Sign inSign up

veracode/pipeline-scan

By veracode

•Updated 6 days ago

Veracode Pipeline Scan enables you to evaluate the security of your application from your pipeline

Image
11

1M+

veracode/pipeline-scan repository overview

⁠Veracode Pipeline scan

The Veracode Pipeline Scan enables you to evaluate the security of your applications within your development pipeline. The Pipeline Scan embeds directly into team development pipelines and provides fast feedback on security flaws introduced on new commits. You can use the Pipeline Scan to break the build based on flaw severity and CWE category. You can also use it to evaluate the changes in your results compared to previous scans, enabling you to identify flaws present in your application before releasing the application to production environments. For information about application packaging requirements and language support, API parameters, logging, and code examples, visit the Veracode Help Center⁠.

⁠Image Details

There are two variants:

  • veracode/pipeline-scan
    The environment variant for when you want a shell. This is probably what you want for pipelines or other situations where you need a shell. The latest tag is applied to this variant.
  • veracode/pipeline-scan:cmd The command variant is for when you just want to run the tool from the command line and is useful when run via shell aliases.

The images are based on Docker Official Images from eclipse-temurin⁠. The Pipeline Scan Tool jar is installed in /opt/veracode/. By default containers run as a non-privileged, local user.

⁠Running as an Environment

In a GitLab pipeline with API credentials provided as environment variables:

scan-my-java-app:
  image: veracode/pipeline-scan:latest
  script:
    - java -jar /opt/veracode/pipeline-scan.jar 
        -vid $VERACODE_API_KEY_ID -vkey $VERACODE_API_KEY_SECRET 
        --file /path/to/built/app.jar

scan-my-python-app:
  image: veracode/pipeline-scan:latest
  script:
    - zip myapp.zip ./src/
    - java -jar /opt/veracode/pipeline-scan.jar
        -vid $VERACODE_API_KEY_ID -vkey $VERACODE_API_KEY_SECRET
        --file myapp.zip

For a local shell with current host OS directory mounted inside the container:

docker run -it --rm -v $PWD:/home/luser veracode/pipeline-scan

By default containers run as a non-privileged, local user in /home/luser. If needed, you can override these defaults. You can get a root shell with the --user argument and change the working directory with the --workdir argument:

docker run -it --rm --user root veracode/pipeline-scan
docker run -it --rm --workdir /my/app/path veracode/pipeline-scan
docker run -it --rm --user root --workdir /my/app/path veracode/pipeline-scan

⁠Running as a Command

Running a Pipeline Scan with a Veracode Credentials⁠ file mounted into the container:

docker run -it --rm \
    -v ~/.veracode/credentials:/home/luser/.veracode/credentials \
    -v /host/os/path/to/myapp/:/myapp/ \
    veracode/pipeline-scan:cmd \
        --file /myapp/myapp.jar

Running a Pipeline Scan with API credentials provided as environment variables:

docker run -it --rm \
    --env VERACODE_API_KEY_ID=c2db7664... \
    --env VERACODE_API_KEY_SECRET=24f62c81... \
    -v /host/os/path/to/myapp/:/myapp/ \
    veracode/pipeline-scan:cmd \
        -vid $VERACODE_API_KEY_ID -vkey $VERACODE_API_KEY_SECRET \
        --file /myapp/myapp.jar

To see all available options and other help:

docker run -it --rm veracode/pipeline-scan:cmd --help
⁠Aliases

The command variant is particularly useful when run via a shell alias:

alias 'veracode-pipeline-scan'='docker run -it --rm -v $PWD:/home/luser -v ~/.veracode/credentials:/home/luser/.veracode/credentials veracode/pipeline-scan:cmd'

Then the container can be run as if it were a locally installed executable:

veracode-pipeline-scan --help
veracode-pipeline-scan --file ./myapp.jar
veracode-pipeline-scan -f ./myapp.jar -p myproject -bf baseline.json

Tag summary

Content type

Image

Digest

sha256:65d29e457…

Size

71.1 MB

Last updated

6 days ago

docker pull veracode/pipeline-scan