Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upcoming Trivy integration is awesome, but a bit slow #3570

Open
2 tasks done
robert-blackman opened this issue Mar 20, 2024 · 0 comments · May be fixed by #3571
Open
2 tasks done

Upcoming Trivy integration is awesome, but a bit slow #3570

robert-blackman opened this issue Mar 20, 2024 · 0 comments · May be fixed by #3571
Labels
defect Something isn't working in triage

Comments

@robert-blackman
Copy link

robert-blackman commented Mar 20, 2024

Current Behavior

Hey! We're really looking forward to the Trivy support added in 4.11.x so we've been testing out the snapshot. We've noticed some poor performance when scanning sboms with larger numbers of components (~600+), in some cases the scan can take 10 minutes. The trivy scan itself only takes a few seconds to return a result.

It's understood that this functionality is unreleased, but I'm keen to take a run at improving it 👍

Thanks again everyone, really great project.

Steps to Reproduce

  1. Enable Trivy integration using 4.11.0-SNAPSHOT
  2. Start an analysis
  3. Make coffee
  4. Get results

Expected Behavior

Repro steps minus step 3 🙂

It would be nice to reduce the scan time as much as possible to facilitate blocking CICD pipelines.

Dependency-Track Version

4.11.0-SNAPSHOT

Dependency-Track Distribution

Container Image

Database Server

PostgreSQL

Database Server Version

15.4

Browser

N/A

Checklist

@robert-blackman robert-blackman added defect Something isn't working in triage labels Mar 20, 2024
@robert-blackman robert-blackman linked a pull request Mar 20, 2024 that will close this issue
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
defect Something isn't working in triage
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant