Sign inSign up

trustsource/ts-scan

By trustsource

•Updated about 1 month ago

ready to use docker image with preset ts-scan installation.

Image
Security
Integration & delivery
Developer tools
0

2.1K

trustsource/ts-scan repository overview

⁠TrustSource's ts-scan

⁠Swiss army knife for Software Composition Analysis (SCA)

⁠Quick Reference
  • Maintainer: EACG⁠ Team
  • ts-scan help: https://trustsource.github.io/ts-scan⁠
  • latest tag: >ts-scan:latest<
  • ⁠What it is:
    This docker image provides the SCA tool ts-scan. ts-scan is capable of:
  • transitive dependency identification for PyPI, Maven, NuGet, NPM, Go, Cargo, Dart, Gradle, Visual Basic 6 and more, plus Docker image scanning via Syft. Integrate it into CI/CD pipelines to catch vulnerabilities and license issues before release, or upload results directly to your TrustSource workspace for continuous supply-chain compliance monitoring.
  • copyright detection and extraction,
  • license detection and identification,
  • crypto-algorithm detection,
  • fingerprinting of files (SCANOSS),
  • yara scanning
  • ts-scan also may be used as an SBOM converter between different SPDX and CycloneDX versions. PLEASE NOTE: Transformation between formats may not always be lossless!

    You may store the results locally or upload them to the TrustSource Product Security platform for further processing or handling. Find more information at ts-scan documentation⁠.

    ⁠How to start
    to pull the image use: docker pull ts-scan:latest to start a scan: docker run ts-scan
    ⁠Further information:
  • Information about the TrustSource Product Security Platform⁠
  • Register free account at the TrustSource platform⁠
  • try to operate the platform locally. There is a community edition, see this repo⁠
  • Tag summary

    Content type

    Image

    Digest

    sha256:7baee04d1…

    Size

    1.2 GB

    Last updated

    about 1 month ago

    docker pull trustsource/ts-scan