ztvs scan#
ztvs scan [TARGET] [OPTIONS]
| Flag | Type | Default | Description |
|---|---|---|---|
--image <REF> |
string | — | Scan an image from a registry |
--archive <PATH> |
path | — | Scan an image tarball |
--policy <PATH> |
path | — | Apply a policy file |
--attest |
flag | off | Emit a detached attestation |
--key <PATH> |
path | ambient | Signing key for --attest |
--out <PATH> |
path | stdout | Write the report to a file |
--format <FMT> |
text | json | sarif |
text |
Output format |
--severity <LEVEL> |
low…critical |
low |
Minimum severity to report |
--no-verify |
flag | off | Skip on-disk verification (faster, weaker) |
--skip-layers <N> |
integer | 0 |
Deprecated — use a policy |
--offline |
flag | off | Fail rather than fetch advisory data |
ztvs watch#
ztvs watch [TARGET] [OPTIONS]
| Flag | Type | Default | Description |
|---|---|---|---|
--interval <DUR> |
duration | 6h |
Advisory refresh interval |
--on-finding <ACTION> |
log | webhook | exec |
log |
What to do on a new finding |
--webhook-url <URL> |
url | — | Required when --on-finding webhook |
--exec <CMD> |
string | — | Required when --on-finding exec |
ztvs verify#
ztvs verify <REPORT> --attestation <PATH>
ztvs policy#
ztvs policy lint <PATH>
ztvs policy explain <PATH> --advisory <ID>
explain answers "why was this suppressed?" against a specific finding.
ztvs attest#
ztvs attest keygen --out <PATH>
ztvs attest show <PATH> [--format subject|json]
ztvs db#
ztvs db update
ztvs db status
Exit codes#
| Code | Meaning |
|---|---|
0 |
Completed, nothing to report |
1 |
Completed, unsuppressed findings present |
2 |
Could not complete |
3 |
Policy invalid, or a suppression expired |
4 |
Attestation verification failed |
Changes from 0.0.1#
- Added
watch,verify,policy,attest - Added
--policy,--attest,--key,--out,--no-verify, SARIF output - Deprecated
--skip-layers - Added exit codes
3and4 - Changed advisory ids from
RUSTSEC-*passthrough to normalisedZTVS-*, with the upstream id retained inadvisory.aliases