aquasecurity/trivy

feat: add flag to pass credentials to different Git hosting platforms

Open

#6,833 opened on 2024年5月31日

GitHub で見る
 (1 comment) (6 reactions) (0 assignees)Go (35,000 stars) (371 forks)batch import
help wantedkind/featuretarget/repository

説明

Discussed in https://github.com/aquasecurity/trivy/discussions/6832

Originally posted by psg18dhc May 31, 2024

Description

I noticed that when using BitBucket private repositories it's not possible to scan my code repo as i get auth errors.

GITHUB_TOKEN and GITLAB_TOKEN env vars do not work (because it's not a GitHub repo)

Is there a way to do this securely without having to make the repo public ?

i.e can we have a BITBUCKET_TOKEN env var specifically for this purpose ?

Regards Daniel C

Target

Git Repository

Scanner

None

コントリビューターガイド