Skip to content

veracode/veracode-dast-action

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Veracode DAST Action

Veracode DAST Action starts Veracode DAST scan as an action on any GitHub pipeline. It requires a DAST scan to be already configured on the Veracode platform and restarts the scan.

About

This action will simply use a little JSON file that is used to reconfigure the time to start and how long a scan should run.

Usage

The action haas some required parameters

vid

Required - The Veracode API ID

vkey

Requireed - The Veracode API Key

dast_config_file_name

Requireed - The DAST Config File Name

token

Requireed - your GITHUB_TOKEN - This will be automatically set to ${{ github.token }}

owner

Requireed - owner of the repo - This will be automatically set to ${{ github.repository_owner }}

repo

Requireed - repo name - This will be automaticall set to ${{ github.event.repository.name }}

Example usage

name: Veracode DAST

jobs:
    Submit-DAST-Scan:
        runs-on: ubuntu-latest
        steps:
            - name: Submit Veracode DAST Scan
              uses: veracode-australia/veracode-dast-action@main with:
                vid: ${{ secrets.VERACODE_API_ID }}
                vkey: ${{ secrets.VERACODE_API_KEY }}
                dast_config_file_name: input.json
                owner: Veracode-DemoLabs repo: verademo-javascript
                token: ${{ secrets.GITHUB_TOKEN }}

An exampkle JSON file would look like this

{
  "name": "Name-of-Your-Dynamic-Analysis",
  "schedule": {
    "start_date": "2020-09-26T02:00+00:00",
    "duration": {
      "length": 3,
      "unit": "DAY"
    }
  }
}

A full documentation about the JSON payload and the API used in the background can be found here

.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Packages

No packages published