This month's (July 22) updates from @AquaSecTeam Open Source Team - features, content, news and more 🧵
(P.S We're also making future updates available via a newsletter, details at the end of the thread)
You already know Trivy could always generate #SBOM, but now it can also *scan SBOM* 😯 This means it doesn't need to analyze the container for every scan, just once when generating an SBOM, and then just match it with vulnerabilities database. aquasecurity.github.io/trivy/v0.30.4/…
🆕 License scanning 👩⚖️ In addition to showing license of detected packages, there's a new full file scan for license files or headers, that classifies results into actionable list (this is based on the excellent @GoogleOSS License classifier 🙏) aquasecurity.github.io/trivy/v0.30.4/…
Did you know about our open source project Postee? It's a security alert management tool that can receive events as a webhook, and route to preferred destination based on your rules. e.g, Tracee makes a detection 🚨, post message in slack channel 🔔 github.com/aquasecurity/p…
Postee can also *respond* to events by invoking an action to remediate the incident. Postee's actions documentation lists all available actions: aquasecurity.github.io/postee/v2.7.2/…
If you want to learn more about Postee, here's @simarpreet7 Postee introduction from DevSecCon
🎥 New videos in the Aqua Open Source YouTube channel:
- Using Prometheus with Trivy Operator
- Configuring Trivy scans using config file
- @josedonizetti sharing his journey with Open Source youtube.com/c/AquaSecurity…
Thanks and see you next time! 📩 If you've made it this far, you might want to subscribe to receive the next update by email: info.aquasec.com/open-source-ne…
• • •
Missing some Tweet in this thread? You can try to
force a refresh
This month's (June 22) updates from @AquaSecTeam Open Source Team - features, content, news and more 🧵
@AquaSecTeam One of the biggest news this past month was that Trivy now scans #kubernetes ⎈ clusters - through the CLI or a native Kubernetes Operator!