Skip to main content
Use the endorctl toolchains command to detect the current tools used in your repository, create a scan profile, or generate a Dockerfile.
Toolchain commands are not supported on Windows.

Usage

  • Use the help argument to see the options associated with toolchains command.

Detect tools in your repository

Use endorctl detect to identify the tools currently used in your repository. The following arguments can help you refine your scan:
  • Use the -p argument to define the local filesystem path to the repository you want to scan.
  • Use the --exclude-path argument to exclude specific file paths or directories.
  • Use the --include-path argument to limit the scan to a specific file path or directory.

Create a scan profile

Use endorctl generate to create a scan profile. See Configure build tools for more details.
  • Use the profile-name argument to assign a name to your profile. This command creates a .endorctl/scanprofile.yaml file with the tools in the repository.
  • Use the output-type argument to specify the format of the output file.
  • Use the --output-path argument to set the output file location.
  • Use the --create-profile argument to create and save the scan profile using the specified options.

Options

The endorctl toolchains command uses the following flags and environment variables.