Skip to content

Commit b37b4b4

Browse files
authored
CHEF-31151: enable Polaris integration (#41)
* chore: enable Polaris integration Signed-off-by: Nikita Mathur <nikita.mathur@progress.com> * fix: correct YAML indentation for run-bundle-install Signed-off-by: Nikita Mathur <nikita.mathur@progress.com> --------- Signed-off-by: Nikita Mathur <nikita.mathur@progress.com>
1 parent 883dbc0 commit b37b4b4

File tree

1 file changed

+8
-8
lines changed

1 file changed

+8
-8
lines changed

.github/workflows/ci-main-pull-request-stub.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -117,15 +117,15 @@ jobs:
117117

118118
# BlackDuck SAST (Polaris) require a build or binary present in repo to do SAST testing
119119
# requires these secrets: POLARIS_SERVER_URL, POLARIS_ACCESS_TOKEN
120-
perform-blackduck-polaris: false
120+
perform-blackduck-polaris: true
121121
polaris-application-name: "Chef-Agents" # one of these: Chef-Agents, Chef-Automate, Chef-Chef360, Chef-Habitat, Chef-Infrastructure-Server, Chef-Shared-Services, Chef-Other, Chef-Non-Product
122122
polaris-project-name: ${{ github.event.repository.name }} # arch-sample-cli
123-
polaris-working-directory: '.' # Working directory for the scan, defaults to . but usually lang-dependent like ./src
124-
polaris-coverity-build-command: 'go build -o bin/chef-cli.exe' # Coverity build command, typically done in build stage by language or here as param 1-liner like "mvn clean install"
125-
polaris-coverity-clean-command: 'go clean' # Coverity clean command, typically done before build stage by language or here as param 1-liner like "mvn clean"
126-
polaris-detect-search-depth: '5' # Detect search depth, blank but can be set to "3" to search up to 3 levels of subdirectories for code to scan'
127-
polaris-assessment-mode: 'SAST' # Assessment mode (SAST, CI or SOURCE_UPLOAD)
128-
wait-for-scan: true
123+
# polaris-working-directory: '.' # Working directory for the scan, defaults to . but usually lang-dependent like ./src
124+
# polaris-coverity-build-command: 'go build -o bin/chef-cli.exe' # Coverity build command, typically done in build stage by language or here as param 1-liner like "mvn clean install"
125+
# polaris-coverity-clean-command: 'go clean' # Coverity clean command, typically done before build stage by language or here as param 1-liner like "mvn clean"
126+
# polaris-detect-search-depth: '5' # Detect search depth, blank but can be set to "3" to search up to 3 levels of subdirectories for code to scan'
127+
# polaris-assessment-mode: 'SAST' # Assessment mode (SAST, CI or SOURCE_UPLOAD)
128+
# wait-for-scan: true
129129
# polaris-detect-args: '' # Additional Detect arguments, can supply extra arguments like "--detect.diagnostic=true"
130130
# coverity_build_command: "go build"
131131
# coverity_clean_command: "go clean"
@@ -171,7 +171,7 @@ jobs:
171171

172172
# perform Blackduck software composition analysis (SCA) for 3rd party CVEs, licensing, and operational risk
173173
perform-blackduck-sca-scan: true
174-
run-bundle-install: true # combined with generate sbom & generate github-sbom, also needs version above
174+
run-bundle-install: true # combined with generate sbom & generate github-sbom, also needs version above
175175
blackduck-project-group-name: 'Chef-Agents' # typically one of (Chef), Chef-Agents, Chef-Automate, Chef-Chef360, Chef-Habitat, Chef-Infrastructure-Server, Chef-Shared-Services, Chef-Non-Product'
176176
blackduck-project-name: ${{ github.event.repository.name }} # BlackDuck project name, typically the repository name
177177
blackduck-force-low-accuracy-mode: false # if true, forces BlackDuck Detect to run in low accuracy mode which can reduce scan time for large projects at the cost of potentially missing some vulnerabilities; see https://synopsys.atlassian.net/wiki/spaces/INTDOCS/pages/1138617921/Black+Duck+Detect+Accuracy+Levels for details

0 commit comments

Comments
 (0)