X-Git-Url: https://gerrit.o-ran-sc.org/r/gitweb?a=blobdiff_plain;ds=inline;f=code%2Fcontainer-analysis%2FREADME.md;fp=code%2Fcontainer-analysis%2FREADME.md;h=d48fd6a19a19596564b01feec6e31222ce4cd7be;hb=fb9580f69f168bc3e93188ec9f87249d2f21e724;hp=0000000000000000000000000000000000000000;hpb=013453c7fdfa031eff560869cb9a64f9d89e0b5f;p=oam.git diff --git a/code/container-analysis/README.md b/code/container-analysis/README.md new file mode 100644 index 0000000..d48fd6a --- /dev/null +++ b/code/container-analysis/README.md @@ -0,0 +1,31 @@ +# Container Analysis + +This directory contains a script to output Software Bill of Materials (SBOM)tree and vulnerabilities of running docker images. + +## Prerequisites + +The script depend on the [Syft](https://github.com/anchore/syft) project and the [Grype](https://github.com/anchore/grype) project. + +### Installing syft + +``` +curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b /usr/local/bin +``` + +### Installing grype + +``` +curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin +``` + +## Usage + +Once your docker containers are up and running just use: + +``` +./container-analysis.sh +``` + +Note: It takes time ... + +You will find the results in the 'out' folder. \ No newline at end of file