Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/security_test_suite.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,4 +18,4 @@ jobs:
run: conviso --version

- name: Run AST
run: conviso ast run --vulnerability-auto-close
run: conviso ast run
30 changes: 15 additions & 15 deletions docs/integrations/azure-devops-ast-orchestrator.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ keywords:

The Conviso Platform **Azure DevOps AST Orchestrator** runs Conviso AST from **one** Azure Pipeline (the orchestrator). Application repositories do **not** need a Conviso pipeline of their own.

When an eligible pull request is **merged**, Conviso triggers that pipeline and passes the target repository and branch. The job obtains a short-lived clone credential from the Platform (using your API key), clones the target repository, runs `conviso-ast`, and sends findings to the mapped asset.
When an eligible pull request is **merged**, Conviso triggers that pipeline and passes the target repository and branch. The job obtains a short-lived clone credential from the Platform (using your API key), clones the target repository, runs `conviso ast run`, and sends findings to the mapped asset.

You do **not** store a PAT or map `System.AccessToken` for clone — only `CONVISO_API_KEY`.

Expand All @@ -29,7 +29,7 @@ flowchart LR
A[PR merged on target repo] --> B[Conviso Platform]
B -->|Pipeline run with<br/>repo + branch| C[Orchestrator pipeline<br/>azure-pipelines.yml]
C -->|conviso-ast-repository-token<br/>integration OAuth token| D[Clone target repo]
D --> E[conviso-ast]
D --> E[conviso ast run]
E --> F[Findings on the asset]
```

Expand Down Expand Up @@ -147,7 +147,7 @@ pool:

# Azure requires an empty entrypoint or container steps fail to docker exec.
container:
image: convisoappsec/convisoast_v2:latest
image: convisoappsec/convisoast:latest
options: --entrypoint ""

steps:
Expand All @@ -160,15 +160,15 @@ steps:
exit 1
fi

export CONVISO_APIKEY="$CONVISO_API_KEY"
export CONVISO_BASE_URL="${API_URL:-https://api.convisoappsec.com}"
CONVISO_BASE_URL="${CONVISO_BASE_URL%/}"
case "$CONVISO_BASE_URL" in
export CONVISO_API_KEY="$CONVISO_API_KEY"
export CONVISO_API_URL="${API_URL:-https://api.convisoappsec.com}"
CONVISO_API_URL="${CONVISO_API_URL%/}"
case "$CONVISO_API_URL" in
https://app.convisoappsec.com)
export CONVISO_BASE_URL="https://api.convisoappsec.com"
export CONVISO_API_URL="https://api.convisoappsec.com"
;;
https://staging.convisoappsec.com)
export CONVISO_BASE_URL="https://api.staging.convisoappsec.com"
export CONVISO_API_URL="https://api.staging.convisoappsec.com"
;;
esac

Expand All @@ -185,7 +185,7 @@ steps:
umask 077
TOKEN=$(conviso-ast-repository-token --provider azure_devops)
echo "##vso[task.setvariable variable=REPO_TOKEN;issecret=true]$TOKEN"
echo "##vso[task.setvariable variable=CONVISO_BASE_URL]$CONVISO_BASE_URL"
echo "##vso[task.setvariable variable=CONVISO_API_URL]$CONVISO_API_URL"
displayName: Get repository token
env:
CONVISO_API_KEY: $(CONVISO_API_KEY)
Expand Down Expand Up @@ -268,8 +268,8 @@ steps:
- script: |
set -euo pipefail
cd target
export CONVISO_APIKEY="$CONVISO_API_KEY"
export CONVISO_BASE_URL="${NORMALIZED_BASE_URL}"
export CONVISO_API_KEY="$CONVISO_API_KEY"
export CONVISO_API_URL="${NORMALIZED_BASE_URL}"
export CONVISO_COMPANY_ID="${PARAM_COMPANY_ID:-$VAR_COMPANY_ID}"
export CONVISO_BRANCH="$BRANCH"
