# Help needed with "interesting" commands

**URL:** <https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191>\
**Category:** General\
**Created:** [October 22, 2024, 1:20pm UTC](https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191 "2024-10-22T13:20:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [October 22, 2024, 1:20pm UTC](https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191/1 "2024-10-22T13:20:43Z")

</div>

I’m putting together a few slides that will become a silent video running on a TV on our stand at [All Things Open](https://2024.allthingsopen.org/) next week. I wanted to have some “interesting” uses of our command line tools shown as embedded videos. I can come up with some standard basic ones, but wondered if you seasoned tools users and developers had some suggestions for something _interesting_ to see in a short GIF/MP4.

Below are some examples of what they kinda look like when made. I may speed them up or slow them down, that’s not set in stone. Some notes:

- They’re intentionally slowed down in places so someone passing by doesn’t just see a flash
- I should probably focus on application containers, and not OS ones, as they’re mostly boring
- That said, it might be interesting to highlight Azure Linux 3, as that’s quite new
- I’d like some examples beyond the basics
- There will be subtitles on screen explaining what people are seeing
- I’m _not_ asking anyone to make GIFs, I can make those
- Ignore that some have and some do not have drop-shadow

`syft alpine:latest`

![rec-2024-10-22_11:05:1729591558](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/138ce1e5d2ba051ead1275f98d2198fb87b3be3b.gif)

`grype ubuntu:latest`

![rec-2024-10-22_11:11:1729591862](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/cb89663641c4bcce5a836ec3c9821e675adaa216.gif)

`grant check alpine:latest --osi-approved --show-packages`

![rec-grant_check_alpine:latest_--osi-approved_--show-packages_1](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/e4de6301fb457f1ae3cb4544085d40abd05e42af.gif)

Suggestions welcome!

---

<div class="post-metadata">

**Author:** ![wagoodman](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/wagoodman/32/13_2.png) [@wagoodman](https://anchorecommunity.discourse.group/u/wagoodman)\
**Post date:** [October 22, 2024, 2:41pm UTC](https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191/2 "2024-10-22T14:41:12Z")

</div>

Get all files and sha256 digests cataloged in the SBOM:

```auto
syft ubuntu:latest -o json | jq -r '[.files[] | select(.digests != null) | {path: .location.path, sha256: (.digests[]? | select(.algorithm == "sha256").value)}] | unique_by(.path)[] | select(.sha256 != null) | "\(.sha256) \(.path)"'

```

Find all executable files:

```auto
syft fedora:latest -o json | jq '.files[] | select(.executable != null)'

```

Find executables missing security features (in this case stack canaries):

```auto
syft fedora:latest -o json | jq '.files[] | select(.executable != null and .executable.elfSecurityFeatures.stackCanary == false).location.path'

```

Find which libraries all binaries on the system import:

```auto
syft fedora:latest -o json | jq '.files[] | select(.executable != null) | {"binary": .location.path, "imports": [.executable.importedLibraries]}'

```

---

<div class="post-metadata">

**Author:** ![kzantow](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/kzantow/32/17_2.png) [@kzantow](https://anchorecommunity.discourse.group/u/kzantow)\
**Post date:** [October 22, 2024, 5:01pm UTC](https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191/3 "2024-10-22T17:01:13Z")

</div>

A worse suggestion is to see a list of interesting files Syft did not find packages for:

```auto
syft maven:latest -o json | jq '.files.[]|select(.unknowns)|{location,unknowns}|.location.path+" - "+(.unknowns|join(", "))'

```

---

<div class="post-metadata">

**Author:** ![spiffcs](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/spiffcs/32/14_2.png) [@spiffcs](https://anchorecommunity.discourse.group/u/spiffcs)\
**Post date:** [October 22, 2024, 5:14pm UTC](https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191/4 "2024-10-22T17:14:52Z")

</div>

For grant here are a couple:

This gets the working compliance document as

```auto
syft -o json node:latest | grant -o json list | jq . > compliance.json

```

This will give you all licenses that were able to be discovered with a reference. I’ve listed the data structure in the output below this command:

```auto
jq '.results[] | select(.license.reference != "") | {license_name: .license.name, reference: .license.reference, packages: [.packages[].name]}' compliance.json    

```

Example of an item in this list - license name and packages associated

```auto
{
  "license_name": "Open LDAP Public License v2.8",
  "reference": "https://spdx.org/licenses/OLDAP-2.8.html",
  "packages": [
    "curl",
    "libcurl3-gnutls",
    "libcurl4",
    "libcurl4-openssl-dev"
  ]
}

```

This will print all licenses and their packages without a reference

```auto
jq '.results[] | select(.license.reference == "") | {license_name: .license.name, packages: [.packages[].name]}' compliance.json

```

---

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [October 22, 2024, 6:03pm UTC](https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191/5 "2024-10-22T18:03:03Z")

</div>

Sure stuff chaps! Thank you! 😃

---

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [October 24, 2024, 11:45am UTC](https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191/6 "2024-10-24T11:45:43Z")

</div>

Some examples of what I cranked out. I piped them through `pv -qL $NUM` to slow down the output. That way I can have the gif play out, and people can just about read what’s happening. Using 20 for `$NUM` when “typing” and 200 or even up to 512K (bytes per sec) when outputting a lot of text. The only downside of this is that piping through `pv` strips the beautiful color out ☹

![0050-syft_find_executables-2024-10-23_16:53:1729698780](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/446e8683c25f68a06baf9c8c9844434bf405f91a.gif)

I took some of your examples and reworked them to also give shorter results, so we can specifically point to one section. For example this one does the same as the one above, but only shows output for `/usr/bin/bash`, not all files.

![0051-syft_find_executables_only_bash-2024-10-23_17:13:1729700031](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/bd6bd3fd4e4d4fadd7504f72b8e806c201d0c105.gif)

Also, for funzies, I also made mobile friendly versions to see how that would work 😃

![0051-syft_find_executables_only_bash-2024-10-23_18:19:1729703989](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/b94cd48f2e154fa228ec6705613338a874625f7e.gif)

---

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [October 25, 2024, 12:31pm UTC](https://anchorecommunity.discourse.group/t/help-needed-with-interesting-commands/191/7 "2024-10-25T12:31:15Z")

</div>

Thanks to @wagoodman and @willmurphy for recommending [vhs](https://github.com/charmbracelet/vhs) from [charmbracelet](https://github.com/charmbracelet/). It’s so much nicer to use, more configurable and faster than [t-rec](https://github.com/sassman/t-rec-rs)!

```auto
Output ./Videos/syft_alpine.latest.gif

Require echo

Set Shell "bash"
Set FontSize 32
Set Width 1200
Set Height 600
Set WindowBar Colorful
Set Theme catppuccin-macchiato
Set Margin 20
Set MarginFill "#0f40c0"
Set BorderRadius 10
Set Framerate 60
Set PlaybackSpeed 0.5

Type "syft alpine:latest" Sleep 500ms Enter

Sleep 5s

```

![syft_alpine.latest](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/09b99ac5562904c31c6a63d1a37b4a79c1e18913.gif)
