diff --git a/.circleci/config.yml b/.circleci/config.yml index abf3481..c8ebb62 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -36,7 +36,8 @@ jobs: mvn clean package curl https://www.shiftleft.io/download/sl-latest-linux-x64.tar.gz > /tmp/sl.tar.gz && sudo tar -C /usr/local/bin -xzf /tmp/sl.tar.gz sl check-environment --jvm - sl analyze --wait --tag branch=$CIRCLE_BRANCH --policy 639070ed-7aad-4e53-bd5c-b97190308dc2/first_policy:latest --sca --cpg --app tarpit-java-circle /home/circleci/repo/target/tarpit-java.war + sl analyze --wait --tag branch=$CIRCLE_BRANCH --sca --cpg --app tarpit-java-circle /home/circleci/repo/target/tarpit-java.war + sl modify-findings --app tarpit-java-circle sl_build_rules: docker: diff --git a/inspect.yml b/inspect.yml index b780548..63116b9 100644 --- a/inspect.yml +++ b/inspect.yml @@ -1,27 +1,19 @@ inspect: - - app: - language: JAVA - name: tarpit-java - policy: 639070ed-7aad-4e53-bd5c-b97190308dc2/first_policy:latest - modify-findings: - - my_modification_rule - - default: - policy: io.shiftleft/default +- app: + language: JAVA + name: tarpit-java-circle + policy: 639070ed-7aad-4e53-bd5c-b97190308dc2/first_policy:latest + modify-findings: + - sdl_to_info finding-modifications: - my_modification_rule: + sdl_to_info: filter: category: - Sensitive Data Leak - id: - - 97 - type: - - vuln - severity: - - info - - moderate - - critical tags: - key: cvss_score value: 3 - key: severity value: info + - key: reason + value: appsec_approved