Add Grafeas v1 protos and vendor Go modules for v1.1.7 live ebuild Include Grafeas v1 compliance/severity protos (0163b5bb2ff5), generated proto packages, and go mod vendor output so the 9999 live ebuild can compile protos and build with -mod=vendor. BUG=b/561623359 TEST=CGO_ENABLED=0 go build -mod=vendor localtoast.go RELEASE_NOTE=None cos-patch: bug Change-Id: I9aeb99372389a05cfd86257a4b746ab7b739e0fd
Localtoast is a scanner for running security-related configuration checks such as CIS benchmarks in an easily configurable manner.
The scanner can either be used as a standalone binary to scan the local machine or as a library with a custom wrapper to perform scans on e.g. container images or remote hosts.
makesudo ./localtoast --config=configs/example.textproto --result=scan-result.textprotomake configssudo ./localtoast --config=configs/full/cos_97/instance_scanning.textproto --result=scan-result.textprotomake configsmake localtoast_sqlsudo localtoast_sql/localtoast_sql --config=configs/full/cassandra-cql/instance_scanning.textproto --result=scan-result.textproto --cassandra-database=localhost:9042github.com/google/localtoast/scannerlib and github.com/google/localtoast/scanapi into your Go projectscanapi.ScanAPI interfacescannerlib.Scanner{}.Scan() with the appropriate config and the implementationSee the scan config and result protos for details on the input+output format.
To add your own checks to a scan config,
make configssudo ./localtoast --config=configs/full/cos_97/instance_scanning.textproto --result=scan-result.textprotoTo build Localtoast, you'll need to have the following installed:
go: Follow https://go.dev/doc/installprotoc: Install the appropriate package, e.g. apt install protobuf-compilerprotoc-gen-go: Run go install google.golang.org/protobuf/cmd/protoc-gen-goRead how to contribute to Localtoast.
Localtoast is released under the Apache 2.0 license.
Copyright 2021 Google Inc.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
Localtoast is not an official Google product.