1
0
mirror of https://github.com/projectatomic/atomic.git synced 2026-02-06 12:45:57 +01:00

5 Commits

Author SHA1 Message Date
Brent Baude
4672f98423 atomic.d/openscap: Fix race condition (bz #1368896)
There is a race condition in oscpd where it sometimes fails to scan
because of a threading issue.  While that is resolved upstream, we
set the max number of threads to 1 to avoid it.

This resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1368896

Closes: #692
Approved by: rhatdan
2016-10-10 21:01:28 +00:00
Martin Preisler
6f7d8f9905 atomic.d/openscap - use custom_args to expose config file for openscap-daemon
Closes: #413
Approved by: baude
2016-06-06 19:18:23 +00:00
Brent Baude
d4bea69183 Define openscap image
The fully qualified name of the openscap image is:
  registry.access.redhat.com/rhel7/openscap

Closes: #407
Approved by: baude
2016-06-06 18:46:57 +00:00
Brent Baude
cca4d0e5ae atomic.d/openscap: Do standard compliance scan without CVEs
When conducting a compliance scan, we do not want to check CVES
as that is done by the default scan.
2016-04-18 14:05:27 -05:00
Brent Baude
6ed4994b0d Implement generic scanning in Atomic
As more scanners besides openscap become available, atomic
can now begin to leverage them.  The new scan function has
been broken out into its on file (scan.py).

The scan command itself now defaults to openscap but can
also be switched to blackduck with --scanner.

Atomic now can use a configuration file which is stored
in /etc/atomic.conf.  The location of the atomic conf
file can be overriden with the environment variable
'ATOMIC_CONF'.  In the case of the scan function,
we need the scanner defined in the configuration file
as well as the fully qualified image name and the
scan arguments.  Optionally, you can provide additional
custom docker arguments for the scanner as well
2016-04-07 09:33:00 -05:00