INNER CODE UNIT · Python
run_trivy
valqore/valqore · benchmarks/run_benchmark.py:175
def run_trivy() -> dict:
if not shutil.which("trivy"):
return {"available": False}
data = _run_json(["trivy", "config", str(CORPUS), "--format", "json", "--quiet"])
if not data:
return {"available": False}
failed = 0
try:
for res in (data.get("Results", []) if isinstance(data, dict) else []):
failed += len(res.get("Misconfigurations", []) or [])
except Exception:
pass
return {"available": True, "failed": failed, "scope": "IaC/K8s/Dockerfile misconfig only"}
def run_kube_score() -> dict:
# kube-score is K8s-manifest-only; it ignores Terraform/Dockerfile. We point
# it at the YAML manifests in the corpus and count CRITICAL/WARNING checks.