Skip to content

Use Trivy database that contains GitLab Advisory Database

Why is this change being made?

We want to use our own Trivy databases (from trivy-db-glad's registry) that contain the GitLab Advisory Database.

See: gitlab-org/gitlab#350232 (closed)

How to test

See: !630 (merged)

The job spec contains the following init container:

initContainers:
- args:
  - --cache-dir
  - /tmp/trivy/.cache
  - image
  - --download-db-only
  - --db-repository
  - registry.gitlab.com/gitlab-org/security-products/dependencies/trivy-db-glad
Edited by Dominic Bauer

Merge request reports