Commit 4127a1ec authored by Dmitriy Zaporozhets's avatar Dmitriy Zaporozhets Committed by Achilleas Pipinellis

Update documentation for sast:image feature

parent 557c4fbd
...@@ -20,15 +20,15 @@ sast:image: ...@@ -20,15 +20,15 @@ sast:image:
- setup_docker - setup_docker
- docker run -d --name db arminc/clair-db:latest - docker run -d --name db arminc/clair-db:latest
- docker run -p 6060:6060 --link db:postgres -d --name clair arminc/clair-local-scan:v2.0.1 - docker run -p 6060:6060 --link db:postgres -d --name clair arminc/clair-local-scan:v2.0.1
- apk update && apk add ca-certificates wget && update-ca-certificates - apk add -U wget ca-certificates
- docker pull ${CI_APPLICATION_REPOSITORY}:${CI_APPLICATION_TAG} - docker pull ${CI_APPLICATION_REPOSITORY}:${CI_APPLICATION_TAG}
- wget https://github.com/arminc/clair-scanner/releases/download/v6/clair-scanner_linux_386 - wget https://github.com/arminc/clair-scanner/releases/download/v6/clair-scanner_linux_386
- mv clair-scanner_linux_386 clair-scanner - mv clair-scanner_linux_386 clair-scanner
- chmod +x clair-scanner - chmod +x clair-scanner
- touch clair-whitelist.yml - touch clair-whitelist.yml
- ./clair-scanner -c http://docker:6060 --ip $(hostname -i) -r gl-clair-report.json -l clair.log -w clair-whitelist.yml ${CI_APPLICATION_REPOSITORY}:${CI_APPLICATION_TAG} || true - ./clair-scanner -c http://docker:6060 --ip $(hostname -i) -r gl-sast-image-report.json -l clair.log -w clair-whitelist.yml ${CI_APPLICATION_REPOSITORY}:${CI_APPLICATION_TAG} || true
artifacts: artifacts:
paths: [gl-clair-report.json] paths: [gl-sast-image-report.json]
``` ```
The above example will create a `sast:image` job in your CI pipeline and will allow The above example will create a `sast:image` job in your CI pipeline and will allow
...@@ -41,7 +41,7 @@ TIP: **Tip:** ...@@ -41,7 +41,7 @@ TIP: **Tip:**
Starting with GitLab Enterprise Edition Ultimate 10.3, this information will Starting with GitLab Enterprise Edition Ultimate 10.3, this information will
be automatically extracted and shown right in the merge request widget. To do be automatically extracted and shown right in the merge request widget. To do
so, the CI job must be named `sast:image` and the artifact path must be so, the CI job must be named `sast:image` and the artifact path must be
`gl-clair-report.json`. `gl-sast-image-report.json`.
[Learn more on application security testing results shown in merge requests](../../user/project/merge_requests/sast-image.md). [Learn more on application security testing results shown in merge requests](../../user/project/merge_requests/sast-image.md).
[ee]: https://about.gitlab.com/gitlab-ee/ [ee]: https://about.gitlab.com/gitlab-ee/
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment