INNER CODE UNIT · Python

run_trivy

valqore/valqore · benchmarks/run_benchmark.py:175

def run_trivy() -> dict:
    if not shutil.which("trivy"):
        return {"available": False}
    data = _run_json(["trivy", "config", str(CORPUS), "--format", "json", "--quiet"])
    if not data:
        return {"available": False}
    failed = 0
    try:
        for res in (data.get("Results", []) if isinstance(data, dict) else []):
            failed += len(res.get("Misconfigurations", []) or [])
    except Exception:
        pass
    return {"available": True, "failed": failed, "scope": "IaC/K8s/Dockerfile misconfig only"}


def run_kube_score() -> dict:
    # kube-score is K8s-manifest-only; it ignores Terraform/Dockerfile. We point
    # it at the YAML manifests in the corpus and count CRITICAL/WARNING checks.

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…