Skip to content

Commit 4567f4b

Browse files
committed
wip
1 parent efe95b8 commit 4567f4b

9 files changed

Lines changed: 714 additions & 17 deletions

File tree

.gitignore

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,4 +4,4 @@ src/base/.devcontainer/language_versions/
44
.trivyignore_combined.yaml
55
.out/
66
.envrc
7-
.grype_out/
7+
.sbom/

Makefile

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,10 @@ build-syft:
6969
build-grype:
7070
docker build -f src/base/.devcontainer/Dockerfile.grype --tag local_grype src/base/.devcontainer/
7171

72-
build-image: build-syft build-grype guard-CONTAINER_NAME guard-BASE_VERSION_TAG guard-BASE_FOLDER guard-IMAGE_TAG
72+
build-grant:
73+
docker build -f src/base/.devcontainer/Dockerfile.grant --tag local_grant src/base/.devcontainer/
74+
75+
build-image: build-syft build-grype build-grant guard-CONTAINER_NAME guard-BASE_VERSION_TAG guard-BASE_FOLDER guard-IMAGE_TAG
7376
npx devcontainer build \
7477
--workspace-folder ./src/$${BASE_FOLDER}/$${CONTAINER_NAME} \
7578
$(NO_CACHE_FLAG) \
@@ -97,8 +100,7 @@ scan-image-json: guard-CONTAINER_NAME guard-BASE_FOLDER guard-IMAGE_TAG
97100
grype "${CONTAINER_PREFIX}$${CONTAINER_NAME}:$${IMAGE_TAG}" \
98101
--scope all-layers \
99102
--output json \
100-
--file ".grype_out/grype_${CONTAINER_NAME}_${IMAGE_TAG}.json" \
101-
--sort-by severity
103+
--file ".grype_out/grype_${CONTAINER_NAME}_${IMAGE_TAG}.json"
102104

103105
shell-image: guard-CONTAINER_NAME guard-IMAGE_TAG
104106
docker run -it \

0 commit comments

Comments
 (0)