From ef96ec7663af59d7cd9d4a55063242cbc1701fde Mon Sep 17 00:00:00 2001 From: colin Date: Sun, 21 Jan 2024 20:39:49 +0000 Subject: [PATCH] Delete docker/trivy/start.sh --- docker/trivy/start.sh | 41 ----------------------------------------- 1 file changed, 41 deletions(-) delete mode 100644 docker/trivy/start.sh diff --git a/docker/trivy/start.sh b/docker/trivy/start.sh deleted file mode 100644 index 82762ca..0000000 --- a/docker/trivy/start.sh +++ /dev/null @@ -1,41 +0,0 @@ -#!/bin/bash -# fix some logic. -TIMEOUT=${TIMEOUT:-120m} -IGNORE_UNFIXED=${IGNORE_UNFIXED:-false} -LOW_PRIORITY=${LOW_PRIORITY:-true} - -# Use SCANNERS_ENV if provided, otherwise default to vuln,misconfig,secret -SCANNERS_ENV=${SCANNERS_ENV:-"vuln,misconfig,secret"} - -run_scan() { - OLD_IFS="$IFS" - IFS=',' - for SCANNER in $SCANNERS_ENV; do - CURRENT_LOG="/log/trivy_scan_${SCANNER}.log" - if [ "$LOW_PRIORITY" = "true" ]; then - nice -n 19 trivy filesystem --cache-dir /tmp --timeout $TIMEOUT --scanners $SCANNER $( [ "$IGNORE_UNFIXED" = "true" ] && echo '--ignore-unfixed' ) /mnt > $CURRENT_LOG - else - trivy filesystem --cache-dir /tmp --timeout $TIMEOUT --scanners $SCANNER $( [ "$IGNORE_UNFIXED" = "true" ] && echo '--ignore-unfixed' ) /mnt > $CURRENT_LOG - fi - done - IFS="$OLD_IFS" -} - -compare_scans() { - for SCANNER in "${SCANNERS[@]}"; do - PREVIOUS_LOG="/log/previous_scan_${SCANNER}.log" - CURRENT_LOG="/log/trivy_scan_${SCANNER}.log" - SCAN_DATE=$(date +%Y.%m.%d) - DIFF_LOG="/log/scandiff_${SCANNER}_$SCAN_DATE.log" - - if [ -f "$CURRENT_LOG" ]; then - if [ -f "$PREVIOUS_LOG" ]; then - diff $PREVIOUS_LOG $CURRENT_LOG > $DIFF_LOG - fi - cp $CURRENT_LOG $PREVIOUS_LOG - fi - done -} - -run_scan -compare_scans