# lysbor-scan: Syft (SBOM) + Semgrep (SAST) + Trivy (misconfig, secrets) + curl. Usage: # curl -sSfLO https://lysbor.example.com/agent/lysbor-scan.Dockerfile && curl -sSfLO https://lysbor.example.com/agent/lysbor-scan.sh # docker build -t lysbor-scan -f lysbor-scan.Dockerfile . (both files are served by your Lysbor instance) # docker run --rm -v "$PWD:/src" -e LYSBOR_URL -e LYSBOR_API_KEY -e LYSBOR_PROJECT lysbor-scan --all /src # docker run --rm -e LYSBOR_URL -e LYSBOR_API_KEY -e LYSBOR_PROJECT lysbor-scan --trivy myregistry/app:1.2.3 # The container runs as an unprivileged user (scanner). Registry images are pulled directly, no Docker daemon needed; # to scan an image that only exists in the local Docker daemon, mount the socket and add its group: # docker run --rm -v /var/run/docker.sock:/var/run/docker.sock --group-add "$(stat -c %g /var/run/docker.sock)" ... lysbor-scan --trivy app:local FROM python:3.11-slim ARG SYFT_VERSION=1.52.0 ARG TRIVY_VERSION=0.74.0 ARG SEMGREP_VERSION=1.177.0 COPY lysbor-scan.sh /usr/local/bin/lysbor-scan # Syft and Trivy come from their published release archives, SHA-256 verified against the release checksum file # (lysbor-scan install-tools): nothing is piped from the network into a shell. RUN apt-get update && apt-get install -y --no-install-recommends bash curl jq ca-certificates git \ && rm -rf /var/lib/apt/lists/* \ && chmod +x /usr/local/bin/lysbor-scan \ && lysbor-scan install-tools --syft "${SYFT_VERSION}" --trivy "${TRIVY_VERSION}" \ && pip install --no-cache-dir "semgrep==${SEMGREP_VERSION}" \ && useradd -m -u 10001 scanner ENV SEMGREP_SEND_METRICS=off USER scanner WORKDIR /src # A one-shot CLI: there is no long-running process to probe. HEALTHCHECK NONE ENTRYPOINT ["lysbor-scan"] CMD ["/src"]