@@ -632,6 +632,108 @@ You can also view the full vulnerability list in your terminal with: `osv-scanne
632
632
633
633
---
634
634
635
+ [TestCommand_OCIImage/rockylinux_empty_image - 1]
636
+ Scanning local image tarball "./testdata/test-rockylinux.tar"
637
+
638
+ Container Scanning Result (Rocky Linux 9.2 (Blue Onyx)):
639
+ Total 13 packages affected by 32 known vulnerabilities (0 Critical, 15 High, 3 Medium, 0 Low, 14 Unknown) from 2 ecosystems.
640
+ 4 vulnerabilities can be fixed.
641
+
642
+
643
+ PyPI
644
+ +--------------------------------------------------------------------------------------------------+
645
+ | Source:artifact:/usr/share/python3-wheels/pip-21.2.3-py3-none-any.whl |
646
+ +---------+-------------------+---------------+------------+------------------+--------------------+
647
+ | PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
648
+ +---------+-------------------+---------------+------------+------------------+--------------------+
649
+ | pip | 21.2.3 | Fix Available | 1 | # 0 Layer | library/rockylinux |
650
+ +---------+-------------------+---------------+------------+------------------+--------------------+
651
+ +-----------------------------------------------------------------------------------------------------+
652
+ | Source:artifact:/usr/share/python3-wheels/setuptools-53.0.0-py3-none-any.whl |
653
+ +------------+-------------------+---------------+------------+------------------+--------------------+
654
+ | PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
655
+ +------------+-------------------+---------------+------------+------------------+--------------------+
656
+ | setuptools | 53.0.0 | Fix Available | 3 | # 0 Layer | library/rockylinux |
657
+ +------------+-------------------+---------------+------------+------------------+--------------------+
658
+ Rocky Linux
659
+ +--------------------------------------------------------------------------------------------------------------------------------------+
660
+ | Source:os:/var/lib/rpm/rpmdb.sqlite |
661
+ +----------------+-------------------+------------------+------------+-------------------------+------------------+--------------------+
662
+ | SOURCE PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | BINARY PACKAGES (COUNT) | INTRODUCED LAYER | IN BASE IMAGE |
663
+ +----------------+-------------------+------------------+------------+-------------------------+------------------+--------------------+
664
+ | expat | 2.5.0-1.el9 | No fix available | 2 | expat | # 0 Layer | library/rockylinux |
665
+ | glib2 | 2.68.4-6.el9 | No fix available | 1 | glib2 | # 0 Layer | library/rockylinux |
666
+ | glibc | 2.34-60.el9 | No fix available | 2 | glibc | # 0 Layer | library/rockylinux |
667
+ | gnutls | 3.7.6-20.el9_2 | No fix available | 1 | gnutls | # 0 Layer | library/rockylinux |
668
+ | less | 590-1.el9_0 | No fix available | 3 | less | # 0 Layer | library/rockylinux |
669
+ | libeconf | 0.4.1-2.el9 | No fix available | 1 | libeconf | # 0 Layer | library/rockylinux |
670
+ | libgcrypt | 1.10.0-10.el9_2 | No fix available | 1 | libgcrypt | # 0 Layer | library/rockylinux |
671
+ | libxml2 | 2.9.13-3.el9_1 | No fix available | 2 | libxml2 | # 0 Layer | library/rockylinux |
672
+ | openssl | 3.0.7-6.el9_2 | No fix available | 12 | openssl | # 0 Layer | library/rockylinux |
673
+ | pam | 1.5.1-14.el9 | No fix available | 1 | pam | # 0 Layer | library/rockylinux |
674
+ | tar | 1.34-6.el9_1 | No fix available | 2 | tar | # 0 Layer | library/rockylinux |
675
+ +----------------+-------------------+------------------+------------+-------------------------+------------------+--------------------+
676
+
677
+ For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name >`.
678
+ You can also view the full vulnerability list in your terminal with: `osv-scanner scan image --format vertical <image_name >`.
