Skip to content

Draft: Allow configuration of Trivy database repository

What does this MR do?

Add optional configuration flags --db-repository and --java-db-repository allowing OCS users to scan their air-gapped clusters.

Why are we doing this?

We run GitLab in an air-gapped environment, which this MR allows us to point to a on-premise copy of trivy-db-glad and a copy of the official Trivy Java DB.

What are the relevant issue numbers?

Edited by Mike Cameron

Merge request reports