trivy-to-sonarqube
v1.2.0
Published
Generates a report for Sonarqube (generic issue import format) based on report trivy.
Downloads
2,305
Maintainers
Readme
Install
npm i trivy-to-sonarqube -g
Generate trivy report
trivy fs --ignorefile .trivyignore -f json -o trivy-report.json .
trivy config --ignorefile .trivyignore -f json -o trivy-report.json .
trivy image --ignorefile .trivyignore -f json -o trivy-report.json my-docker-image
Convert data to sonarqube generic issue format
trivy-to-sonarqube -f trivy-report.json -o ./my-sonarqube-report.json
Run sonar-scaner witch additional params
sonar-scanner
-Dsonar.projectKey=MyProject
-Dsonar.host.url=my-host.com
-Dsonar.login=${SONARQUBE_TOKEN}
-Dsonar.sources=.
-Dsonar.externalIssuesReportPaths=./trivy-report.json