Configure SAST in .gitlab-ci.yml, creating this file if it does not already exist

This commit is contained in:
Slava
2024-03-11 06:52:16 +00:00
parent 26439df3d6
commit 4f11883b55

View File

@@ -1,24 +1,37 @@
# You can override the included template(s) by including variable overrides
# SAST customization: https://docs.gitlab.com/ee/user/application_security/sast/#customizing-the-sast-settings
# Secret Detection customization: https://docs.gitlab.com/ee/user/application_security/secret_detection/#customizing-settings
# Dependency Scanning customization: https://docs.gitlab.com/ee/user/application_security/dependency_scanning/#customizing-the-dependency-scanning-settings
# Container Scanning customization: https://docs.gitlab.com/ee/user/application_security/container_scanning/#customizing-the-container-scanning-settings
# Note that environment variables can be set in several places
# See https://docs.gitlab.com/ee/ci/variables/#cicd-variable-precedence
qodana: qodana:
only: only:
- master - master
- merge_requests - merge_requests
image: image:
name: jetbrains/qodana-python-community name: jetbrains/qodana-python-community
entrypoint: [""] entrypoint:
- ''
cache: cache:
- key: qodana-2023.3-$CI_DEFAULT_BRANCH-$CI_COMMIT_REF_SLUG - key: qodana-2023.3-$CI_DEFAULT_BRANCH-$CI_COMMIT_REF_SLUG
fallback_keys: fallback_keys:
- qodana-2023.3-$CI_DEFAULT_BRANCH- - qodana-2023.3-$CI_DEFAULT_BRANCH-
- qodana-2023.3- - qodana-2023.3-
paths: paths:
- .qodana/cache - ".qodana/cache"
variables: variables:
QODANA_TOKEN: $qodana_token QODANA_TOKEN: "$qodana_token"
script: script:
- qodana --save-report --results-dir=$CI_PROJECT_DIR/.qodana/results - qodana --save-report --results-dir=$CI_PROJECT_DIR/.qodana/results --cache-dir=$CI_PROJECT_DIR/.qodana/cache
--cache-dir=$CI_PROJECT_DIR/.qodana/cache
artifacts: artifacts:
expose_as: 'qodana_report' expose_as: qodana_report
expire_in: 1 week expire_in: 1 week
paths: [ '.qodana/results/' ] paths:
- ".qodana/results/"
stages:
- test
sast:
stage: test
include:
- template: Security/SAST.gitlab-ci.yml