Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Offline functionality for air-gapped environments #83

Closed
ataraxus opened this issue Nov 15, 2022 · 5 comments
Closed

Offline functionality for air-gapped environments #83

ataraxus opened this issue Nov 15, 2022 · 5 comments
Assignees
Labels
enhancement New feature or request

Comments

@ataraxus
Copy link

Are there any plans to support offline functionality for air-gapped environments?

@djschleen
Copy link
Member

That's an interesting idea. Depends on if you have a vulnerability scanner that accepts PURLs in their API. What vulnerability scanners do you use?

@ataraxus
Copy link
Author

Sorry for the delayed answer. Currently we are using trivy, which has a very nice Support for airgapped environments

@djschleen
Copy link
Member

I took a look at Trivvy but it doesn't look like it is going to be able to find the vulnerabilities for the purls bomber parses out of a SBOM. I know there are some standalone services that will match a purl to a vulnerability but I think those require regular signature updates from the public internet.

@djschleen djschleen self-assigned this Dec 4, 2022
@djschleen djschleen added the enhancement New feature or request label Dec 4, 2022
@djschleen
Copy link
Member

Issue #98 should make this a reality.

@devops-kung-fu devops-kung-fu locked as resolved and limited conversation to collaborators Dec 14, 2022
@djschleen
Copy link
Member

This will be covered by #98

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement New feature or request
Development

No branches or pull requests

2 participants