Image with tools for generating SBOMs and run vulnerability / license gates
1.5K
Short-lived CI toolchain image that generate SBOMs and run vulnerability / license gates: syft, grype, trivy, and grant.
| Item | Value |
|---|---|
| Docker Hub | pirlruc/ci-supply-chain |
| Architectures | linux/amd64 |
| User | non-root 1000:1000 |
| Tag | Meaning |
|---|---|
5.1.1 / 5.1.1-alpine | Immutable Alpine sha256:10c82137edb980db080e682def182d236f40d042afd403bf025848838e9515ce |
5.1.1-debian | Immutable Debian sha256:ad653b38a199064d9a0d75cbd7c489618229c2eb2f8f9ae8b2d768cf8304f687 |
5.1.0 / 5.1.0-alpine | Previous Alpine sha256:1bbe1ff600e0b1b9bb05e5f3acd512776bf65d48728a883dc074e6d52af10b07 |
5.1.0-debian | Previous Debian sha256:b2827c388dccbfdd60538d33bfe58df1fda356bfb39de31076291b67414c5d31 |
latest / latest-alpine | Latest non-prerelease Alpine publish |
latest-debian | Latest non-prerelease Debian publish |
sha-<git> / sha-<git>-alpine / sha-<git>-debian | Exact git SHA of the published commit |
Alpine owns the unsuffixed tags because it currently has the lower OS vulnerability
posture on the DHI catalog. Prefer an explicit -alpine / -debian suffix when the
libc matters; prefer a digest in production.
latest equals latest-alpine (flavor: latest=false). A monthly rebuild may
move latest off the SemVer tag — pin the digest, not latest.
docker pull pirlruc/ci-supply-chain:5.1.1
docker pull pirlruc/ci-supply-chain:5.1.1-debian
docker pull pirlruc/ci-supply-chain@sha256:10c82137edb980db080e682def182d236f40d042afd403bf025848838e9515ce
docker run --rm -v "$PWD:/workspace:ro" -w /workspace \
pirlruc/ci-supply-chain:5.1.1 \
syft . -o spdx-json
Hardened local run:
docker run --rm \
--read-only \
--cap-drop ALL \
--security-opt no-new-privileges \
--tmpfs /tmp:rw,noexec,nosuid,size=256m \
-v "$PWD:/workspace:ro" -w /workspace \
pirlruc/ci-supply-chain:5.1.1 \
trivy fs --scanners vuln --severity HIGH,CRITICAL .
| Tool | Role |
|---|---|
| syft | SBOM generation |
| grype | Vulnerability scan from SBOM / image |
| trivy | Filesystem and image vulnerability scan |
| grant | License policy gate |
Not included: actionlint, hadolint, shellcheck, zizmor, yamllint, gitleaks,
semgrep (see ci-lint), dive (see ci-container).
Donor Go binaries embed dependency CVEs that only clear when upstream publishes a newer digest.
MIT
Content type
Image
Digest
sha256:10c82137e…
Size
217 MB
Last updated
14 days ago
docker pull pirlruc/ci-supply-chain