scan-action icon indicating copy to clipboard operation
scan-action copied to clipboard

Add show-grype-output option to show vulnerabilities in console when …

Open ken-chou-glia opened this issue 4 years ago • 6 comments

…running scan in blocking mode

Signed-off-by: Ken Chou [email protected]

ken-chou-glia avatar Dec 04 '21 07:12 ken-chou-glia

This would close #168

JAORMX avatar Apr 22 '22 15:04 JAORMX

This is a great idea -- however, I think we could probably do this without a config parameter to just always dump the table view to the console, WDYT?

kzantow avatar Apr 22 '22 17:04 kzantow

This is a great idea -- however, I think we could probably do this without a config parameter to just always dump the table view to the console, WDYT?

to be honest, that behavior would be a nice default to have.

JAORMX avatar Apr 22 '22 17:04 JAORMX

@kzantow is this a change that would need to go into grype itself or is it something that needs to happen in this action?

JAORMX avatar Apr 25 '22 16:04 JAORMX

@ken-chou-finn thank for your work on this PR. On @JAORMX's latest question: grype currently prints the table and then errors out, like in the example below:

$ grype ubuntu:20.04 --fail-on medium                                                                                                                                                              
NAME          INSTALLED                 FIXED-IN            TYPE  VULNERABILITY   SEVERITY
coreutils     8.30-3ubuntu2                                 deb   CVE-2016-2781   Low
e2fsprogs     1.45.5-2ubuntu1                               deb   CVE-2022-1304   Medium
[other vulns removed for brevity of this snippet]
1 error occurred:
	* discovered vulnerabilities at or above the severity threshold

We just need to make use of the table output, so no need to change grype, just this action. I am happy to help with this PR and get the feature delivered.

jonasagx avatar May 25 '22 06:05 jonasagx

@jonasagx that would be great!

JAORMX avatar May 25 '22 07:05 JAORMX

Sorry this has taken a while to get back to -- I think we may want to combine this with #187 by allowing users to specify a format parameter, which could be table.

One question: is there any situation a user wants to get both a table output printed and an output file of some sort?

kzantow avatar Sep 12 '22 17:09 kzantow