Skip to content

Commit 53e039d

Browse files
bomokoBlaize Kaye
andauthored
Feature: uses service image for trivy scans (#433)
* Changes java opt * removes serveropt * Updates with comment * Removes explicit Docker host set --------- Co-authored-by: Blaize Kaye <[email protected]>
1 parent a417b1d commit 53e039d

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

legacy/scripts/exec-generate-insights-configmap.sh

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ IMAGE_INSPECT_CONFIGMAP="lagoon-insights-image-${IMAGE_NAME}"
99
IMAGE_INSPECT_OUTPUT_FILE="${TMP_DIR}/${IMAGE_NAME}.image-inspect.json.gz"
1010

1111
# Here we give the cluster administrator the ability to override the insights scan image
12-
INSIGHTS_SCAN_IMAGE="aquasec/trivy"
12+
INSIGHTS_SCAN_IMAGE="uselagoon/insights-trivy"
1313
if [ "$ADMIN_LAGOON_FEATURE_FLAG_INSIGHTS_SCAN_IMAGE" ]; then
1414
INSIGHTS_SCAN_IMAGE="${ADMIN_LAGOON_FEATURE_FLAG_INSIGHTS_SCAN_IMAGE}"
1515
fi
@@ -55,7 +55,9 @@ echo "Running sbom scan using trivy"
5555
echo "Image being scanned: ${IMAGE_FULL}"
5656
echo "Using image for scan ${IMAGECACHE_REGISTRY}${INSIGHTS_SCAN_IMAGE}"
5757

58-
DOCKER_HOST=docker-host.lagoon.svc docker run --rm -v /var/run/docker.sock:/var/run/docker.sock ${IMAGECACHE_REGISTRY}${INSIGHTS_SCAN_IMAGE} image --skip-java-db-update ${IMAGE_FULL} --format ${SBOM_OUTPUT} | gzip > ${SBOM_OUTPUT_FILE}
58+
# Setting JAVAOPT to skip the java db update, as the upstream image comes with a pre-populated database
59+
JAVAOPT="--skip-java-db-update"
60+
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock ${IMAGECACHE_REGISTRY}${INSIGHTS_SCAN_IMAGE} image ${JAVAOPT} ${IMAGE_FULL} --format ${SBOM_OUTPUT} | gzip > ${SBOM_OUTPUT_FILE}
5961

6062
FILESIZE=$(stat -c%s "$SBOM_OUTPUT_FILE")
6163
echo "Size of ${SBOM_OUTPUT_FILE} = $FILESIZE bytes."

0 commit comments

Comments
 (0)