679
+
680
+ ---
681
+
682
+ [TestCommand_OCIImage/rockylinux_empty_image - 2]
683
+
684
+ ---
685
+
686
+ [TestCommand_OCIImage/rockylinux_empty_image_all_vulns - 1]
687
+ Scanning local image tarball "./testdata/test-rockylinux.tar"
688
+
689
+ Container Scanning Result (Rocky Linux 9.2 (Blue Onyx)):
690
+ Total 13 packages affected by 32 known vulnerabilities (0 Critical, 15 High, 3 Medium, 0 Low, 14 Unknown) from 2 ecosystems.
691
+ 4 vulnerabilities can be fixed.
692
+
693
+
694
+ PyPI
695
+ +--------------------------------------------------------------------------------------------------+
696
+ | Source:artifact:/usr/share/python3-wheels/pip-21.2.3-py3-none-any.whl |
697
+ +---------+-------------------+---------------+------------+------------------+--------------------+
698
+ | PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
699
+ +---------+-------------------+---------------+------------+------------------+--------------------+
700
+ | pip | 21.2.3 | Fix Available | 1 | # 0 Layer | library/rockylinux |
701
+ +---------+-------------------+---------------+------------+------------------+--------------------+
702
+ +-----------------------------------------------------------------------------------------------------+
703
+ | Source:artifact:/usr/share/python3-wheels/setuptools-53.0.0-py3-none-any.whl |
704
+ +------------+-------------------+---------------+------------+------------------+--------------------+
705
+ | PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
706
+ +------------+-------------------+---------------+------------+------------------+--------------------+
707
+ | setuptools | 53.0.0 | Fix Available | 3 | # 0 Layer | library/rockylinux |
708
+ +------------+-------------------+---------------+------------+------------------+--------------------+
709
+ Rocky Linux
710
+ +--------------------------------------------------------------------------------------------------------------------------------------+
711
+ | Source:os:/var/lib/rpm/rpmdb.sqlite |
712
+ +----------------+-------------------+------------------+------------+-------------------------+------------------+--------------------+
713
+ | SOURCE PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | BINARY PACKAGES (COUNT) | INTRODUCED LAYER | IN BASE IMAGE |
714
+ +----------------+-------------------+------------------+------------+-------------------------+------------------+--------------------+
715
+ | expat | 2.5.0-1.el9 | No fix available | 2 | expat | # 0 Layer | library/rockylinux |
716
+ | glib2 | 2.68.4-6.el9 | No fix available | 1 | glib2 | # 0 Layer | library/rockylinux |
717
+ | glibc | 2.34-60.el9 | No fix available | 2 | glibc | # 0 Layer | library/rockylinux |
718
+ | gnutls | 3.7.6-20.el9_2 | No fix available | 1 | gnutls | # 0 Layer | library/rockylinux |
719
+ | less | 590-1.el9_0 | No fix available | 3 | less | # 0 Layer | library/rockylinux |
720
+ | libeconf | 0.4.1-2.el9 | No fix available | 1 | libeconf | # 0 Layer | library/rockylinux |
721
+ | libgcrypt | 1.10.0-10.el9_2 | No fix available | 1 | libgcrypt | # 0 Layer | library/rockylinux |
722
+ | libxml2 | 2.9.13-3.el9_1 | No fix available | 2 | libxml2 | # 0 Layer | library/rockylinux |
723
+ | openssl | 3.0.7-6.el9_2 | No fix available | 12 | openssl | # 0 Layer | library/rockylinux |
724
+ | pam | 1.5.1-14.el9 | No fix available | 1 | pam | # 0 Layer | library/rockylinux |
725
+ | tar | 1.34-6.el9_1 | No fix available | 2 | tar | # 0 Layer | library/rockylinux |
726
+ +----------------+-------------------+------------------+------------+-------------------------+------------------+--------------------+
727
+
728
+ For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name >`.
729
+ You can also view the full vulnerability list in your terminal with: `osv-scanner scan image --format vertical <image_name >`.
730
+
731
+ ---
732
+
733
+ [TestCommand_OCIImage/rockylinux_empty_image_all_vulns - 2]
734
+
735
+ ---
736
+
635
737
[TestCommand_OCIImage/scanning_image_with_go_binary - 1]
636
738
Scanning local image tarball "./testdata/test-package-tracing.tar"
637
739
0 commit comments