Skip to content

Feature/lab4#483

Open
alsstarikova wants to merge 5 commits intoinno-devops-labs:mainfrom
alsstarikova:feature/lab4
Open

Feature/lab4#483
alsstarikova wants to merge 5 commits intoinno-devops-labs:mainfrom
alsstarikova:feature/lab4

Conversation

@alsstarikova
Copy link

@alsstarikova alsstarikova commented Mar 2, 2026

Goal

Generate Software Bills of Materials (SBOMs) for OWASP Juice Shop using Syft and Trivy, perform comprehensive Software Composition Analysis with Grype and Trivy, then compare the toolchain capabilities.

Changes

  • Added labs/submission4.md with analysis for all three tasks
  • Added labs/lab4/ with all generated SBOMs, vulnerability reports, and comparison data from Syft, Trivy, and Grype scans

Testing

All Docker commands from lab instructions were executed successfully. Outputs verified with jq and manual review.

Artifacts & Screenshots

Evidence demonstrating completion attached in labs/submission4.md. All reports and scans placed in labs/lab4

Pre-submission Checklist

  • PR title is clear and descriptive
  • Documentation updated
  • No secrets, credentials, or large temp files committed
  • Task 1 done — SBOM Generation with Syft and Trivy
  • Task 2 done — SCA with Grype and Trivy
  • Task 3 done — Comprehensive Toolchain Comparison

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant