Sign inSign up

pirlruc/ci-supply-chain

By pirlruc

•Updated 14 days ago

Image with tools for generating SBOMs and run vulnerability / license gates

Image
Security
Developer tools
0

1.5K

pirlruc/ci-supply-chain repository overview

⁠ci-supply-chain

Short-lived CI toolchain image that generate SBOMs and run vulnerability / license gates: syft, grype, trivy, and grant.

⁠Image

ItemValue
Docker Hubpirlruc/ci-supply-chain
Architectureslinux/amd64
Usernon-root 1000:1000
⁠Tags
TagMeaning
5.1.1 / 5.1.1-alpineImmutable Alpine sha256:10c82137edb980db080e682def182d236f40d042afd403bf025848838e9515ce
5.1.1-debianImmutable Debian sha256:ad653b38a199064d9a0d75cbd7c489618229c2eb2f8f9ae8b2d768cf8304f687
5.1.0 / 5.1.0-alpinePrevious Alpine sha256:1bbe1ff600e0b1b9bb05e5f3acd512776bf65d48728a883dc074e6d52af10b07
5.1.0-debianPrevious Debian sha256:b2827c388dccbfdd60538d33bfe58df1fda356bfb39de31076291b67414c5d31
latest / latest-alpineLatest non-prerelease Alpine publish
latest-debianLatest non-prerelease Debian publish
sha-<git> / sha-<git>-alpine / sha-<git>-debianExact git SHA of the published commit

Alpine owns the unsuffixed tags because it currently has the lower OS vulnerability posture on the DHI catalog. Prefer an explicit -alpine / -debian suffix when the libc matters; prefer a digest in production. latest equals latest-alpine (flavor: latest=false). A monthly rebuild may move latest off the SemVer tag — pin the digest, not latest.

docker pull pirlruc/ci-supply-chain:5.1.1
docker pull pirlruc/ci-supply-chain:5.1.1-debian
docker pull pirlruc/ci-supply-chain@sha256:10c82137edb980db080e682def182d236f40d042afd403bf025848838e9515ce

⁠Quick start

docker run --rm -v "$PWD:/workspace:ro" -w /workspace \
  pirlruc/ci-supply-chain:5.1.1 \
  syft . -o spdx-json

Hardened local run:

docker run --rm \
  --read-only \
  --cap-drop ALL \
  --security-opt no-new-privileges \
  --tmpfs /tmp:rw,noexec,nosuid,size=256m \
  -v "$PWD:/workspace:ro" -w /workspace \
  pirlruc/ci-supply-chain:5.1.1 \
  trivy fs --scanners vuln --severity HIGH,CRITICAL .

⁠What is inside

ToolRole
syftSBOM generation
grypeVulnerability scan from SBOM / image
trivyFilesystem and image vulnerability scan
grantLicense policy gate

Not included: actionlint, hadolint, shellcheck, zizmor, yamllint, gitleaks, semgrep (see ci-lint), dive (see ci-container).

⁠Vulnerabilities

Donor Go binaries embed dependency CVEs that only clear when upstream publishes a newer digest.

⁠License

MIT

Tag summary

Content type

Image

Digest

sha256:10c82137e…

Size

217 MB

Last updated

14 days ago

docker pull pirlruc/ci-supply-chain