broadinstitute/Docker image parse and scan

Parse Dockerfile and build, scan the image if a "blessed" base image is not used

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
contextPath to Docker build context (omit if using the 'image' option)no.
dockerfilePath to Dockerfile within the build context (omit if using the 'image' option)noDockerfile
imagePre-built Docker image URL to scan (omit if using the 'dockerfile' option)no""
typeComma-delimited list of scan typesnoos
severitiesComma-delimited list of severities for TrivynoCRITICAL
sarifSarif template output path relative to repository root, if any (example: trivy-results.sarif)no""
scannersDoes not scan image for secrets, but only vulnerabilitiesnovuln

no outputs