You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package
(implicit)
name:my-package
(explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true
(prereleases)
prerelease:false
(no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo
for negation
For string queries, you can use:
^foo
to anchor to start of term
foo$
to anchor to end of term
foo*bar
for fuzzy matching
For number/date or version queries, you can use:
>foo
for values greater than
>=foo
for values greater / equal
<foo
for values less than
<=foo
for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Go,
Helm,
Hex,
LuaRocks,
Maven,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
sonar-scanner
7115904281b236e361cfd3e0b8c…
One-liner (summary)
Description
This package was uploaded with the following V2 Distribution manifest:
{
"schemaVersion": 2,
"mediaType": "application/vnd.docker.distribution.manifest.v2+json",
"config": {
"mediaType": "application/vnd.docker.container.image.v1+json",
"size": 6025,
"digest": "sha256:ea3b0c2203ad96fa8d0505027a647df1a34b23609baa77fe488171e6c5cf1fd6"
},
"layers": [
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 3379404,
"digest": "sha256:3c854c8cbf469fda815b8f6183300c07cfa2fbb5703859ca79aff93ae934961b"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 32,
"digest": "sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 119888205,
"digest": "sha256:abe98265d20621af12bd6fb29184dbcc565b6e4962601ebc2588cb9dc3c5b36b"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 723,
"digest": "sha256:c49a837592579e418683af4151503325beb5cb4b1ca4fc45e1267c6c2483ecce"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 32,
"digest": "sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 89384835,
"digest": "sha256:911dda69debdbc09df6fe10bbc0c4a5414c2eb2d251d20bceaed85131ea78dcb"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 1725058,
"digest": "sha256:58385b5db76cefd1e35f7f0697aa0331337c70e25c470e598fc66ad03cdbd73a"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 1115,
"digest": "sha256:141b303f6f38fb61b6eb875dd91b8b0177aa7744666e7325d28ebaa5bdbf0c45"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 126,
"digest": "sha256:e6d3eae474c6fce388e0ad72286f1b6a553d3bb76ca206248886289ccf527647"
}
]
}
Digest:
sha256:3c854c8cbf469fda815b8f6183300c07cfa2fbb5703859ca79aff93ae934961b
Command: /bin/sh -c #(nop) ADD file:c44c9bd36ba35cc78fb9396304ea008def9f42a3beef76aa33b2cf1fde1c10b3 in / |
3.2 MB | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/sh"] |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: LABEL org.opencontainers.image.url=https://github.com/SonarSource/sonar-scanner-cli-docker |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG SONAR_SCANNER_HOME=/opt/sonar-scanner |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG SONAR_SCANNER_VERSION |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG UID=1000 |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG GID=1000 |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV JAVA_HOME=/usr/lib/jvm/java-17-openjdk HOME=/tmp XDG_CONFIG_HOME=/tmp SONAR_SCANNER_HOME=/opt/sonar-scanner SONAR_USER_HOME=/opt/sonar-scanner/.sonar PATH=/opt/sonar-scanner/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin NODE_PATH=/usr/lib/node_modules SRC_PATH=/usr/src LANG=en_US.UTF-8 LC_ALL=en_US.UTF-8 |
32 bytes | ||
Digest:
sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1
Command: WORKDIR /opt |
32 bytes | ||
Digest:
sha256:abe98265d20621af12bd6fb29184dbcc565b6e4962601ebc2588cb9dc3c5b36b
