InsightAppSec Scan application image for use with GitLab CI/CD pipelines
3.3K
The Rapid7 InsightAppSec Scan workflow for GitLab CI/CD leverages the InsightAppSec RESTful API to automate web application scanning as part of a GitLab CI/CD pipeline. The extension provides a variety of configuration options to allow for flexibility when utilized within a pipeline. This includes options for scan timeouts and gating based on the results of a completed scan. This facilitates the implementation of Dynamic Application Security Testing (DAST) and enables organizations to address application security as part of the software development life cycle.
Note that this is a step to be included in an already existing CI/CD pipeline. It's sole purpose is to kick off a scan on InsightAppSec and report the results.
The InsightAppSec API key will need to be added as a GitLab CI/CD variable named IAS_API_KEY in order for this to work. See how to do this here: https://docs.gitlab.com/ee/ci/variables/#add-a-cicd-variable-to-a-project
insightappsec_dast:
image: rapid7/insightappsec-gitlab-scan:latest
script:
- python3 /insightappsec_scan/actions.py
--TOKEN="${IAS_API_KEY}"
--SCAN_CONFIG_ID="${SCAN_CONFIG_ID}"
--REGION="${REGION}"
--FAIL_ON_VULN_FINDINGS="${FAIL_ON_VULN_FINDINGS}"
--WAIT_FOR_SCAN_COMPLETE="${WAIT_FOR_SCAN_COMPLETE}"
--VULN_QUERY="${VULN_QUERY}"
--LOG_LEVEL="${LOG_LEVEL}"
--TIMEOUT="${TIMEOUT}"
variables:
# The region indicates the geo-location of the Insight Platform. For example 'us'.
REGION: "us"
# The UUID of the scan configuration to be used during scanning. The scan configuration should be a sub-resource of
# the application and can be obtained from InsightAppSec.
SCAN_CONFIG_ID: "272c9a61-7696-4798-8287-51c49b4c75d6"
# If true the job will raise an error on finding any vulnerabilities from the scan results, this will make the pipeline fail.
# Defaults to true.
FAIL_ON_VULN_FINDINGS: "true"
# If false the Scan ID will be returned as soon as the scan is kicked off, else the workflow will continually poll
# until the scan is completed and return the results. Defaults to true.
WAIT_FOR_SCAN_COMPLETE: "true"
# Scan gating query. Used to filter results by vulnerability properties. If this has a value and the query returns
# vulnerabilities from the scan then the job will be marked as failed. The format of the scan gating query should conform to the
# VULNERABILITY search query format described in the documentation:
# https://help.rapid7.com/insightappsec/en-us/api/v1/docs.html#tag/Search
VULN-QUERY: "vulnerability.vulnerabilityScore > 4"
# Sets the verbosity level of the logs. Valid options are DEBUG, INFO, WARNING, ERROR. Defaults to INFO.
LOG_LEVEL: "info"
# Sets the scan timeout in minutes. If this time limit is reached, the scan will be cancelled and the pipeline will fail. Defaults to 0 which means no timeout.
TIMEOUT: "15"
The body of a vulnerability query cannot contain double quotes ("), single quotes (') should be used instead. The entire VULN-QUERY property can be wrapped in double quotes. For example:
VULN-QUERY: "vulnerability.severity = 'MEDIUM'"
Content type
Image
Digest
sha256:ec5547437…
Size
22.1 MB
Last updated
about 1 month ago
docker pull rapid7/insightappsec-gitlab-scan