Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .circleci/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,8 @@ jobs:
mvn clean package
curl https://www.shiftleft.io/download/sl-latest-linux-x64.tar.gz > /tmp/sl.tar.gz && sudo tar -C /usr/local/bin -xzf /tmp/sl.tar.gz
sl check-environment --jvm
sl analyze --wait --tag branch=$CIRCLE_BRANCH --policy 639070ed-7aad-4e53-bd5c-b97190308dc2/first_policy:latest --sca --cpg --app tarpit-java-circle /home/circleci/repo/target/tarpit-java.war
sl analyze --wait --tag branch=$CIRCLE_BRANCH --sca --cpg --app tarpit-java-circle /home/circleci/repo/target/tarpit-java.war
sl modify-findings --app tarpit-java-circle

sl_build_rules:
docker:
Expand Down
26 changes: 9 additions & 17 deletions inspect.yml
Original file line number Diff line number Diff line change
@@ -1,27 +1,19 @@
inspect:
- app:
language: JAVA
name: tarpit-java
policy: 639070ed-7aad-4e53-bd5c-b97190308dc2/first_policy:latest
modify-findings:
- my_modification_rule
- default:
policy: io.shiftleft/default
- app:
language: JAVA
name: tarpit-java-circle
policy: 639070ed-7aad-4e53-bd5c-b97190308dc2/first_policy:latest
modify-findings:
- sdl_to_info
finding-modifications:
my_modification_rule:
sdl_to_info:
filter:
category:
- Sensitive Data Leak
id:
- 97
type:
- vuln
severity:
- info
- moderate
- critical
tags:
- key: cvss_score
value: 3
- key: severity
value: info
- key: reason
value: appsec_approved