Itay Shakury Profile picture
Aug 6, 2022 11 tweets 6 min read Read on X
This month's (July 22) updates from @AquaSecTeam Open Source Team - features, content, news and more 🧵
(P.S We're also making future updates available via a newsletter, details at the end of the thread)
You already know Trivy could always generate #SBOM, but now it can also *scan SBOM* 😯 This means it doesn't need to analyze the container for every scan, just once when generating an SBOM, and then just match it with vulnerabilities database. aquasecurity.github.io/trivy/v0.30.4/… Image
Support for new platforms: Amazon Linux 2022, pnpm, improved .NET Core, and more..
aquasecurity.github.io/trivy/v0.30.4/…
🆕 License scanning 👩‍⚖️ In addition to showing license of detected packages, there's a new full file scan for license files or headers, that classifies results into actionable list (this is based on the excellent @GoogleOSS License classifier 🙏)
aquasecurity.github.io/trivy/v0.30.4/… Image
There's a new @AzureDevOps extension for Trivy! Tell us what you think about it marketplace.visualstudio.com/items?itemName… Image
Trivy Operator has a initial support for #Kubernetes RBAC assessment 👮‍♀️ Check that your roles and permissions are not exposing you
aquasecurity.github.io/trivy-operator…
Did you know about our open source project Postee? It's a security alert management tool that can receive events as a webhook, and route to preferred destination based on your rules. e.g, Tracee makes a detection 🚨, post message in slack channel 🔔
github.com/aquasecurity/p…
Postee can also *respond* to events by invoking an action to remediate the incident. Postee's actions documentation lists all available actions: aquasecurity.github.io/postee/v2.7.2/… Image
If you want to learn more about Postee, here's @simarpreet7 Postee introduction from DevSecCon
🎥 New videos in the Aqua Open Source YouTube channel:
- Using Prometheus with Trivy Operator
- Configuring Trivy scans using config file
- @josedonizetti sharing his journey with Open Source
youtube.com/c/AquaSecurity…
Thanks and see you next time! 📩 If you've made it this far, you might want to subscribe to receive the next update by email: info.aquasec.com/open-source-ne…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Itay Shakury

Itay Shakury Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @itaysk

Jul 4, 2022
This month's (June 22) updates from @AquaSecTeam Open Source Team - features, content, news and more 🧵
@AquaSecTeam One of the biggest news this past month was that Trivy now scans #kubernetes ⎈ clusters - through the CLI or a native Kubernetes Operator!
Read 15 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(