<#22400 Vulnerability Scanning> Issue created by <...
# github-notifications
c
#22400 Vulnerability Scanning Issue created by sheenobu Is your feature request related to a problem? Please describe. There are tools (Grype and Syft come to mind) that can scan docker images, jar files, python requirements, etc for known CVEs. Ideally, users could mark an asset as "this is expected to pass this vulnerability scanning tool" and provide config. Would be willing to submit code for this. Describe the solution you'd like I'm not really sure what this could look like. I could see it in the adhoc backend and require users to configure the binaries themselves. Security is a cross-cutting concern so I could this as its own generic backend that other tools can hook into. I now see this PR for an audit goal which would be applicable here. #20838 but it currently looks tied to python/pip. I personally would like it callable via
pants test
but also called before any published asset gets pushed (like docker image). Describe alternatives you've considered I will try test_shell_command with some sort of adhoc_tool. code_quality_tool might also work but I doubt it runs during the test phase. I think it's worth tracking regardless of any alternative figured out. Additional context pantsbuild/pants