Skip to content

Evaluate alternative scanners and portable database snapshots #2

Description

@andreashaerter

ConClear currently uses Trivy for vulnerability, secret, and configuration scanning.

Evaluate whether another scanner stack is useful. Using Syft and Grype would not replace the Trivy secret and configuration checks, so this option adds tools and another vulnerability database.

The design must retain exactly one authoritative vulnerability verdict, bind database snapshots by digest across workers, and define record, attestation, verification, and rescan behavior.

Also decide whether workers need an explicit transport for scanner database snapshots.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    blocked: upstreamWaiting on a change outside this projectenhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions