Sign inSign up

tychoncorp/vulnerability-scanner

By tychoncorp

•Updated 5 days ago

Agentless SCAP/DISA STIG + CVE scanning for containers, Kubernetes, VM disks, and hosts.

Image
0

736

tychoncorp/vulnerability-scanner repository overview

⁠TYCHON Vulnerability Scanner (TVS)

Agentless SCAP / DISA STIG compliance and CVE vulnerability scanning for containers, Kubernetes workloads, VM disks, and hosts — a single self-contained Go binary on a hardened, STIG'd Rocky 9 base. Offline-capable: vulnerability feeds are read from a mounted cache by default and refreshed from the TYCHON feed origin (HTTPS, SHA-256 verified) when -vulnFetch is enabled.

⁠What it does

  • Kubernetes live monitoring — run as a DaemonSet node agent (-watch -watchLive) that discovers every running container via the shared host PID namespace (/proc/<pid>/root, runtime-agnostic: containerd, CRI-O, Docker) and scans each for CVEs and STIG compliance, emitting to Elastic Cloud Security Posture and to kubectl-visible VulnerabilityReport / ConfigAuditReport custom resources.
  • Dormant at-rest disks — with -dormantDiskDirs, report failing CVEs/STIG on stopped-VM DataVolumes and unattached PVCs, kept separate from the live "running-only" findings.
  • Harbor registry — a pluggable scanner adapter (-harborAdapter) that fills Harbor's own Vulnerabilities/SBOM columns, plus a full registry sweep (-scanRegistry) for images at rest.
  • Hosts & VM disks — STIG + CVE scans of a host, a container image, or a VM disk (-scanRoot), including the DISA Kubernetes STIG on the cluster's own control-plane node.

⁠Quick start (node agent)

docker run --rm --pid=host --privileged \
  -v /var/lib/tychon/feeds:/feeds:ro \
  -v /var/lib/tychon/reports:/reports \
  docker.io/tychoncorp/vulnerability-scanner:dev

The default entrypoint runs the continuous node agent (-watch -watchStig -watchStigDir=/stig -vulnCache=/feeds -vulnFetch -watchReports=/reports).

⁠Kubernetes + Harbor + Elastic

Deploy as a DaemonSet — see deploy/kubernetes/ (rbac.yaml, crd.yaml, daemonset.yaml) and the Harbor + Kubernetes + Elastic deployment manual in the TYCHON user guide for the complete, step-by-step runbook (active running workloads + dormant at-rest disks → Elastic).

⁠Signature updates

CVE/OVAL and STIG content refresh from the TYCHON cloud feed origin (domain-restricted HTTPS, every artifact SHA-256 verified). Enable with -vulnFetch; air-gapped sites stage a -feedBundle instead and never touch the network.

⁠Tags

  • dev — development build (this tag). For production, pin a released version tag.

Tag summary

Content type

Image

Digest

sha256:3357bdb40…

Size

180.6 MB

Last updated

5 days ago

docker pull tychoncorp/vulnerability-scanner:dev