Skip to navigation

Command-Line Arguments

View as Markdown

Volume Mounts

Volume Mounts

  • AI Supply Chain Security CLI requires its input - the model(s) to be scanned - to be made available to the running Docker container through a mounted volume.
  • AI Supply Chain Security CLI can optionally write scan results to a file within a mounted volume.
  • All file paths provided in command-line argument to the container are with respect to the container’s file system, not the local file system.
  • See the Docker documentation for more information.

Example

  • Suppose that the models to be scanned are located on the local machine in /home/user/models.
  • Supply Chain CLI’s scan results should be output to the local machine in /home/user/results.
  • This example runs the 26.4.0 Supply Chain CLI image. Change the Supply Chain CLI version if you want to pull a different Supply Chain version. Example: change 26.4.0 to 26.5.0.

In this case, volume mounts could be specified as follows:

docker run --rm \
-e HL_LICENSE \
-v /home/user/models:/files-to-scan \
-v /home/user/results:/scan-results \
images.hiddenlayer.ai/proxy/supply-chain-security/ghcr.io/hiddenlayer-engineering/supply-chain-scanner:26.4.0 \
--input /files-to-scan \
--output /scan-results/results.json
Runtime Security Version

This example runs the latest Supply Chain CLI image. Change the Supply Chain CLI version if you want to pull a different Supply Chain version.

Supply Chain CLI

Input

ArgumentRequiredExample UsageDescription
--input [file]yes--input /files-to-scan/my_model.torchAn absolute file or directory path to scan:
-eyes-e HL_LICENSE,
-e HL_CLIENT_ID,
-e HL_CLIENT_SECRET
Set the environment variables.
--include-patternno--include-pattern "*.h5" --include-pattern "*.rds"- If not provided (default):
--exclude-patternno--exclude-pattern "*test*"- If not provided (default):
--deep-hashingno--deep-hashingCalculates MD5, SHA1, and SHA256 hashes. These are not calculated by default.

Glob Syntax

Some of the input arguments for the Supply Chain CLI allow the user to specify one or more globs to use for matching certain file path patterns. The following tokens can be used within globs to specify matching patterns:

  • *: matches any (possibly empty) sequence of non-special characters

    • Special characters are *, ?, \\, and [
  • ?: matches any single non-special character

Output

ArgumentRequiredExample UsageDescription
--output [file]no--output /scan-results/output.json- If not provided (default):
`—output-format [v3sarifcyclonedx-json]`no
--log-file <file>no--log-file /mnt/volume/log.json- If not provided (default):
--detections-are-errorsno--detections-are-errorsSpecifies whether scan results should drive exit code.
--persistno--persistIf provided, you can add the scan results to an existing model in the AISec Platform Console.
--model-nameno--model-name=testmodelIf you are using --persist, you can specify the --model-name to add the scan results to the existing model in the AISec Platform Console.
--model-versionno--model-version=2If you are using --persist, you can specify the --model-version to increment the scan results version for an existing model in the AISec Platform Console.