oscap-docker(8) | System Administration Utilities | oscap-docker(8) |
oscap-docker - Tool for running oscap within docker container or image
oscap-docker tool can asses vulnerabilities or security compliance of running Docker containers or cold Docker images. OpenSCAP tool oscap(8) is used underneath. Definition of vulnerabilities (CVE stream) is downloaded from product vendor.
Usage: oscap-docker image IMAGE_NAME OSCAP_ARGUMENT [OSCAP_ARGUMENT...]
Run any OpenSCAP oscap(8) command within chroot of mounted docker image. Learn more about arguments in oscap(8) man page.
Usage: oscap-docker container CONTAINER_NAME OSCAP_ARGUMENT [OSCAP_ARGUMENT...]
Run any OpenSCAP oscap(8) command within chroot of mounted docker container. Result of this command may differ from scanning just an image due to defined mount points.
Usage: oscap-docker image-cve IMAGE_NAME [--results oval-results-file.xml [--report report.html]]
Attach docker image, determine OS variant/version, download CVE stream applicable to the given OS, and finally run vulnerability scan.
Usage: oscap-docker container-cve CONTAINER_NAME [--results oval-results-file.xml [--report report.html]]
Chroot to running container, determine OS variant/version, download CVE stream applicable to the given OS and finally run a vulnerability scan.
In order to use different oscap(8) binary pass it like --oscap=<path/to/oscap>, as the first argument.
Please report bugs using https://github.com/OpenSCAP/openscap/issues
Šimon Lukašík <slukasik@redhat.com>
January 2016 | Red Hat, Inc. |