Anchore-Engine

File Types

DefectDojo parser accepts a .json file.

Using the Anchore CLI is the most reliable way to generate an Anchore report which DefectDojo can parse. When generating a report with the Anchore CLI, please use the following command to ensure complete data: anchore-cli --json image vuln <image:tag> all

Acceptable JSON Format

All properties are strings and are required by the parser. As the parser evolved, two anchore engine parser JSON formats are present till now. Both (old / new) are supported.

Sample Scan Data

Sample Anchore-Engine scans can be found here.