# Source this file to make every grype/syft command use the local DB and never touch the network: # source /work/acb/grype-db/grype-offline.env export PATH=/work/acb/grype-db/bin:$PATH # Grype: read the DB from ./cache, never download or check for a newer one. export GRYPE_DB_CACHE_DIR=/work/acb/grype-db/cache export GRYPE_DB_AUTO_UPDATE=false export GRYPE_DB_REQUIRE_UPDATE_CHECK=false # By default grype refuses a DB built more than 5 days (120h) ago. Offline the DB is # always a snapshot, so turn that off and check its age yourself (see GUIDE.md, section 5). export GRYPE_DB_VALIDATE_AGE=false export GRYPE_CHECK_FOR_APP_UPDATE=false # No Maven Central lookups for JARs without embedded metadata. export GRYPE_EXTERNAL_SOURCES_ENABLE=false # Syft (SBOM generation): no update check, no network lookups. export SYFT_CHECK_FOR_APP_UPDATE=false export SYFT_JAVA_USE_NETWORK=false export SYFT_GOLANG_SEARCH_REMOTE_LICENSES=false export SYFT_JAVASCRIPT_SEARCH_REMOTE_LICENSES=false export SYFT_PYTHON_SEARCH_REMOTE_LICENSES=false