Skip to content

feat(lab4): juice-shop SBOM + Grype/Trivy comparison + sign-ready attestation#1159

Open
ratteperk wants to merge 2 commits into
inno-devops-labs:mainfrom
ratteperk:feature/lab4
Open

feat(lab4): juice-shop SBOM + Grype/Trivy comparison + sign-ready attestation#1159
ratteperk wants to merge 2 commits into
inno-devops-labs:mainfrom
ratteperk:feature/lab4

Conversation

@ratteperk

Copy link
Copy Markdown

Goal

Generate an SBOM of the Juice Shop image with Syft, scan it with Grype, compare against Trivy's all-in-one approach, and produce a signed-ready CycloneDX SBOM for Lab 8


Changes

  • submissions/lab4.md - file with all answered questions
  • labs/lab4/juice-shop.cdx.json, labs/lab4/juice-shop.spdx.json - files generated by syft

Testing

Check files, parse by jq


Artifacts & Screenshots


  • Task 1 — Syft SBOMs + Grype scan + top-10 CVE analysis
  • Task 2 — Trivy comparison + when-to-pick-each tradeoff
  • Bonus — sign-ready CycloneDX attestation for Lab 8

@ratteperk ratteperk changed the title Feature/lab4 feat(lab4): juice-shop SBOM + Grype/Trivy comparison + sign-ready attestation Jun 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant