Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
73 commits
Select commit Hold shift + click to select a range
5c70341
set up workflows
tjarrettveracode Nov 19, 2020
109d4c3
fix pipeline scan upload
tjarrettveracode Nov 19, 2020
38b3f93
remove pipeline scan
tjarrettveracode Nov 23, 2020
cc44fc0
Remove policy scan
tjarrettveracode Nov 23, 2020
0426dbb
Add policy scan template
tjarrettveracode Nov 23, 2020
f6a79b3
fix wildcard
tjarrettveracode Nov 23, 2020
cb66367
fix wildcards again
tjarrettveracode Nov 23, 2020
a5cc611
don't create profile
tjarrettveracode Nov 23, 2020
012ce96
pipeline scan workflow from template
tjarrettveracode Nov 23, 2020
e0b7b10
Merge pull request #1 from veracode/master
tjarrettveracode Jan 21, 2021
cf36419
Update pipelinescan-java.yml
tjarrettveracode Jan 21, 2021
8299b12
Update pipelinescan-java.yml
tjarrettveracode Jan 21, 2021
5d723bd
debug pipeline scan workflow
tjarrettveracode Jan 21, 2021
c5fee5b
fix file target
tjarrettveracode Jan 21, 2021
f39b3c6
file fix once more
tjarrettveracode Jan 21, 2021
7402b97
fix files again
tjarrettveracode Jan 21, 2021
fe50d15
debug file name
tjarrettveracode Jan 21, 2021
2230cda
eliminate wildcard
tjarrettveracode Jan 21, 2021
279f860
clean up script
tjarrettveracode Jan 21, 2021
aa569d2
fix location for files
tjarrettveracode Jan 21, 2021
25170d3
conditional support for gradle
tjarrettveracode Aug 6, 2021
13270b0
Update pipeline scan to later codeql action
tjarrettveracode Jul 25, 2022
d4577ed
archive sarif in pipelinescan yml
tjarrettveracode Jul 28, 2022
f8035ca
pipeline scan
tjarrettveracode Jul 28, 2022
247a0bb
fix sarif file upload
tjarrettveracode Jul 28, 2022
1228474
Update policyscan-java.yml
tjarrettveracode Oct 20, 2022
67eea65
Update policyscan-java.yml
tjarrettveracode Oct 20, 2022
d64cd75
Update policyscan-java.yml
tjarrettveracode Oct 20, 2022
6f385c4
Update policyscan-java.yml
tjarrettveracode Oct 20, 2022
381efa0
Update policyscan-java.yml
tjarrettveracode Oct 20, 2022
7bfe60d
Update policyscan-java.yml
tjarrettveracode Oct 20, 2022
57a1af4
Update policyscan-java.yml
tjarrettveracode Oct 23, 2022
8c34b50
create sbom.yml
tjarrettveracode Oct 24, 2022
52c132a
Update sbom.yml
tjarrettveracode Oct 24, 2022
680e4f8
Update sbom.yml
tjarrettveracode Oct 24, 2022
16a0a05
Update sbom.yml
tjarrettveracode Oct 24, 2022
a10c15e
Update sbom.yml
tjarrettveracode Oct 24, 2022
13f68f5
Update sbom.yml
tjarrettveracode Oct 24, 2022
bc1312a
Update sbom.yml
tjarrettveracode Oct 24, 2022
a0ea88c
Update sbom.yml
tjarrettveracode Oct 24, 2022
e9d7c4c
Update sbom.yml
tjarrettveracode Oct 24, 2022
ff08042
Update sbom.yml
tjarrettveracode Oct 24, 2022
d4e34bc
Update sbom.yml
tjarrettveracode Oct 24, 2022
c170bfa
Update sbom.yml
tjarrettveracode Oct 24, 2022
6038ada
Update sbom.yml
tjarrettveracode Oct 24, 2022
ed2646e
Update sbom.yml
tjarrettveracode Oct 24, 2022
bc2da3b
Update sbom.yml
tjarrettveracode Oct 24, 2022
0079b34
Update sbom.yml
tjarrettveracode Oct 24, 2022
ce1caa6
Update sbom.yml
tjarrettveracode Oct 24, 2022
dd61588
Update sbom.yml
tjarrettveracode Oct 24, 2022
e30e85e
Update sbom.yml
tjarrettveracode Oct 24, 2022
155e3ab
Update sbom.yml
tjarrettveracode Oct 24, 2022
04a0076
Update sbom.yml
tjarrettveracode Oct 24, 2022
dcb0863
Update sbom.yml
tjarrettveracode Oct 24, 2022
76baef2
Update sbom.yml
tjarrettveracode Oct 24, 2022
25d9fb6
Update sbom.yml
tjarrettveracode Oct 24, 2022
5b4054a
Update sbom.yml
tjarrettveracode Oct 24, 2022
dc35814
Update sbom.yml
tjarrettveracode Oct 24, 2022
0837a0a
Update sbom.yml
tjarrettveracode Oct 24, 2022
384ea0e
Update sbom.yml
tjarrettveracode Oct 24, 2022
74a5f00
create bitbucket template
tjarrettveracode Apr 4, 2023
7c37559
update gitignore
tjarrettveracode Aug 7, 2023
7e3cdfc
Create pipelinescan-cli.yml
tjarrettveracode Nov 2, 2023
2b6a9f5
Update pipelinescan-cli.yml
tjarrettveracode Nov 2, 2023
a2ae068
Update pipelinescan-cli.yml
tjarrettveracode Nov 2, 2023
ae2c21d
Update pipelinescan-cli.yml
tjarrettveracode Nov 2, 2023
df88ad3
Update pipelinescan-cli.yml
tjarrettveracode Nov 3, 2023
37ae243
Update pipelinescan-cli.yml
tjarrettveracode Nov 3, 2023
8439eb2
Update pipelinescan-cli.yml
tjarrettveracode Nov 3, 2023
db2ff24
Update pipelinescan-cli.yml
tjarrettveracode Nov 3, 2023
99edcf9
Update pipelinescan-cli.yml
tjarrettveracode Nov 3, 2023
6b08005
Update pipelinescan-cli.yml
tjarrettveracode Nov 3, 2023
1abf304
Update pipelinescan-cli.yml
tjarrettveracode Nov 3, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
106 changes: 106 additions & 0 deletions .github/workflows/pipelinescan-cli.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
# This workflow will initiate a Veracode Static Analysis Pipeline scan, return a results.json and convert to SARIF for upload as a code scanning alert

name: Veracode Static Analysis Pipeline Scan (CLI)

# Controls when the action will run. Triggers the workflow on push or pull request
# events but only for the master branch
on:
workflow_dispatch:
push:
branches: [ master, main ]
pull_request:
branches: [ master, main ]

# A workflow run is made up of one or more jobs that can run sequentially or in parallel
jobs:
# This workflow contains a job to build and submit pipeline scan, you will need to customize the build process accordingly and make sure the artifact you build is used as the file input to the pipeline scan file parameter
build:
# The type of runner that the job will run on
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2

# build the application
- name: Check for Maven build
id: check_maven
uses: andstor/file-existence-action@v2
with:
files: "pom.xml"

- name: Check for Gradle build
id: check_gradle
uses: andstor/file-existence-action@v2
with:
files: "build.gradle"

- name: Build application with mvn
if: steps.check_maven.outputs.files_exists == 'true'
run: mvn -B package --file pom.xml

- name: Build application with gradle
if: steps.check_gradle.outputs.files_exists == 'true'
run: gradle clean build

- name: Archive package
uses: actions/upload-artifact@v3
with:
name: CodePackage
path: '**/*.war'

pipeline-scan:
needs: build
runs-on: ubuntu-latest

env:
VERACODE_API_KEY_ID: ${{secrets.VERACODE_API_ID}}
VERACODE_API_KEY_SECRET: ${{secrets.VERACODE_API_KEY}}

steps:
- name: setup cli
run: |
curl -fsS https://tools.veracode.com/veracode-cli/install | sh
continue-on-error: false

