Sign inSign up

rapid7/insightappsec-gitlab-scan

By rapid7

•Updated about 1 month ago

InsightAppSec Scan application image for use with GitLab CI/CD pipelines

Image
0

3.3K

rapid7/insightappsec-gitlab-scan repository overview

⁠Description

The Rapid7 InsightAppSec Scan workflow for GitLab CI/CD leverages the InsightAppSec RESTful API to automate web application scanning as part of a GitLab CI/CD pipeline. The extension provides a variety of configuration options to allow for flexibility when utilized within a pipeline. This includes options for scan timeouts and gating based on the results of a completed scan. This facilitates the implementation of Dynamic Application Security Testing (DAST) and enables organizations to address application security as part of the software development life cycle.

⁠Key Features

  • Performs web application scanning within a Gitlab CI/CD pipeline
  • Monitors and records scan status
  • Provides scan gating capability with custom user-defined query

⁠Requirements

  • Rapid7 Platform API Key

⁠Documentation

⁠Configuration

Note that this is a step to be included in an already existing CI/CD pipeline. It's sole purpose is to kick off a scan on InsightAppSec and report the results.

The InsightAppSec API key will need to be added as a GitLab CI/CD variable named IAS_API_KEY in order for this to work. See how to do this here: https://docs.gitlab.com/ee/ci/variables/#add-a-cicd-variable-to-a-project⁠

insightappsec_dast:
  image: rapid7/insightappsec-gitlab-scan:latest
  script:
    - python3 /insightappsec_scan/actions.py 
        --TOKEN="${IAS_API_KEY}"
        --SCAN_CONFIG_ID="${SCAN_CONFIG_ID}"
        --REGION="${REGION}"
        --FAIL_ON_VULN_FINDINGS="${FAIL_ON_VULN_FINDINGS}"
        --WAIT_FOR_SCAN_COMPLETE="${WAIT_FOR_SCAN_COMPLETE}"
        --VULN_QUERY="${VULN_QUERY}"
        --LOG_LEVEL="${LOG_LEVEL}"
        --TIMEOUT="${TIMEOUT}"
  variables:
    # The region indicates the geo-location of the Insight Platform. For example 'us'.
    REGION: "us"
    # The UUID of the scan configuration to be used during scanning. The scan configuration should be a sub-resource of
    # the application and can be obtained from InsightAppSec.
    SCAN_CONFIG_ID: "272c9a61-7696-4798-8287-51c49b4c75d6"
    # If true the job will raise an error on finding any vulnerabilities from the scan results, this will make the pipeline fail.
    # Defaults to true.
    FAIL_ON_VULN_FINDINGS: "true"
    # If false the Scan ID will be returned as soon as the scan is kicked off, else the workflow will continually poll 
    # until the scan is completed and return the results. Defaults to true.
    WAIT_FOR_SCAN_COMPLETE: "true"
    # Scan gating query. Used to filter results by vulnerability properties. If this has a value and the query returns
    # vulnerabilities from the scan then the job will be marked as failed. The format of the scan gating query should conform to the 
    # VULNERABILITY search query format described in the documentation: 
    # https://help.rapid7.com/insightappsec/en-us/api/v1/docs.html#tag/Search
    VULN-QUERY: "vulnerability.vulnerabilityScore > 4"
    # Sets the verbosity level of the logs. Valid options are DEBUG, INFO, WARNING, ERROR. Defaults to INFO.
    LOG_LEVEL: "info"
    # Sets the scan timeout in minutes. If this time limit is reached, the scan will be cancelled and the pipeline will fail. Defaults to 0 which means no timeout.
    TIMEOUT: "15"

The body of a vulnerability query cannot contain double quotes ("), single quotes (') should be used instead. The entire VULN-QUERY property can be wrapped in double quotes. For example:

  VULN-QUERY: "vulnerability.severity = 'MEDIUM'"

⁠References

Tag summary

Content type

Image

Digest

sha256:ec5547437…

Size

22.1 MB

Last updated

about 1 month ago

docker pull rapid7/insightappsec-gitlab-scan