diff --git a/README.md b/README.md index ff40b77df126f6fd7ead5c4b8e15d9b4774fda77..6a8786a1345a4ebfcaf1a58551bf9aeff1c1fe1b 100644 --- a/README.md +++ b/README.md @@ -416,7 +416,7 @@ It is bound to the `package-test` stage, and uses the following variables: | `trivy-addr` / `DOCKER_TRIVY_ADDR` | The Trivy server address (for client/server mode) | _(none: standalone mode)_ | | `trivy-security-level-threshold` / `DOCKER_TRIVY_SECURITY_LEVEL_THRESHOLD` | Severities of vulnerabilities to be displayed (comma separated values: `UNKNOWN`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`) | `UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL` | | `trivy-disabled` / `DOCKER_TRIVY_DISABLED` | Set to `true` to disable Trivy analysis | _(none)_ | -| `trivy-args` / `DOCKER_TRIVY_ARGS` | Additional [`trivy client` arguments](https://aquasecurity.github.io/trivy/v0.27.1/docs/references/cli/client/) | `--ignore-unfixed --vuln-type os --exit-on-eol 1` | +| `trivy-args` / `DOCKER_TRIVY_ARGS` | Additional [`trivy client` arguments](https://aquasecurity.github.io/trivy/v0.27.1/docs/references/cli/client/) | `--ignore-unfixed --vuln-type os --exit-on-eol 1 --detection-priority comprehensive` | | `trivy-db-repository` / `DOCKER_TRIVY_DB_REPOSITORY` | OCI repository to retrieve Trivy Database from | _none_ (use Trivy default `ghcr.io/aquasecurity/trivy-db`) | | `trivy-java-db-repository` / `DOCKER_TRIVY_JAVA_DB_REPOSITORY` | OCI repository to retrieve Trivy Java Database from | _none_ (use Trivy default `ghcr.io/aquasecurity/trivy-java-db:1`)\_ | diff --git a/kicker.json b/kicker.json index 5fa92ebfcf5182d1f637e2dd0397fa3b9b3a7196..76e465c498403f28f68126d2412fe693d8aac0c9 100644 --- a/kicker.json +++ b/kicker.json @@ -198,7 +198,7 @@ { "name": "DOCKER_TRIVY_ARGS", "description": "Additional `trivy client` arguments", - "default": "--ignore-unfixed --vuln-type os --exit-on-eol 1", + "default": "--ignore-unfixed --vuln-type os --exit-on-eol 1 --detection-priority comprehensive", "advanced": true }, { diff --git a/templates/gitlab-ci-docker.yml b/templates/gitlab-ci-docker.yml index eab79e0cd33ce2c8600679b074557e6c31ab7944..012236c9b4a95970dde566104f36a2a8ee764de5 100644 --- a/templates/gitlab-ci-docker.yml +++ b/templates/gitlab-ci-docker.yml @@ -172,7 +172,7 @@ spec: default: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL trivy-args: description: Additional `trivy client` arguments - default: --ignore-unfixed --vuln-type os --exit-on-eol 1 + default: --ignore-unfixed --vuln-type os --exit-on-eol 1 --detection-priority comprehensive trivy-db-repository: description: Custom OCI repository to retrieve Trivy Database from default: ''