- name: Retrieve artifact
uses: actions/download-artifact@v3
with:
name: CodePackage

# Submit project to pipeline scan
- name: Pipeline Scan
run: |
./veracode static scan "target/verademo.war" --fail-on-severity="Very High, High" --app-id="${{secrets.VERACODE_APP_ID}}" --results-file="results.json"
continue-on-error: true

- uses: actions/upload-artifact@v3
with:
name: ScanResults
path: results.json

# Convert pipeline scan output to SARIF format
process-results:
needs: pipeline-scan
runs-on: ubuntu-latest
steps:

- name: Retrieve results
uses: actions/download-artifact@v3
with:
name: ScanResults

- name: convert
uses: veracode/veracode-pipeline-scan-results-to-sarif@master
with:
pipeline-results-json: results.json
output-results-sarif: veracode-results.sarif
finding-rule-level: "4:3:0"

- uses: actions/upload-artifact@v3
with:
name: SarifFile
path: veracode-results.sarif

- uses: github/codeql-action/upload-sarif@v2
with:
# Path to SARIF file relative to the root of the repository
sarif_file: veracode-results.sarif
106 changes: 106 additions & 0 deletions .github/workflows/pipelinescan-java.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
# This workflow will initiate a Veracode Static Analysis Pipeline scan, return a results.json and convert to SARIF for upload as a code scanning alert

name: Veracode Static Analysis Pipeline Scan

# Controls when the action will run. Triggers the workflow on push or pull request
# events but only for the master branch
on:
workflow_dispatch:
push:
branches: [ master, main ]
pull_request:
branches: [ master, main ]

# A workflow run is made up of one or more jobs that can run sequentially or in parallel
jobs:
# This workflow contains a job to build and submit pipeline scan, you will need to customize the build process accordingly and make sure the artifact you build is used as the file input to the pipeline scan file parameter
build:
# The type of runner that the job will run on
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2

# build the application
- uses: actions/setup-java@v1 # Make java accessible on path so the uploadandscan action can run.
with:
java-version: '8'

- name: Check for Maven build
id: check_maven
uses: andstor/file-existence-action@v1
with:
files: "pom.xml"

- name: Check for Gradle build
id: check_gradle
uses: andstor/file-existence-action@v1
with:
files: "build.gradle"

- name: Build application with mvn
if: steps.check_maven.outputs.files_exists == 'true'
run: mvn -B package --file pom.xml

- name: Build application with gradle
if: steps.check_gradle.outputs.files_exists == 'true'
run: gradle clean build

- name: Archive package
uses: actions/upload-artifact@v2
with:
name: CodePackage
path: '**/*.war'

pipeline-scan:
needs: build
runs-on: ubuntu-latest
container:
image: veracode/pipeline-scan:latest
options: --user root # our normal luser doesn't have privs to write to github directories

steps:
- name: Retrieve artifact
uses: actions/download-artifact@v2
with:
name: CodePackage
path: /github/home

# Submit project to pipeline scan
- name: Pipeline Scan
run: |
cd /github/home/target
java -jar /opt/veracode/pipeline-scan.jar --veracode_api_id="${{secrets.VERACODE_API_ID}}" --veracode_api_key="${{secrets.VERACODE_API_KEY}}" --fail_on_severity="Very High, High" --file="verademo.war" --app_id="${{secrets.VERACODE_APP_ID}}" --json_output_file="results.json"
continue-on-error: true

- uses: actions/upload-artifact@v2
with:
name: ScanResults
path: /github/home/target/results.json

# Convert pipeline scan output to SARIF format
process-results:
needs: pipeline-scan
runs-on: ubuntu-latest
steps:

- name: Retrieve results
uses: actions/download-artifact@v2
with:
name: ScanResults

- name: convert
uses: veracode/veracode-pipeline-scan-results-to-sarif@master
with:
pipeline-results-json: results.json
output-results-sarif: veracode-results.sarif
finding-rule-level: "4:3:0"

