# -*- coding: utf-8; mode: tcl; tab-width: 4; indent-tabs-mode: nil; c-basic-offset: 4 -*- vim:fenc=utf-8:ft=tcl:et:sw=4:ts=4:sts=4

PortSystem          1.0
PortGroup           golang 1.0

go.setup            github.com/aquasecurity/trivy 0.75.0 v
go.offline_build    no
go.toolchain_min    1.27.0
revision            0

description         \
    A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable \
    for CI

long_description    \
    {*}${description}. Trivy detects vulnerabilities of OS packages (Alpine, \
    RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, \
    yarn, etc.). Trivy is easy to use. Just install the binary and you're \
    ready to scan. All you need to do for scanning is to specify a target \
    such as an image name of the container.

categories          security sysutils
installs_libs       no
license             Apache-2
maintainers         {gmail.com:herby.gillot @herbygillot} \
                    openmaintainer
platforms           darwin linux freebsd

checksums           rmd160  b0012da57289eb643577545d5e20c589fd02db31 \
                    sha256  4ee2010384f90bf23d4059ae49c11129e5041816a3754d890a90ae80f678d765 \
                    size    56749163

# trivy imports encoding/json/v2, which Go 1.27 still keeps behind the jsonv2
# experiment.
build.env-append    CGO_ENABLED=0 GOEXPERIMENT=jsonv2
build.args-append   -trimpath \
                    -ldflags \"-s -w -X ${go.package}/pkg/version/app.ver=${version}\" \
                    ./cmd/${name}

destroot {
    xinstall -m 0755 ${worksrcpath}/${name} ${destroot}${prefix}/bin/
}
