Veracode Pipeline Scan enables you to evaluate the security of your application from your pipeline
1M+
The Veracode Pipeline Scan enables you to evaluate the security of your applications within your development pipeline. The Pipeline Scan embeds directly into team development pipelines and provides fast feedback on security flaws introduced on new commits. You can use the Pipeline Scan to break the build based on flaw severity and CWE category. You can also use it to evaluate the changes in your results compared to previous scans, enabling you to identify flaws present in your application before releasing the application to production environments. For information about application packaging requirements and language support, API parameters, logging, and code examples, visit the Veracode Help Center.
There are two variants:
veracode/pipeline-scanlatest tag is applied to this variant.veracode/pipeline-scan:cmd
The command variant is for when you just want to run the tool from the command line and is useful when run via shell aliases.The images are based on Docker Official Images from eclipse-temurin. The Pipeline Scan Tool jar is installed in /opt/veracode/. By default containers run as a non-privileged, local user.
In a GitLab pipeline with API credentials provided as environment variables:
scan-my-java-app:
image: veracode/pipeline-scan:latest
script:
- java -jar /opt/veracode/pipeline-scan.jar
-vid $VERACODE_API_KEY_ID -vkey $VERACODE_API_KEY_SECRET
--file /path/to/built/app.jar
scan-my-python-app:
image: veracode/pipeline-scan:latest
script:
- zip myapp.zip ./src/
- java -jar /opt/veracode/pipeline-scan.jar
-vid $VERACODE_API_KEY_ID -vkey $VERACODE_API_KEY_SECRET
--file myapp.zip
For a local shell with current host OS directory mounted inside the container:
docker run -it --rm -v $PWD:/home/luser veracode/pipeline-scan
By default containers run as a non-privileged, local user in /home/luser. If needed, you can override these defaults. You can get a root shell with the --user argument and change the working directory with the --workdir argument:
docker run -it --rm --user root veracode/pipeline-scan
docker run -it --rm --workdir /my/app/path veracode/pipeline-scan
docker run -it --rm --user root --workdir /my/app/path veracode/pipeline-scan
Running a Pipeline Scan with a Veracode Credentials file mounted into the container:
docker run -it --rm \
-v ~/.veracode/credentials:/home/luser/.veracode/credentials \
-v /host/os/path/to/myapp/:/myapp/ \
veracode/pipeline-scan:cmd \
--file /myapp/myapp.jar
Running a Pipeline Scan with API credentials provided as environment variables:
docker run -it --rm \
--env VERACODE_API_KEY_ID=c2db7664... \
--env VERACODE_API_KEY_SECRET=24f62c81... \
-v /host/os/path/to/myapp/:/myapp/ \
veracode/pipeline-scan:cmd \
-vid $VERACODE_API_KEY_ID -vkey $VERACODE_API_KEY_SECRET \
--file /myapp/myapp.jar
To see all available options and other help:
docker run -it --rm veracode/pipeline-scan:cmd --help
The command variant is particularly useful when run via a shell alias:
alias 'veracode-pipeline-scan'='docker run -it --rm -v $PWD:/home/luser -v ~/.veracode/credentials:/home/luser/.veracode/credentials veracode/pipeline-scan:cmd'
Then the container can be run as if it were a locally installed executable:
veracode-pipeline-scan --help
veracode-pipeline-scan --file ./myapp.jar
veracode-pipeline-scan -f ./myapp.jar -p myproject -bf baseline.json
Content type
Image
Digest
sha256:65d29e457…
Size
71.1 MB
Last updated
6 days ago
docker pull veracode/pipeline-scan