Skip to content

Commit d3a967a

Browse files
committed
Add GitLab / Gemnasium dependency vulnerability scanning.
1 parent 530d5e9 commit d3a967a

File tree

1 file changed

+17
-0
lines changed

1 file changed

+17
-0
lines changed

.gitlab-ci.yml

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
# Enable gemnasium dependency vulnerability scanning
2+
dependency_scanning:
3+
image: docker:stable
4+
variables:
5+
DOCKER_DRIVER: overlay2
6+
allow_failure: true
7+
services:
8+
- docker:stable-dind
9+
script:
10+
- export SP_VERSION=$(echo "$CI_SERVER_VERSION" | sed 's/^\([0-9]*\)\.\([0-9]*\).*/\1-\2-stable/')
11+
- docker run
12+
--env DEP_SCAN_DISABLE_REMOTE_CHECKS="${DEP_SCAN_DISABLE_REMOTE_CHECKS:-false}"
13+
--volume "$PWD:/code"
14+
--volume /var/run/docker.sock:/var/run/docker.sock
15+
"registry.gitlab.com/gitlab-org/security-products/dependency-scanning:$SP_VERSION" /code
16+
artifacts:
17+
paths: [gl-dependency-scanning-report.json]

0 commit comments

Comments
 (0)