Skip to content

Add ShiftLeft build rules - #1

Open
rafikmojr wants to merge 1 commit into
masterfrom
demo-branch-1719140633
Open

Add ShiftLeft build rules#1
rafikmojr wants to merge 1 commit into
masterfrom
demo-branch-1719140633

Conversation

@rafikmojr

Copy link
Copy Markdown
Collaborator

Qwiet LogoQwiet Logo

This pull request enables build rules. You can read more about build rules here. The build rules are controlled by the shiftleft.yml file in the repository.

Visit app.shiftleft.io to see the security findings for this repository.

We've done a few things on your behalf

  • Forked this demo application
  • Generated a unique secret SHIFTLEFT_ACCESS_TOKEN to allow GitHub Actions in this repository to communicate with the Qwiet (Shiftleft) API
  • Committed a GitHub Action that will invoke Qwiet preZero's Static Application Security Testing (SAST) on all future pull requests on this repository
  • Created this pull request that demonstrates build rules. It also adds a status check that displays the result of the GitHub Action

Questions? Comments? Want to learn more? Get in touch with us or check out our documentation.

@github-actions

Copy link
Copy Markdown

Qwiet LogoQwiet Logo

Checking analysis of application Benchmark against 3 build rules.

Using sl version 0.9.2563 (562f0ba3adc158e3d5914467b9cc77788001f1e4).

Checking findings on scan 1.

Results per rule:

  • Allow no critical findings: pass
    (0 matched vulnerabilities; configured threshold is 0).

  • Allow one OSS or container finding: pass
    (0 matched vulnerabilities; configured threshold is 1).

  • Allow no reachable OSS vulnerability: pass
    (0 matched vulnerabilities; configured threshold is 0).

All rules passed.

@github-actions

Copy link
Copy Markdown

👋 @rafikmojr OWASP Benchmark scorecard is available for download in the Artifacts Section of GitHub Action

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant