grype/cmd/root.go

99 lines
2.8 KiB
Go
Raw Normal View History

2020-05-26 14:37:28 +00:00
package cmd
import (
"fmt"
"os"
"runtime/pprof"
2020-05-26 14:37:28 +00:00
2020-07-24 01:29:05 +00:00
"github.com/anchore/grype/grype"
"github.com/anchore/grype/grype/presenter"
"github.com/anchore/grype/internal"
"github.com/anchore/grype/internal/format"
"github.com/anchore/syft/syft/scope"
2020-05-26 14:37:28 +00:00
"github.com/spf13/cobra"
2020-05-26 17:31:50 +00:00
"github.com/spf13/viper"
2020-05-26 14:37:28 +00:00
)
var rootCmd = &cobra.Command{
Use: fmt.Sprintf("%s [IMAGE]", internal.ApplicationName),
Short: "A vulnerability scanner for container images and filesystems", // TODO: add copy, add path-based scans
2020-05-26 17:31:50 +00:00
Long: format.Tprintf(`Supports the following image sources:
2020-05-26 14:37:28 +00:00
{{.appName}} yourrepo/yourimage:tag defaults to using images from a docker daemon
2020-05-26 17:31:50 +00:00
{{.appName}} docker://yourrepo/yourimage:tag explicitly use a docker daemon
2020-05-26 14:37:28 +00:00
{{.appName}} tar://path/to/yourimage.tar use a tarball from disk
`, map[string]interface{}{
"appName": internal.ApplicationName,
}),
2020-07-20 16:00:25 +00:00
Args: cobra.ExactArgs(1),
2020-05-26 17:31:50 +00:00
Run: func(cmd *cobra.Command, args []string) {
if appConfig.Dev.ProfileCPU {
f, err := os.Create("cpu.profile")
if err != nil {
log.Errorf("unable to create CPU profile: %+v", err)
} else {
err := pprof.StartCPUProfile(f)
if err != nil {
log.Errorf("unable to start CPU profile: %+v", err)
}
}
}
err := runDefaultCmd(cmd, args)
if appConfig.Dev.ProfileCPU {
pprof.StopCPUProfile()
}
if err != nil {
log.Errorf(err.Error())
os.Exit(1)
}
2020-05-26 17:31:50 +00:00
},
2020-05-26 14:37:28 +00:00
}
func init() {
2020-05-26 17:31:50 +00:00
// setup CLI options specific to scanning an image
2020-05-26 14:37:28 +00:00
2020-05-26 17:31:50 +00:00
// scan options
flag := "scope"
rootCmd.Flags().StringP(
"scope", "s", scope.AllLayersScope.String(),
fmt.Sprintf("selection of layers to analyze, options=%v", scope.Options),
)
2020-05-26 17:31:50 +00:00
if err := viper.BindPFlag(flag, rootCmd.Flags().Lookup(flag)); err != nil {
fmt.Printf("unable to bind flag '%s': %+v", flag, err)
2020-05-26 14:37:28 +00:00
os.Exit(1)
}
2020-05-26 17:31:50 +00:00
// output & formatting options
flag = "output"
rootCmd.Flags().StringP(
flag, "o", presenter.JSONPresenter.String(),
fmt.Sprintf("report output formatter, options=%v", presenter.Options),
2020-05-26 17:31:50 +00:00
)
if err := viper.BindPFlag(flag, rootCmd.Flags().Lookup(flag)); err != nil {
fmt.Printf("unable to bind flag '%s': %+v", flag, err)
os.Exit(1)
}
2020-05-26 14:37:28 +00:00
}
func runDefaultCmd(_ *cobra.Command, args []string) error {
2020-05-26 14:37:28 +00:00
userImageStr := args[0]
2020-07-24 01:29:05 +00:00
provider, err := grype.LoadVulnerabilityDb(appConfig.Db.ToCuratorConfig(), appConfig.Db.AutoUpdate)
2020-05-26 14:37:28 +00:00
if err != nil {
return fmt.Errorf("failed to load vulnerability db: %w", err)
2020-05-26 14:37:28 +00:00
}
2020-07-24 01:29:05 +00:00
results, catalog, _, err := grype.FindVulnerabilities(provider, userImageStr, appConfig.ScopeOpt)
2020-06-19 14:12:29 +00:00
if err != nil {
return fmt.Errorf("failed to find vulnerabilities: %w", err)
2020-06-19 14:12:29 +00:00
}
if err = presenter.GetPresenter(appConfig.PresenterOpt).Present(os.Stdout, catalog, results); err != nil {
return fmt.Errorf("could not format catalog results: %w", err)
}
2020-05-26 14:37:28 +00:00
return nil
2020-05-26 14:37:28 +00:00
}