Command: RUN |4 SONAR_SCANNER_HOME=/opt/sonar-scanner SONAR_SCANNER_VERSION=5.0.1.3006 UID=1000 GID=1000 /bin/sh -c set -eux; addgroup -S -g ${GID} scanner-cli; adduser -S -D -u ${UID} -G scanner-cli scanner-cli; apk add --no-cache --virtual build-dependencies wget unzip gnupg; apk add --no-cache git python3 py-pip bash shellcheck 'nodejs>12' openjdk17-jre curl musl-locales musl-locales-lang; wget -U "scannercli" -q -O /opt/sonar-scanner-cli.zip https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-${SONAR_SCANNER_VERSION}.zip; wget -U "scannercli" -q -O /opt/sonar-scanner-cli.zip.asc https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-${SONAR_SCANNER_VERSION}.zip.asc; for server in $(shuf -e hkps://keys.openpgp.org hkps://keyserver.ubuntu.com) ; do gpg --batch --keyserver "${server}" --recv-keys 679F1EE92B19609DE816FDE81DB198F93525EC1A && break || : ; done; gpg --verify /opt/sonar-scanner-cli.zip.asc /opt/sonar-scanner-cli.zip; unzip sonar-scanner-cli.zip; rm sonar-scanner-cli.zip sonar-scanner-cli.zip.asc; mv sonar-scanner-${SONAR_SCANNER_VERSION} ${SONAR_SCANNER_HOME}; pip install --no-cache-dir --upgrade pip; pip install --no-cache-dir pylint; apk del --purge build-dependencies; mkdir -p "${SRC_PATH}" "${SONAR_USER_HOME}" "${SONAR_USER_HOME}/cache"; chown -R scanner-cli:scanner-cli "${SONAR_SCANNER_HOME}" "${SRC_PATH}"; chmod -R 777 "${SRC_PATH}" "${SONAR_USER_HOME}"; # buildkit |
114.3 MB | ||
Digest:
sha256:c49a837592579e418683af4151503325beb5cb4b1ca4fc45e1267c6c2483ecce
Command: COPY bin /usr/bin/ # buildkit |
723 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/tmp/cacerts] |
32 bytes | ||
Digest:
sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1
Command: WORKDIR /usr/src |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/bin/entrypoint.sh"] |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: CMD ["sonar-scanner"] |
32 bytes | ||
Digest:
sha256:911dda69debdbc09df6fe10bbc0c4a5414c2eb2d251d20bceaed85131ea78dcb
Command: RUN /bin/sh -c apk upgrade --no-cache && apk add --no-cache python3 py3-pip # buildkit |
85.2 MB | ||
Digest:
sha256:58385b5db76cefd1e35f7f0697aa0331337c70e25c470e598fc66ad03cdbd73a
Command: RUN /bin/sh -c pip install requests # buildkit |
1.6 MB | ||
Digest:
sha256:141b303f6f38fb61b6eb875dd91b8b0177aa7744666e7325d28ebaa5bdbf0c45
Command: COPY wrapper.py /usr/local/bin # buildkit |
1.1 KB | ||
Digest:
sha256:e6d3eae474c6fce388e0ad72286f1b6a553d3bb76ca206248886289ccf527647
Command: WORKDIR /data |
126 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["wrapper.py"] |
32 bytes |
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
28324 |
![]() |
||
![]() |
sonar-scanner |
69205 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
1 |
![]() |
||
![]() |
sonar-scanner |
6244 |
![]() |
||
![]() |
sonar-scanner |
12943 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
0 |
![]() |
||
![]() |
sonar-scanner |
4 |
![]() |
||
![]() |
sonar-scanner |
146438 |
![]() |
Last scanned
1 month, 3 weeks ago
Scan result
Vulnerable
Vulnerability count
1
Max. severity
MediumTarget: | Java | |
MEDIUM |
CVE-2023-3635: okio: GzipSource class improper exception handlingGzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.Package Name: com.squareup.okio:okio Installed Version: 1.17.2 Fixed Version: 3.4.0, 1.17.6 References: access.redhat.com github.com github.com github.com github.com github.com github.com nvd.nist.gov research.jfrog.com research.jfrog.com www.cve.org |
These instructions assume you have setup the repository first (or read it).
To pull sonar-scanner @ reference/tag latest:
docker pull docker.myob.com/appsec/sonar-scanner:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM docker.myob.com/appsec/sonar-scanner:latest
Note: You should replace latest with an alternative reference to pull, such as: preprod and d61b9f591f1b0bdd8cfcf50ad8a3aea971c302e6.