You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:Grype容器未加载自定义config.yaml配置如何解决?

解决Grype容器运行时未加载自定义配置的问题

问题重现

通过Docker容器运行Grype扫描自定义镜像,执行命令如下:

docker run -v ./grype-config:/config -e "DOCKER_CONFIG=/config" anchore/grype:latest -c "/config/config.yaml" my-own-image

本地grype-config/config.yaml配置内容:

# the output format of the vulnerability report (options: table, json, cyclonedx)
# same as -o ; GRYPE_OUTPUT env var
output: "json"

ignore:
  # We can make rules to match just by vulnerability ID:
  - vulnerability: CVE-2023-5156
  - vulnerability: CVE-2023-4813
  - vulnerability: CVE-2023-4806
  - vulnerability: CVE-2016-20013
  - vulnerability: CVE-2022-27943
  - vulnerability: CVE-2022-27943

实际扫描结果仍使用默认的table输出格式,且配置中标记忽略的漏洞全部被列出:

NAME        INSTALLED              FIXED-IN  TYPE  VULNERABILITY   SEVERITY
libc6       2.35-0ubuntu3.4                  deb   CVE-2023-5156   Medium
libc6       2.35-0ubuntu3.4                  deb   CVE-2023-4813   Low
libc6       2.35-0ubuntu3.4                  deb   CVE-2023-4806   Low
libc6       2.35-0ubuntu3.4                  deb   CVE-2016-20013  Negligible
libgcc-s1   12.3.0-1ubuntu1~22.04            deb   CVE-2022-27943  Low
libstdc++6  12.3.0-1ubuntu1~22.04            deb   CVE-2022-27943  Low

核心原因

  1. 参数格式错误:-c参数后的路径被引号包裹,Grype无法正确解析容器内的配置文件路径
  2. 多余环境变量干扰:DOCKER_CONFIG是Docker客户端的环境变量,和Grype配置加载无关,添加后可能导致逻辑冲突

修复步骤

1. 修正运行命令

移除多余的DOCKER_CONFIG环境变量,同时去掉-c参数路径的引号,修改后的命令:

docker run -v ./grype-config:/config anchore/grype:latest -c /config/config.yaml my-own-image

2. 验证配置文件权限

确保挂载到容器内的config.yaml具备可读权限,执行以下命令检查:

docker run -v ./grype-config:/config anchore/grype:latest ls -l /config/config.yaml

如果权限不足,调整本地目录权限:

chmod -R 755 ./grype-config

3. (可选)添加环境变量双重保障

如果配置仍未生效,可以通过GRYPE_OUTPUT环境变量强制指定输出格式,进一步确保配置生效:

docker run -v ./grype-config:/config -e GRYPE_OUTPUT=json anchore/grype:latest -c /config/config.yaml my-own-image

验证方法

执行修复后的命令,检查输出是否为JSON格式,同时确认配置中指定忽略的CVE不再出现在扫描结果中。

内容的提问来源于stack exchange,提问作者Philip Frerk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 04:22:05