mirror of https://github.com/docker/docs.git
Merge pull request #20543 from felipecruz91/scout-release-notes-v1.13.0
add release notes for docker scout v1.13.0
This commit is contained in:
commit
2c51a10815
|
@ -136,6 +136,16 @@ options:
|
|||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: only-policy
|
||||
value_type: stringSlice
|
||||
default_value: '[]'
|
||||
description: Comma separated list of policies to evaluate
|
||||
deprecated: false
|
||||
hidden: false
|
||||
experimental: false
|
||||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: only-severity
|
||||
value_type: stringSlice
|
||||
default_value: '[]'
|
||||
|
|
|
@ -124,6 +124,17 @@ options:
|
|||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: ignore-suppressed
|
||||
value_type: bool
|
||||
default_value: "false"
|
||||
description: |
|
||||
Filter CVEs found in Scout exceptions based on the specified exception scope
|
||||
deprecated: false
|
||||
hidden: false
|
||||
experimental: false
|
||||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: locations
|
||||
value_type: bool
|
||||
default_value: "false"
|
||||
|
|
|
@ -30,6 +30,16 @@ options:
|
|||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: only-policy
|
||||
value_type: stringSlice
|
||||
default_value: '[]'
|
||||
description: Comma separated list of policies to evaluate
|
||||
deprecated: false
|
||||
hidden: false
|
||||
experimental: false
|
||||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: org
|
||||
value_type: string
|
||||
description: Namespace of the Docker organization
|
||||
|
|
|
@ -46,6 +46,17 @@ options:
|
|||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: ignore-suppressed
|
||||
value_type: bool
|
||||
default_value: "false"
|
||||
description: |
|
||||
Filter CVEs found in Scout exceptions based on the specified exception scope
|
||||
deprecated: false
|
||||
hidden: false
|
||||
experimental: false
|
||||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: latest
|
||||
value_type: bool
|
||||
default_value: "false"
|
||||
|
@ -56,6 +67,16 @@ options:
|
|||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: only-policy
|
||||
value_type: stringSlice
|
||||
default_value: '[]'
|
||||
description: Comma separated list of policies to evaluate
|
||||
deprecated: false
|
||||
hidden: false
|
||||
experimental: false
|
||||
experimentalcli: false
|
||||
kubernetes: false
|
||||
swarm: false
|
||||
- option: only-vex-affected
|
||||
value_type: bool
|
||||
default_value: "false"
|
||||
|
|
|
@ -19,6 +19,7 @@ Compare two images and display differences (experimental)
|
|||
| `--multi-stage` | | | Show packages from multi-stage Docker builds |
|
||||
| `--only-fixed` | | | Filter to fixable CVEs |
|
||||
| `--only-package-type` | `stringSlice` | | Comma separated list of package types (like apk, deb, rpm, npm, pypi, golang, etc) |
|
||||
| `--only-policy` | `stringSlice` | | Comma separated list of policies to evaluate |
|
||||
| `--only-severity` | `stringSlice` | | Comma separated list of severities (critical, high, medium, low, unspecified) to filter CVEs by |
|
||||
| `--only-stage` | `stringSlice` | | Comma separated list of multi-stage Docker build stage names |
|
||||
| `--only-unfixed` | | | Filter to unfixed CVEs |
|
||||
|
|
|
@ -19,6 +19,7 @@ Display CVEs identified in a software artifact
|
|||
| `-e`, `--exit-code` | | | Return exit code '2' if vulnerabilities are detected |
|
||||
| `--format` | `string` | `packages` | Output format of the generated vulnerability report:<br>- packages: default output, plain text with vulnerabilities grouped by packages<br>- sarif: json Sarif output<br>- spdx: json SPDX output<br>- gitlab: json GitLab output<br>- markdown: markdown output (including some html tags like collapsible sections)<br>- sbom: json SBOM output<br> |
|
||||
| `--ignore-base` | | | Filter out CVEs introduced from base image |
|
||||
| `--ignore-suppressed` | | | Filter CVEs found in Scout exceptions based on the specified exception scope |
|
||||
| `--locations` | | | Print package locations including file paths and layer diff_id |
|
||||
| `--multi-stage` | | | Show packages from multi-stage Docker builds |
|
||||
| `--only-base` | | | Only show CVEs introduced by the base image |
|
||||
|
|
|
@ -6,8 +6,9 @@ Evaluate policies against an image and display the policy evaluation results (ex
|
|||
### Options
|
||||
|
||||
| Name | Type | Default | Description |
|
||||
|:--------------------|:---------|:--------|:------------------------------------------------------------|
|
||||
|:--------------------|:--------------|:--------|:------------------------------------------------------------|
|
||||
| `-e`, `--exit-code` | | | Return exit code '2' if policies are not met, '0' otherwise |
|
||||
| `--only-policy` | `stringSlice` | | Comma separated list of policies to evaluate |
|
||||
| `--org` | `string` | | Namespace of the Docker organization |
|
||||
| `-o`, `--output` | `string` | | Write the report to a file |
|
||||
| `--platform` | `string` | | Platform of image to pull policy results from |
|
||||
|
|
|
@ -12,7 +12,9 @@ Quick overview of an image
|
|||
| Name | Type | Default | Description |
|
||||
|:----------------------|:--------------|:--------|:--------------------------------------------------------------------------------------------------------|
|
||||
| `--env` | `string` | | Name of the environment |
|
||||
| `--ignore-suppressed` | | | Filter CVEs found in Scout exceptions based on the specified exception scope |
|
||||
| `--latest` | | | Latest indexed image |
|
||||
| `--only-policy` | `stringSlice` | | Comma separated list of policies to evaluate |
|
||||
| `--only-vex-affected` | | | Filter CVEs by VEX statements with status not affected |
|
||||
| `--org` | `string` | | Namespace of the Docker organization |
|
||||
| `-o`, `--output` | `string` | | Write the report to a file |
|
||||
|
|
|
@ -3,4 +3,4 @@
|
|||
# github.com/docker/buildx v0.16.2
|
||||
# github.com/docker/cli v27.0.3+incompatible
|
||||
# github.com/docker/compose/v2 v2.29.1
|
||||
# github.com/docker/scout-cli v1.12.0
|
||||
# github.com/docker/scout-cli v1.13.0
|
||||
|
|
|
@ -8,6 +8,25 @@ This page contains information about the new features, improvements, known
|
|||
issues, and bug fixes in the Docker Scout [CLI plugin](https://github.com/docker/scout-cli/)
|
||||
and the `docker/scout-action` [GitHub Action](https://github.com/docker/scout-action).
