Configure SAST in .gitlab-ci.yml, creating this file if it does not already exist
This commit is contained in:
@@ -1,24 +1,37 @@
|
|||||||
|
# You can override the included template(s) by including variable overrides
|
||||||
|
# SAST customization: https://docs.gitlab.com/ee/user/application_security/sast/#customizing-the-sast-settings
|
||||||
|
# Secret Detection customization: https://docs.gitlab.com/ee/user/application_security/secret_detection/#customizing-settings
|
||||||
|
# Dependency Scanning customization: https://docs.gitlab.com/ee/user/application_security/dependency_scanning/#customizing-the-dependency-scanning-settings
|
||||||
|
# Container Scanning customization: https://docs.gitlab.com/ee/user/application_security/container_scanning/#customizing-the-container-scanning-settings
|
||||||
|
# Note that environment variables can be set in several places
|
||||||
|
# See https://docs.gitlab.com/ee/ci/variables/#cicd-variable-precedence
|
||||||
qodana:
|
qodana:
|
||||||
only:
|
only:
|
||||||
- master
|
- master
|
||||||
- merge_requests
|
- merge_requests
|
||||||
image:
|
image:
|
||||||
name: jetbrains/qodana-python-community
|
name: jetbrains/qodana-python-community
|
||||||
entrypoint: [""]
|
entrypoint:
|
||||||
|
- ''
|
||||||
cache:
|
cache:
|
||||||
- key: qodana-2023.3-$CI_DEFAULT_BRANCH-$CI_COMMIT_REF_SLUG
|
- key: qodana-2023.3-$CI_DEFAULT_BRANCH-$CI_COMMIT_REF_SLUG
|
||||||
fallback_keys:
|
fallback_keys:
|
||||||
- qodana-2023.3-$CI_DEFAULT_BRANCH-
|
- qodana-2023.3-$CI_DEFAULT_BRANCH-
|
||||||
- qodana-2023.3-
|
- qodana-2023.3-
|
||||||
paths:
|
paths:
|
||||||
- .qodana/cache
|
- ".qodana/cache"
|
||||||
|
|
||||||
variables:
|
variables:
|
||||||
QODANA_TOKEN: $qodana_token
|
QODANA_TOKEN: "$qodana_token"
|
||||||
script:
|
script:
|
||||||
- qodana --save-report --results-dir=$CI_PROJECT_DIR/.qodana/results
|
- qodana --save-report --results-dir=$CI_PROJECT_DIR/.qodana/results --cache-dir=$CI_PROJECT_DIR/.qodana/cache
|
||||||
--cache-dir=$CI_PROJECT_DIR/.qodana/cache
|
|
||||||
artifacts:
|
artifacts:
|
||||||
expose_as: 'qodana_report'
|
expose_as: qodana_report
|
||||||
expire_in: 1 week
|
expire_in: 1 week
|
||||||
paths: [ '.qodana/results/' ]
|
paths:
|
||||||
|
- ".qodana/results/"
|
||||||
|
stages:
|
||||||
|
- test
|
||||||
|
sast:
|
||||||
|
stage: test
|
||||||
|
include:
|
||||||
|
- template: Security/SAST.gitlab-ci.yml
|
||||||
|
|||||||
Reference in New Issue
Block a user