case "${ASSET_ID:-}" in
Expand All @@ -280,14 +280,14 @@ steps:
""|none|0) unset CONVISO_SCAN_RUN_ID || true ;;
*) export CONVISO_SCAN_RUN_ID="$SCAN_RUN_ID" ;;
esac
conviso-ast -p . -o "$(Build.ArtifactStagingDirectory)/conviso-ast-session.zip"
conviso ast run --repository-dir . --output "$(Build.ArtifactStagingDirectory)/conviso-ast-session.zip"
displayName: Run Conviso AST
env:
GIT_CONFIG_COUNT: "1"
GIT_CONFIG_KEY_0: safe.directory
GIT_CONFIG_VALUE_0: "*"
CONVISO_API_KEY: $(CONVISO_API_KEY)
NORMALIZED_BASE_URL: $(CONVISO_BASE_URL)
NORMALIZED_BASE_URL: $(CONVISO_API_URL)
PARAM_COMPANY_ID: ${{ parameters.company_id }}
VAR_COMPANY_ID: $(CONVISO_COMPANY_ID)
ASSET_ID: ${{ parameters.asset_id }}
Expand Down Expand Up @@ -385,7 +385,7 @@ Do **not** add an Azure DevOps PAT for clone. The job calls `conviso-ast-reposit
1. Developer merges a PR into the configured merge target on an imported, enabled asset.
2. Conviso validates the event and configuration, then starts the orchestrator pipeline on the **Ref** branch.
3. Template parameters include the repository, branch, and related ids Conviso needs for the run.
4. Job steps: issue repository token → clone target → run `conviso-ast` → upload session artifact.
4. Job steps: issue repository token → clone target → run `conviso ast run` → upload session artifact.
5. Findings appear on the asset in Conviso Platform.
6. In Azure DevOps, open the **orchestrator** pipeline run to inspect logs.

Expand Down
8 changes: 4 additions & 4 deletions docs/integrations/azure-pipelines-cli.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ image: '/static/img/azurepipelinesseo.png'

Integrate the Conviso Platform seamlessly into your [Azure DevOps Pipelines](https://dev.azure.com/) to automate and streamline your security processes. This integration ensures thorough security assessments for your applications throughout the development lifecycle.

You can run the Conviso Platform AST (Application Security Testing), which offers Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Code Review directly on your Azure Pipelines.
You can run the Conviso Platform AST (Application Security Testing), which offers Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC) analysis, SBOM generation and secret detection directly on your Azure Pipelines.

This integration provides the **CLI as a Docker** image for executing tasks and establishing connections with the Conviso Platform.

Expand Down Expand Up @@ -54,9 +54,9 @@ To set a variable for a build pipeline:
</div>

## Perform a Conviso AST scan to analyze your application's security
Empower your security analysis with Application Security Testing (AST) by directly incorporating the Conviso AST scan into your pipeline. This versatile tool offers SAST, SCA, and Code Review capabilities, all integrated within your pipeline.
Empower your security analysis with Application Security Testing (AST) by directly incorporating the Conviso AST scan into your pipeline. A single `conviso ast run` covers SAST, SCA, IaC, SBOM and secret analysis, all integrated within your pipeline.

Follow the script below to integrate Security Code Review seamlessly into your pipeline, creating a comprehensive solution within your ```azure-pipelines.yml``` file:
Follow the script below to integrate it seamlessly into your pipeline, creating a comprehensive solution within your ```azure-pipelines.yml``` file:

```yml
trigger:
Expand All @@ -72,7 +72,7 @@ jobs:
- checkout: self
persistCredentials: true
- bash: |
conviso ast run --vulnerability-auto-close
conviso ast run
displayName: 'Running Conviso AST'
env:
CONVISO_API_KEY: $(CONVISO_API_KEY)
Expand Down
8 changes: 4 additions & 4 deletions docs/integrations/azure-pipelines-graph.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,11 +71,11 @@ Given an Azure DevOps project, to create a Welcome Pipeline you can follow the s
```bash
docker run --rm \
-v /var/run/docker.sock:/var/run/docker.sock \
-v $(pwd):/opt/flowcli \
-v $(pwd):/workdir \
-e DOCKER_HOST=$(DOCKER_HOST) \
-e CONVISO_API_KEY=$(CONVISO_API_KEY) \
convisoappsec/convisoast:latest \
conviso ast run --vulnerability-auto-close
conviso ast run
```

2. Click at **Save & Queue**. The pipeline execution will begin in a few moments.
Expand Down Expand Up @@ -131,7 +131,7 @@ variable.
```bash
docker run --rm \
-v /var/run/docker.sock:/var/run/docker.sock \
-v $(pwd):/opt/flowcli \
-v $(pwd):/workdir \
-e DOCKER_HOST=$(DOCKER_HOST) \
-e CONVISO_API_KEY=$(CONVISO_API_KEY) \
convisoappsec/convisoast:latest \
Expand All @@ -149,7 +149,7 @@ docker run --rm \
```bash
docker run --rm \
-v /var/run/docker.sock:/var/run/docker.sock \
-v $(pwd):/opt/flowcli \
-v $(pwd):/workdir \
-e DOCKER_HOST=$(DOCKER_HOST) \
-e CONVISO_API_KEY=$(CONVISO_API_KEY) \
convisoappsec/convisoast:latest \
Expand Down
22 changes: 11 additions & 11 deletions docs/integrations/bitbucket-ast-orchestrator.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ keywords:

The Conviso Platform **Bitbucket AST Orchestrator** runs Conviso AST from **one** Bitbucket repository (the orchestrator). Application repositories do **not** need a Conviso Pipelines file.

When an eligible pull request is **merged**, Conviso triggers a **custom pipeline** (`run-ast-scan`) on the orchestrator and passes the target repository and branch. The job obtains a short-lived clone credential from the Platform (using your API key), clones the target repository, runs `conviso-ast`, and sends findings to the mapped asset.
When an eligible pull request is **merged**, Conviso triggers a **custom pipeline** (`run-ast-scan`) on the orchestrator and passes the target repository and branch. The job obtains a short-lived clone credential from the Platform (using your API key), clones the target repository, runs `conviso ast run`, and sends findings to the mapped asset.

You do **not** store a Bitbucket App password or OAuth token for clone — only `CONVISO_API_KEY`.

Expand All @@ -29,7 +29,7 @@ flowchart LR
A[PR merged on target repo] --> B[Conviso Platform]
B -->|Custom pipeline run-ast-scan on Ref| C[Orchestrator repo<br/>bitbucket-pipelines.yml]
C -->|conviso-ast-repository-token<br/>integration OAuth token| D[Clone target repo]
D --> E[conviso-ast]
D --> E[conviso ast run]
E --> F[Findings on the asset]
```

Expand Down Expand Up @@ -125,7 +125,7 @@ On the orchestrator branch you will set as **Ref** (usually `main`):
2. Paste the YAML below (or copy it from the example repo).

```yaml
image: convisoappsec/convisoast_v2:latest
image: convisoappsec/convisoast:latest

