trivy icon indicating copy to clipboard operation
trivy copied to clipboard

How to package trivy vulnerability database to docker image

Open nistal97 opened this issue 2 years ago • 1 comments

Hello team, we would like to use trivy to scan image in CI/CD pipeline, and seems in a clean env trivy will download vuln database for the first time. To reduce time cost, is it possible to package database file into docker image so it runs everytime without downloading db? Thanks.

nistal97 avatar Jan 22 '23 06:01 nistal97

it seems that you are looking for this? https://aquasecurity.github.io/trivy/v0.36/docs/advanced/air-gap/

itaysk avatar Jan 22 '23 07:01 itaysk

This issue is stale because it has been labeled with inactivity.

github-actions[bot] avatar Mar 24 '23 00:03 github-actions[bot]