- uses: actions/upload-artifact@v2
with:
name: SarifFile
path: veracode-results.sarif

- uses: github/codeql-action/upload-sarif@v2
with:
# Path to SARIF file relative to the root of the repository
sarif_file: veracode-results.sarif
55 changes: 55 additions & 0 deletions .github/workflows/policyscan-java.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# This is a basic workflow to help you get started with Actions

name: Veracode Policy Scan

# Controls when the action will run. Triggers the workflow on push or pull request
# events but only for the master branch
on:
workflow_dispatch:

# A workflow run is made up of one or more jobs that can run sequentially or in parallel
jobs:
# This workflow contains a single job called "build"
build-and-policy-scan:
# The type of runner that the job will run on
runs-on: ubuntu-latest

# Steps represent a sequence of tasks that will be executed as part of the job
steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
- uses: actions/checkout@v2
- uses: actions/setup-java@v1 # Make java accessible on path so the uploadandscan action can run.
with:
java-version: '8'

- name: Build with Maven
run: mvn -B package --file pom.xml

- uses: actions/upload-artifact@v2 # Copy files from repository to docker container so the next uploadandscan action can access them.
with:
path: '**/*.war' # Wildcards can be used to filter the files copied into the container. See: https://github.com/actions/upload-artifact
- uses: veracode/veracode-uploadandscan-action@master # Run the uploadandscan action. Inputs are described above.
with:
appname: '${{ secrets.VERACODE_APP_NAME }}'
filepath: '**/*.war'
vid: '${{ secrets.VERACODE_API_ID }}'
vkey: '${{ secrets.VERACODE_API_KEY }}'
scantimeout: 15
createprofile: false

sbom:
if: ${{ always() }}
needs: build-and-policy-scan
runs-on: ubuntu-latest
env:
VERACODE_API_KEY_ID: '${{ secrets.VERACODE_API_ID }}'
VERACODE_API_KEY_SECRET: '${{ secrets.VERACODE_API_KEY }}'

steps:
- uses: actions/setup-python@v4
with:
python-version: '3.9'
cache: 'pip'
- run:
pip install veracode-api-signing
http --auth-type=veracode_hmac "http://api.veracode.com/appsec/v1/applications?legacy_id=$VERACODE_APP_ID"
35 changes: 35 additions & 0 deletions .github/workflows/sbom.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
# This workflow retrieves the SBOM for the application being scanned and saves it as an artifact in the pipeline.
# Required secrets (also used by the pipelinescan-*.yml workflows):
# VERACODE_API_ID, VERACODE_API_KEY: API credentials for a Veracode user
# VERACODE_APP_ID: Numeric application ID for the application profile for this project

---
name: SBOM

on:
workflow_dispatch:

jobs:
sbom:
name: setup
runs-on: ubuntu-latest
container:
image: veracode/api-signing:latest
env:
VERACODE_API_KEY_ID: ${{ secrets.VERACODE_API_ID }}
VERACODE_API_KEY_SECRET : ${{ secrets.VERACODE_API_KEY }}

steps:
- name: generate-sbom
run: |
cd /tmp
export LEGACYID=${{ secrets.VERACODE_APP_ID }}
appguid=$(http --auth-type=veracode_hmac GET "https://api.veracode.com/appsec/v1/applications?legacy_id=${LEGACYID}" | jq -r '._embedded.applications[0].guid')
echo GUID: ${appguid}
http --auth-type=veracode_hmac GET "https://api.veracode.com/srcclr/sbom/v1/targets/${appguid}/cyclonedx?type=application" > sbom.json
ls -l
- name: save sbom file
uses: actions/upload-artifact@v3
with:
name: sbom
path: /tmp/sbom.json
6 changes: 6 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -10,3 +10,9 @@ target/
WebContent/
flaws.json
.vscode/settings.json

filtered_results.json
results.json
pipeline-scan-LATEST.zip
pipeline-scan.jar
out/
Loading