Search documentation
karat

+

K

apollo-cli cve list

List CVE due dates per product release and container image

List CVE due dates per product release and container image.

For each CVE found in the queried releases, outputs one row per affected container image showing the product coordinate, CVE ID, container image, and due date. CVEs with active findings show "Overdue" for the due date.

Input sources (at least one required):

  1. An environment (-e): Query all product releases from entities in the environment
  2. A YAML file (-f): Query Maven coordinates listed in the provided YAML file
  3. A product ID (-p): Query the latest release for the specified product

Example usage:

List CVE due dates for all releases in an environment

apollo-cli cve list -e my-environment

List CVE due dates for the latest release of a specific product

apollo-cli cve list -p com.palantir.foo

List CVE due dates for coordinates in a file

apollo-cli cve list -f coordinates.yaml

Output as JSON

apollo-cli cve list -e my-environment -o json

Copied!
1 apollo-cli cve list [flags]

Flags

FlagUse
-e, --environmentEnvironment
-h, --helpHelp for list
-f, --maven-coordinates-fileFile containing a list of maven coordinates (yaml format)
-p, --product-idProduct ID of the form 'group'

Flags inherited from parent commands

FlagUse
--apollo-client-idClient ID to use for generating Bearer Token
--apollo-client-secretClient secret to use for generating Bearer Token
--apollo-tokenBearer Token to use for authenticated endpoints
--apollo-token-providerSpecifies how the Bearer Token used for authenticated Apollo endpoint calls is provided. Valid values are "auto", "static", "service-user", or "sso" (default "auto"). If "auto" is specified, the mode is picked from what is configured: "static" if "apollo-token" is set, "service-user" if "apollo-client-id" and "apollo-client-secret" are both set, otherwise "sso" (interactive browser login). Errors if both a bearer token AND (client id OR client secret) are set. If "static" is specified, the token provided by "apollo-token" is used. If "service-user" is specified, "apollo-client-id" and "apollo-client-secret" are used to generate a token from Multipass. If "sso" is specified, an interactive browser-based SSO login against Multipass is used (supports hardware keys like YubiKey); the resulting token is cached per profile and refreshed silently. The login flow is triggered automatically the first time a command needs a token and no valid cached token exists.
--apollo-urlBase URL for Apollo that is used to derive the API endpoints
--debugEnable debug level logging
--http-timeoutTimeout in minutes for all apollo requests
-k, --insecure-skip-verifySkip verification of server certificate
-o, --outputOutput format (json,yaml,pretty)
--profileUse a specific profile from your configuration file
--quietDo not print log output to stderr
--space-idSpace ID to use for certain space-scoped commands

See also