8 versionMetadata = import ./sysdig-cli-scanner.versions.nix;
9 fetchForSystem = versionMetadata.${stdenv.system} or (throw "unsupported system ${stdenv.system}");
12 pname = "sysdig-cli-scanner";
13 version = versionMetadata.version;
15 src = fetchurl { inherit (fetchForSystem) url hash; };
17 nativeBuildInputs = [ makeWrapper ];
24 install -Dm755 -T $src $out/bin/sysdig-cli-scanner
26 wrapProgram $out/bin/sysdig-cli-scanner \
27 --add-flags --dbpath="\$HOME/.cache/sysdig-cli-scanner/"
32 passthru.updateScript = ./update.sh;
35 description = "Tool for scanning container images and directories using Sysdig";
37 The Sysdig Vulnerability CLI Scanner, sysdig-cli-scanner, is a versatile tool designed to
38 manually scan container images and directories, whether they are located locally or remotely.
39 Depending on your specific use case, you have the flexibility to execute sysdig-cli-scanner
40 in Vulnerability Management (VM) mode for image scanning or Infrastructure as Code (IaC) mode
41 for scanning directories.
43 homepage = "https://docs.sysdig.com/en/docs/installation/sysdig-secure/install-vulnerability-cli-scanner/";
44 mainProgram = "sysdig-cli-scanner";
45 license = licenses.unfreeRedistributable;
46 maintainers = with maintainers; [ tembleking ];
53 sourceProvenance = with sourceTypes; [ binaryNativeCode ];