|
||||
|
||||
## 1.13.0
|
||||
|
||||
{{< release-date date="2024-08-05" >}}
|
||||
|
||||
### New
|
||||
|
||||
- Add `--only-policy` filter option to the `docker scout quickview`, `docker scout policy` and `docker scout compare` commands.
|
||||
- Add `--ignore-suppressed` filter option to `docker scout cves` and `docker scout quickview` commands to filter out CVEs affected by [exceptions](/scout/explore/exceptions/).
|
||||
|
||||
### Bug fixes and enhancements
|
||||
|
||||
- Use conditional policy name in checks.
|
||||
- Add support for detecting the version of a Go project set using linker flags,
|
||||
for example:
|
||||
|
||||
```console
|
||||
$ go build -ldflags "-X main.Version=1.2.3"
|
||||
```
|
||||
|
||||
## 1.12.0
|
||||
|
||||
{{< release-date date="2024-07-31" >}}
|
||||
|
|
4
go.mod
4
go.mod
|
@ -8,7 +8,7 @@ require (
|
|||
github.com/docker/buildx v0.16.2 // indirect
|
||||
github.com/docker/cli v27.0.3+incompatible // indirect
|
||||
github.com/docker/compose/v2 v2.29.1 // indirect
|
||||
github.com/docker/scout-cli v1.12.0 // indirect
|
||||
github.com/docker/scout-cli v1.13.0 // indirect
|
||||
github.com/moby/buildkit v0.15.1 // indirect
|
||||
github.com/moby/moby v27.0.3+incompatible // indirect
|
||||
)
|
||||
|
@ -17,7 +17,7 @@ replace (
|
|||
github.com/docker/buildx => github.com/docker/buildx v0.16.2
|
||||
github.com/docker/cli => github.com/docker/cli v27.0.3+incompatible
|
||||
github.com/docker/compose/v2 => github.com/docker/compose/v2 v2.29.0
|
||||
github.com/docker/scout-cli => github.com/docker/scout-cli v1.12.0
|
||||
github.com/docker/scout-cli => github.com/docker/scout-cli v1.13.0
|
||||
github.com/moby/buildkit => github.com/moby/buildkit v0.15.1
|
||||
github.com/moby/moby => github.com/moby/moby v27.0.3+incompatible
|
||||
)
|
||||
|
|
2
go.sum
2
go.sum
|
@ -204,6 +204,8 @@ github.com/docker/scout-cli v1.11.0 h1:I310kNhjw3oeKe8T1cQEh6yPgy6VtpuwzjWchETn8
|
|||
github.com/docker/scout-cli v1.11.0/go.mod h1:Eo1RyCJsx3ldz/YTY5yGxu9g9mwTYbRUutxQUkow3Fc=
|
||||
github.com/docker/scout-cli v1.12.0 h1:NhmT4BzL2lYiIk5hPFvK5FzQ8izbLDL3/Rugcyulv1M=
|
||||
github.com/docker/scout-cli v1.12.0/go.mod h1:Eo1RyCJsx3ldz/YTY5yGxu9g9mwTYbRUutxQUkow3Fc=
|
||||
github.com/docker/scout-cli v1.13.0 h1:RThUM56yooV5izqgMEYQS+a6Yx+vGmZofJwX0qjgkco=
|
||||
github.com/docker/scout-cli v1.13.0/go.mod h1:Eo1RyCJsx3ldz/YTY5yGxu9g9mwTYbRUutxQUkow3Fc=
|
||||
github.com/elazarl/goproxy v0.0.0-20191011121108-aa519ddbe484/go.mod h1:Ro8st/ElPeALwNFlcTpWmkr6IoMFfkjXAvTHpevnDsM=
|
||||
github.com/evanphx/json-patch v4.9.0+incompatible/go.mod h1:50XU6AFN0ol/bzJsmQLiYLvXMP4fmwYFNcr97nuDLSk=
|
||||
github.com/fatih/color v1.7.0/go.mod h1:Zm6kSWBoL9eyXnKyktHP6abPY2pDugNf5KwzbycvMj4=
|
||||
|
|
Loading…
Reference in New Issue