Simple demo for Anchore Enterprise.
Includes workflow examples for Jenkins, CircleCI, Codefresh, Drone, and GitHub.
Partial list of conditions that can be tested with this image:
- xmrig cryptominer installed at
/xmrig/xmrig
- simulated AWS access key in
/aws_access
- simulated ssh private key in
/ssh_key
- selection of commonly-blocked packages installed (sudo, curl, etc)
/log4j-core-2.14.1.jar
(CVE-2021-44228, et al)- added anchorectl to demonstrate automatic go library detection in binaries
- wide variety of ruby, node, python, java installed with different licenses
- build drift detection (see .baseline directory for Dockerfile/Jenkinsfile)
- Terraform RPM with BUSL license installed
- modify file from gzip RPM to trigger package verification gate
Secret scanning and hints file handling for distributed scanning is configured in .anchorectl.yaml