Skip to main content

ocean-trivy-verify

Verify CVE/image-vulnerability fixes for ocean (Nx Cloud / Polygraph) docker images by building the real image locally and scanning it with the exact trivy version our trivy-operator deploys. Covers finding where a flagged package actually lives (base-image npm bundle vs app node_modules vs inlined esbuild code), the scoped rego ignorePolicy escape hatch in cloud-infrastructure, and the disk/JSON gotchas. Triggers on "trivy", "verify CVE fix", "scan the image", "image vulnerability", "trivy alert", "is the CVE gone", "check the docker image for vulns".

Aller à l'installation

Informations de source

Dépôt
jaysoo/dot-ai-config
Dernière activité de la source
29 juillet 2026 à 15:45
Langue détectée de SKILL.md
anglais
Étoiles
1
Forks
0

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.