Skip to content

Feature/lab4#490

Open
kvassoedik wants to merge 7 commits intoinno-devops-labs:mainfrom
kvassoedik:feature/lab4
Open

Feature/lab4#490
kvassoedik wants to merge 7 commits intoinno-devops-labs:mainfrom
kvassoedik:feature/lab4

Conversation

@kvassoedik
Copy link

Goal

Complete Lab 4 by generating SBOMs for OWASP Juice Shop, performing vulnerability analysis, and comparing Syft+Grype with Trivy.

Changes

  • Generated SBOMs using Syft and Trivy
  • Performed SCA with Grype and Trivy
  • Added quantitative metrics and analysis to labs/submission4.md
  • Included generated reports in labs/lab4/

Testing

  • Verified SBOM files were successfully generated
  • Confirmed vulnerability scans produced results
  • Compared package counts and critical vulnerabilities between tools

Artifacts & Screenshots

  • labs/submission4.md
  • labs/lab4/syft/
  • labs/lab4/trivy/

Checklist

  • Task 1 done — SBOM generation with Syft and Trivy
  • Task 2 done — SCA with Grype and Trivy
  • Task 3 done — Toolchain comparison and recommendations
  • All required artifacts committed
  • No secrets or unnecessary large files committed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant