Trivy v0.49.1使用HTML模板输出无结果问题求助
解决Trivy v0.49.1生成HTML报告无内容的问题
你遇到的问题确实是旧模板和新版Trivy的输出结构不匹配导致的——v0.49.1的扫描结果字段和旧模板里的变量对应不上,所以即使检测到结果,模板也没法渲染出来。
解决步骤:
先搞清楚当前Trivy的输出结构
先把扫描结果导出成JSON,查看具体字段:trivy config . --format json > result.json打开这个JSON文件,能看到结果是包含
Results数组的结构,每个Result里有Target、Type、Findings等字段,Findings里才是具体的漏洞信息。使用适配v0.49.1的HTML模板
旧模板用的变量已失效,需要用匹配当前字段的模板。下面是一个基础可用的模板示例,保存为html.tpl放在当前目录:<!DOCTYPE html> <html> <head> <meta charset="UTF-8"> <title>Trivy扫描报告</title> <style> body { font-family: Arial, sans-serif; margin: 20px; } .scan-section { margin-bottom: 30px; padding: 15px; border: 1px solid #eee; border-radius: 6px; } .finding-item { margin: 10px 0; padding: 10px; border-radius: 4px; } .critical { background-color: #ffebee; border-left: 4px solid #c62828; } .high { background-color: #fff3e0; border-left: 4px solid #ef6c00; } .medium { background-color: #fff8e1; border-left: 4px solid #f57c00; } .low { background-color: #e8f5e9; border-left: 4px solid #43a047; } </style> </head> <body> <h1>Trivy安全扫描报告</h1> {{ range .Results }} <div class="scan-section"> <h2>扫描目标: {{ .Target }}</h2> <h3>扫描类型: {{ .Type }}</h3> {{ if .Findings }} <h4>检测到 {{ len .Findings }} 个问题</h4> {{ range .Findings }} <div class="finding-item {{ .Severity | lower }}"> <p><strong>漏洞ID:</strong> {{ .VulnerabilityID }}</p> <p><strong>风险等级:</strong> {{ .Severity }}</p> <p><strong>描述:</strong> {{ .Description }}</p> <p><strong>涉及包:</strong> {{ .PkgName }}</p> <p><strong>当前版本:</strong> {{ .InstalledVersion }}</p> <p><strong>修复版本:</strong> {{ .FixedVersion }}</p> </div> {{ end }} {{ else }} <p>未检测到任何问题。</p> {{ end }} </div> {{ end }} </body> </html>执行正确的生成命令
用本地模板生成报告,注意模板路径要写对(当前目录用./html.tpl):trivy config . --format template --template "./html.tpl" -o report.html如果是扫描镜像,把
config .换成你的镜像名即可:trivy image --format template --template "./html.tpl" -o report.html golang:1.12-alpine
额外说明
旧文档里的@contrib/html.tpl是旧版Trivy的内置模板,新版本要么路径变更要么结构不兼容,直接用自定义模板更靠谱。如果需要更复杂的样式,可以根据JSON里的字段自行调整模板内容。
内容的提问来源于stack exchange,提问作者Emme
相关产品推荐
相关产品推荐

