From nobody Tue Mar 26 07:57:12 2024 X-Original-To: dev-commits-ports-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4V3hwS60DGz5F4rw; Tue, 26 Mar 2024 07:57:12 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4V3hwS5DR3z46S2; Tue, 26 Mar 2024 07:57:12 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1711439832; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=lfYsV4zI2n8kXl9/gO/de53QhEmNKF5sOKdRbxPCsIs=; b=TKyZwr7d+SuxPNHiJJb34UYbZ+WWJD9s5Otzrk4OMMVJvrsMrCVAR6kHCODCbqeJ9Xsqed l5miDqiv2hJv6cCkAG57PJgiFfNeG2eMEX1Z8+eU1ZpiHRoPkChEu2gQtV/G/vMBmll8Sj XSsHr8t7jMKzvHhAgJ4vcu+hkNZkaawFU8kyOHngnMp8Rd/RrTjeiaizsi5FxVb0wXqLOG yz7kB+UgmhtltAeoykYuGhgjfTUlrV4CahF3SB/55pO6MM9n6yA44C69VgcX0DMs6J7fVP 8u4v1i9hueukhA9Wjn2YXaM+P+XUqGigsFqOVOfUj0sHSZqHmjFk+j3hx2X4Ww== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1711439832; a=rsa-sha256; cv=none; b=ad30h5bg6Qrb62Ia4LuaoyHxA81w0k6SmamaOS35Ype9lNiOFITedywe//tnUdnmZKY6rc FzqO3f08+/8faH6IcR80s4evJAg4Jouo49S9QJjZuHedLJPxZwiX5+OWhUl4AippY4fhyh q/hMvmBt07qBJmTJia1UCOZiC5ppQn4sycALwTxJsF7wA2i1W11vDHBhWxfxw6gcH4miYd Nnrb8SzqPTSuA40D5gMmN6EhyVygpLXg1ENn+IDUqY83pxuTvm3yIxNyn3qYebS24Ok8xp 7aNN1eunBVVLhxVlR9zfO1F8VQCY/dlTbkY4jrolgGzjuPUjc6xAk8k9h6qt0A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1711439832; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=lfYsV4zI2n8kXl9/gO/de53QhEmNKF5sOKdRbxPCsIs=; b=j66jJVg9WuwbcDx3b9Ng9ceHNwuphFWX3KX0eAJm2NLm39yJj4+ZXgKiWMcztRKW5HRFtB bypDZY4n1jpP7euejgW50Lzb8e89oDRYkwrWHSU/fUuqKFD7khRNTmFjHtouF1ugHHd3Uo 6ou4eTbnB0T46dN7oQTHeDdJSy4e+T9pyRemvctgaEHhW+exjqswlRMsh/XXwBoBrx/qkr fAmjtczril56YehdYRfXDUy/2GF9ibntK6xb/PM5R9cEPM0+RZVdJaDVfZbIfDROsKjK9R +YHp9Hzmq8m6h1weql+89lmJh35v+J58X3RIlnNcPj2vUlixwpJuHEnR9qypRg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4V3hwS4q06zs3C; Tue, 26 Mar 2024 07:57:12 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 42Q7vC8e006203; Tue, 26 Mar 2024 07:57:12 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 42Q7vCDI006200; Tue, 26 Mar 2024 07:57:12 GMT (envelope-from git) Date: Tue, 26 Mar 2024 07:57:12 GMT Message-Id: <202403260757.42Q7vCDI006200@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Matthias Fechner Subject: git: 1d8a7133d438 - 2024Q1 - ecurity/trivy: add a new security scanner List-Id: Commits to the quarterly branches of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-branches@freebsd.org X-BeenThere: dev-commits-ports-branches@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: mfechner X-Git-Repository: ports X-Git-Refname: refs/heads/2024Q1 X-Git-Reftype: branch X-Git-Commit: 1d8a7133d438ce6028011488b2fa70cb53e3975a Auto-Submitted: auto-generated The branch 2024Q1 has been updated by mfechner: URL: https://cgit.FreeBSD.org/ports/commit/?id=1d8a7133d438ce6028011488b2fa70cb53e3975a commit 1d8a7133d438ce6028011488b2fa70cb53e3975a Author: Matthias Fechner AuthorDate: 2024-03-09 05:35:43 +0000 Commit: Matthias Fechner CommitDate: 2024-03-26 07:56:28 +0000 ecurity/trivy: add a new security scanner Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more (cherry picked from commit f08836ef7bded933702cdd8119ce12f68fd46883) --- security/Makefile | 1 + security/trivy/Makefile | 26 ++++++++++++++++++++++++++ security/trivy/distinfo | 5 +++++ security/trivy/pkg-descr | 2 ++ 4 files changed, 34 insertions(+) diff --git a/security/Makefile b/security/Makefile index c61c48bcc171..3e91032996ef 100644 --- a/security/Makefile +++ b/security/Makefile @@ -1333,6 +1333,7 @@ SUBDIR += transcrypt SUBDIR += trezord SUBDIR += tripwire + SUBDIR += trivy SUBDIR += trousers SUBDIR += trufflehog SUBDIR += tthsum diff --git a/security/trivy/Makefile b/security/trivy/Makefile new file mode 100644 index 000000000000..44282f9226e1 --- /dev/null +++ b/security/trivy/Makefile @@ -0,0 +1,26 @@ +PORTNAME= trivy +DISTVERSION= 0.49.1 +DISTVERSIONPREFIX= v +CATEGORIES= security + +MAINTAINER= mfechner@FreeBSD.org +COMMENT= Security scanner written in go +WWW= https://github.com/aquasecurity/trivy + +LICENSE= APACHE20 +LICENSE_FILE= ${WRKSRC}/LICENSE + +USES= go:modules,1.21 + +GO_MODULE= github.com/aquasecurity/trivy +GO_TARGET= ./cmd/trivy +GO_BUILDFLAGS= -ldflags=" \ + -extldflags '-static' \ + -X github.com/aquasecurity/trivy/pkg/version.ver=${DISTVERSION} \ + -s -w" + +PLIST_FILES= bin/${PORTNAME} + + + +.include diff --git a/security/trivy/distinfo b/security/trivy/distinfo new file mode 100644 index 000000000000..61d83462dc59 --- /dev/null +++ b/security/trivy/distinfo @@ -0,0 +1,5 @@ +TIMESTAMP = 1709899091 +SHA256 (go/security_trivy/trivy-v0.49.1/v0.49.1.mod) = 49e23b72ebeef255b19969704ddf58c118888efad7058ae732cb5701b15b1145 +SIZE (go/security_trivy/trivy-v0.49.1/v0.49.1.mod) = 22827 +SHA256 (go/security_trivy/trivy-v0.49.1/v0.49.1.zip) = 71fd4e3d5abf9e7fdcff4b844cdfdd28cac91a78d36c22de1f581e4bafbe567f +SIZE (go/security_trivy/trivy-v0.49.1/v0.49.1.zip) = 40379854 diff --git a/security/trivy/pkg-descr b/security/trivy/pkg-descr new file mode 100644 index 000000000000..bc47a5f20e4f --- /dev/null +++ b/security/trivy/pkg-descr @@ -0,0 +1,2 @@ +Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, +code repositories, clouds and more