false
191+ - option : only-vex-affected
192+ value_type : bool
193+ default_value : " false"
194+ description : Filter CVEs by VEX statements with status not affected
195+ deprecated : false
196+ hidden : false
197+ experimental : false
198+ experimentalcli : false
199+ kubernetes : false
200+ swarm : false
180201 - option : org
181202 value_type : string
182203 description : Namespace of the Docker organization
@@ -264,6 +285,36 @@ options:
264285 experimentalcli : false
265286 kubernetes : false
266287 swarm : false
288+ - option : vex
289+ value_type : bool
290+ default_value : " false"
291+ description : Apply VEX statements to filter CVEs
292+ deprecated : true
293+ hidden : true
294+ experimental : false
295+ experimentalcli : false
296+ kubernetes : false
297+ swarm : false
298+ - option : vex-author
299+ value_type : stringSlice
300+ default_value : ' [<.*@docker.com>]'
301+ description : List of VEX statement authors to accept
302+ deprecated : false
303+ hidden : false
304+ experimental : false
305+ experimentalcli : false
306+ kubernetes : false
307+ swarm : false
308+ - option : vex-location
309+ value_type : stringSlice
310+ default_value : ' []'
311+ description : File location of directory or file containing VEX statements
312+ deprecated : false
313+ hidden : false
314+ experimental : false
315+ experimentalcli : false
316+ kubernetes : false
317+ swarm : false
267318inherited_options :
268319 - option : debug
269320 value_type : bool
Original file line number Diff line number Diff line change @@ -359,7 +359,7 @@ options:
359359 swarm : false
360360 - option : vex-author
361361 value_type : stringSlice
362- default_value : ' []'
362+ default_value : ' [<.*@docker.com> ]'
363363 description : List of VEX statement authors to accept
364364 deprecated : false
365365 hidden : false
Original file line number Diff line number Diff line change @@ -147,7 +147,7 @@ options:
147147 swarm : false
148148 - option : vex-author
149149 value_type : stringSlice
150- default_value : ' []'
150+ default_value : ' [<.*@docker.com> ]'
151151 description : List of VEX statement authors to accept
152152 deprecated : false
153153 hidden : false
Original file line number Diff line number Diff line change 1+ command : docker scout vex
2+ aliases : docker scout vex, docker scout vex
3+ short : Manage VEX attestations on images
4+ long : Manage VEX attestations on images
5+ pname : docker scout
6+ plink : docker_scout.yaml
7+ cname :
8+ - docker scout vex get
9+ clink :
10+ - docker_scout_vex_get.yaml
11+ inherited_options :
12+ - option : debug
13+ value_type : bool
14+ default_value : " false"
15+ description : Debug messages
16+ deprecated : false
17+ hidden : true
18+ experimental : false
19+ experimentalcli : false
20+ kubernetes : false
21+ swarm : false
22+ - option : verbose-debug
23+ value_type : bool
24+ default_value : " false"
25+ description : Verbose debug
26+ deprecated : false
27+ hidden : true
28+ experimental : false
29+ experimentalcli : false
30+ kubernetes : false
31+ swarm : false
32+ deprecated : false
33+ experimental : false
34+ experimentalcli : true
35+ kubernetes : false
36+ swarm : false
37+
You can’t perform that action at this time.
0 commit comments