-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add an other Aqua scan format #11957
Comments
Can you point us to the documentation of this format? Is there an official name for this type of report? Are you able to contribute a PR? |
Here is the doc of the api/v2/risks/vulnerabilities endpoint: The command list all vulnerabilities found in images |
I could try a PR |
Thanks. I cannot access that documentation as I don't have an aquasec account. PRs are welcome. Just want to make sure this is a common use case to generated these reports/exports and not just an API endpoint that is being called and not used by many users. |
From what I know, the actual aqua formats covered by the parser are CICD reports and also scan results from a call to That report generated over the api/v1 doesnt include de cvssv3 score, resulting in discording aqua severity when I import the scan in Defect Dojo vs what I see in the Aqua UI... I contacted Aqua Support and they told me to use the api/v2/risks/vulnerabilities endpoint instead. Saying that the other one was probably getting obsolete. |
OK, might be a good idea with the PR to update also the docs for the existing parser. |
When I run GET api/v2/risks/vulnerabilities in Aqua Security, I get a scan report listing vulnerabilities in my image, but the report generated is not supported for parsing in DefectDojo. Is it possible to add that new format report?
Sample file
api.json
The text was updated successfully, but these errors were encountered: