Skip to content

Commit 2624ddf

Browse files
authored
Enabling polaris sast scan (#332)
* enabling polaris sast Signed-off-by: nikhil2611 <ngupta@progress.com> * updating to main Signed-off-by: nikhil2611 <ngupta@progress.com> --------- Signed-off-by: nikhil2611 <ngupta@progress.com>
1 parent 2580cc2 commit 2624ddf

File tree

1 file changed

+7
-7
lines changed

1 file changed

+7
-7
lines changed

.github/workflows/ci-main-pull-request-stub-1.0.7.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -98,15 +98,15 @@ jobs:
9898

9999
# BlackDuck SAST (Polaris) require a build or binary present in repo to do SAST testing
100100
# requires these secrets: POLARIS_SERVER_URL, POLARIS_ACCESS_TOKEN
101-
perform-blackduck-polaris: false
101+
perform-blackduck-polaris: true
102102
polaris-application-name: "Chef-Agents" # one of these: Chef-Agents, Chef-Automate, Chef-Chef360, Chef-Habitat, Chef-Infrastructure-Server, Chef-Shared-Services, Chef-Other, Chef-Non-Product
103103
polaris-project-name: ${{ github.event.repository.name }} # arch-sample-cli
104-
polaris-working-directory: '.' # Working directory for the scan, defaults to . but usually lang-dependent like ./src
105-
polaris-coverity-build-command: 'go build -o bin/chef-cli.exe' # Coverity build command, typically done in build stage by language or here as param 1-liner like "mvn clean install"
106-
polaris-coverity-clean-command: 'go clean' # Coverity clean command, typically done before build stage by language or here as param 1-liner like "mvn clean"
107-
polaris-detect-search-depth: '5' # Detect search depth, blank but can be set to "3" to search up to 3 levels of subdirectories for code to scan'
108-
polaris-assessment-mode: 'SAST' # Assessment mode (SAST, CI or SOURCE_UPLOAD)
109-
wait-for-scan: true
104+
# polaris-working-directory: '.' # Working directory for the scan, defaults to . but usually lang-dependent like ./src
105+
# polaris-coverity-build-command: 'go build -o bin/chef-cli.exe' # Coverity build command, typically done in build stage by language or here as param 1-liner like "mvn clean install"
106+
# polaris-coverity-clean-command: 'go clean' # Coverity clean command, typically done before build stage by language or here as param 1-liner like "mvn clean"
107+
# polaris-detect-search-depth: '5' # Detect search depth, blank but can be set to "3" to search up to 3 levels of subdirectories for code to scan'
108+
# polaris-assessment-mode: 'SAST' # Assessment mode (SAST, CI or SOURCE_UPLOAD)
109+
# wait-for-scan: true
110110
# polaris-detect-args: '' # Additional Detect arguments, can supply extra arguments like "--detect.diagnostic=true"
111111
# coverity_build_command: "go build"
112112
# coverity_clean_command: "go clean"

0 commit comments

Comments
 (0)