Sign inSign up

rapid7/container-image-scanner

By rapid7

•Updated over 3 years ago
Archived

Container Image Scanner for InsightVM

Image
5

100K+

rapid7/container-image-scanner repository overview

⁠Container Image Scanner

Tool for analyzing a Docker image using the InsightVM API and exporting as JSON object.

For more information view the help page⁠. For additional assistance, see Get Support⁠.

⁠Usage

docker run -it [--rm] -v path_to_local_file:path_to_file_on_container container-image-scanner:tagname -f=path_to_file_on_container -k=api_key [-r=api_region] [-l] [-ct=connect_timeout] [-rt=read_timeout] [-bn=build_name] [-bi=build_id]
Converts a docker image into JSON.
  -f, --file=path_to_file_on_container      Location of image tar file.
  -k, --key=api_key                         API key used for authentication, region-specific.
  -r, --region=api_region                   API region code, optional arg. Defaults to "us".
  -l, --logging                             Debug logging flag, include if debug statements wanted.
  -ct, --connect=connect_timeout            The duration in milliseconds before connect timeout.
  -rt, --read=read_timeout                  The duration in milliseconds before read timeout.
  -bn --name=build_name                     The name of the build.  This flag will post information to your console.  It must be used with -bi.
  -bi --id=build_id                         The id of the build.  This flag will post information to your console.  It must be used with -bn
  --rm                                      Clean up container after it runs.

⁠API Key

https://insight.help.rapid7.com/docs/managing-platform-api-keys⁠

⁠Regions

https://insight.help.rapid7.com/docs/product-apis#section-supported-regions⁠

⁠Help/Options

docker run -it container-image-scanner:tagname -h

⁠Run (Docker)

Export a docker image and pass the path into the main method along with a valid API key and valid API region.

  1. Obtain or save an image file.
  • docker save <image> -o test_image.tar
  1. Run tool
  • Please note that the -bn and -bi flags are optional arguments to post the build results. However if one is supplied they both must be supplied.
  • java -jar container-image-scanner-<version>.jar -f=<path_to_file_in_environment> -k=<api_key> [-r=<api_region>] (local)
  • docker run -it -v <path/to/local_file>:<path_to_file_on_container> container-image-scanner:latest [-f=<path_to_file_on_container>] [-k=<api_key>] [-r=<api_region>] (Docker)
    • ex. docker run -it -v /local/file.tar:/newFile.tar container-image-scanner:latest -f newFile.tar -k "1234567key" -r us
  1. Inspect the output for correct JSON formatting and analysis.

⁠Notes

  • API key must match API region, otherwise 400 error.

Tag summary

Content type

Image

Digest

sha256:cceea7528…

Size

99 MB

Last updated

over 3 years ago

docker pull rapid7/container-image-scanner