-
Notifications
You must be signed in to change notification settings - Fork 2.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(k8s): kbom cyclondx support #4252
Conversation
d872a05
to
93aa983
Compare
f49035b
to
b673977
Compare
0dcaec8
to
357a63c
Compare
Signed-off-by: chenk <hen.keinan@gmail.com>
Signed-off-by: chenk <hen.keinan@gmail.com>
Signed-off-by: chenk <hen.keinan@gmail.com>
Signed-off-by: chenk <hen.keinan@gmail.com>
Signed-off-by: chenk <hen.keinan@gmail.com>
Signed-off-by: chenk <hen.keinan@gmail.com>
Signed-off-by: chenk <hen.keinan@gmail.com>
Signed-off-by: chenk <hen.keinan@gmail.com>
Signed-off-by: chenk <hen.keinan@gmail.com>
357a63c
to
c4a26da
Compare
Signed-off-by: chenk <hen.keinan@gmail.com>
@@ -17,6 +17,10 @@ $ trivy image --format spdx-json --output result.json alpine:3.15 | |||
$ trivy fs --format cyclonedx --output result.json /app/myproject | |||
``` | |||
|
|||
``` | |||
$ trivy k8s cluster --format cyclonedx --output result.json |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this is the kbom creation referenced in the Kubernetes scanning docs? It is a bit unclear what the difference here is between kbom and sbom
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
KBOM is BOM for the cluster (what your k8s is made of). SBOM is usually BOM for the image (what your application is made of). agree if can be clarified in the docs
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Maybe providing a sentence or two of clarification e.g. "SBOMs for Kubernetes i.e. KBOM
A KBOM specifies XXX" @chen-keinan what do you think?
Duplicate #4557 |
Description
support cyclonedx kubernetes bom
Related issues
Checklist
usage:
# trivy k8s cluster --format cyclonedx