pipelines:
custom:
Expand All @@ -150,16 +150,16 @@ pipelines:
clone:
enabled: false
script:
- export CONVISO_APIKEY="$CONVISO_API_KEY"
- export CONVISO_API_KEY="$CONVISO_API_KEY"
- |
export CONVISO_BASE_URL="${api_url:-https://api.convisoappsec.com}"
CONVISO_BASE_URL="${CONVISO_BASE_URL%/}"
case "$CONVISO_BASE_URL" in
export CONVISO_API_URL="${api_url:-https://api.convisoappsec.com}"
CONVISO_API_URL="${CONVISO_API_URL%/}"
case "$CONVISO_API_URL" in
https://app.convisoappsec.com)
export CONVISO_BASE_URL="https://api.convisoappsec.com"
export CONVISO_API_URL="https://api.convisoappsec.com"
;;
https://staging.convisoappsec.com)
export CONVISO_BASE_URL="https://api.staging.convisoappsec.com"
export CONVISO_API_URL="https://api.staging.convisoappsec.com"
;;
esac
- export CONVISO_REPO_FULL_NAME="$repo_full_name"
Expand All @@ -181,7 +181,7 @@ pipelines:
- export GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0=safe.directory GIT_CONFIG_VALUE_0='*'
- export CONVISO_COMPANY_ID="${company_id:-$CONVISO_COMPANY_ID}"
- export CONVISO_BRANCH="$branch"
- conviso-ast -p . -o "$BITBUCKET_CLONE_DIR/conviso-ast-session.zip"
- conviso ast run --repository-dir . --output "$BITBUCKET_CLONE_DIR/conviso-ast-session.zip"
artifacts:
- conviso-ast-session.zip
```
Expand Down Expand Up @@ -228,7 +228,7 @@ pipelines:
1. Developer merges a PR into the configured merge target on an imported, enabled asset.
2. Conviso validates the event and configuration, then starts custom pipeline **`run-ast-scan`** on the orchestrator / **Ref**.
3. Variables include at least: `repo_full_name`, `branch` (PR destination), `commit_sha`, `pr_id`, `api_url`, `company_id`, `asset_id` (blank values may be omitted).
4. Job steps: issue repository token → clone target at `branch` → run `conviso-ast` → upload session artifact.
4. Job steps: issue repository token → clone target at `branch` → run `conviso ast run` → upload session artifact.
5. Findings appear on the asset in Conviso Platform.
6. In Bitbucket, open the **orchestrator** → **Pipelines** → run **`run-ast-scan`** to inspect the job.

Expand Down
8 changes: 4 additions & 4 deletions docs/integrations/bitbucket-pipelines.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ Looking for **centralized AST after merge** (one Pipelines repo for many assets,

With Conviso Platform integrated into your Bitbucket CI/CD Pipeline, you can automate your security processes, ensuring that your applications undergo through automated security assessments in new versions of your code.

You can run Conviso Platform **AST (Application Security Testing)**. This product offers **Static Application Security Testing (SAST)**, **Software Composition Analysis (SCA)**, Infrastructure as Code (IaC) and enables **Continuous Code Review** performed by our Security Analysts directly on your Bitbucket pipeline.
You can run Conviso Platform **AST (Application Security Testing)**. This product offers **Static Application Security Testing (SAST)**, **Software Composition Analysis (SCA)**, **Infrastructure as Code (IaC)** analysis, **SBOM** generation and **secret detection** directly on your Bitbucket pipeline.

## Setting up a new repository without an existing pipeline

Expand Down Expand Up @@ -73,7 +73,7 @@ In order for the environment to be ready for the execution of all Conviso AST re

## Conviso AST

You can run Conviso Platform **AST (Application Security Testing)**. This product offers **Static Application Security Testing (SAST)**, **Software Composition Analysis (SCA)**, **Infrastructure as Code (IaC)** and enables **Continuous Code Review** to be performed by Security Analysts of Conviso (when supported in your plan) or by your own Security Analysts team.
You can run Conviso Platform **AST (Application Security Testing)**. This product offers **Static Application Security Testing (SAST)**, **Software Composition Analysis (SCA)**, **Infrastructure as Code (IaC)** analysis, **SBOM** generation and **secret detection**, reporting every finding to the asset on the Conviso Platform.

```yml
image: convisoappsec/convisoast
Expand All @@ -85,7 +85,7 @@ pipelines:
name: Conviso BitBucket Pipeline
script:
- |
conviso ast run --vulnerability-auto-close \
conviso ast run \
services:
- docker
```
Expand Down Expand Up @@ -166,7 +166,7 @@ To view the company ID, click on the company logo icon, as exemplified in the im
Example
```
- export CONVISO_COMPANY_ID=0000
- conviso ast run --vulnerability-auto-close
- conviso ast run
```


Expand Down
2 changes: 1 addition & 1 deletion docs/integrations/circleci.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ jobs:
- checkout
- run:
name: "Conviso AST"
command: "conviso ast run --vulnerability-auto-close"
command: "conviso ast run"

# Orchestrate jobs using workflows
# See: https://circleci.com/docs/workflows/ & https://circleci.com/docs/configuration-reference/#workflows
Expand Down
27 changes: 14 additions & 13 deletions docs/integrations/codefresh.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,19 +51,20 @@ steps:

```txt title="Output:"
Executing command: conviso --help
Usage: conviso [OPTIONS] COMMAND [ARGS]...
Options:
-k, --api-key TEXT The api key to access conviso resources. [env var: FLOW_API_KEY]
-u, --api-url TEXT The api url to access conviso resources. [env var: FLOW_API_URL; default: https://app.convisoappsec.com]
-i, --api-insecure HTTPS requests to untrusted hosts is enable. [env var: FLOW_API_INSECURE; default: False]
-h, --help Show this message and exit.
-v, --version Show the version and exit.
Conviso AST 4.0.0

Commands:
deploy
finding
sast
sca
Run conviso COMMAND --help for more information on a command.

conviso ast run [options] run SAST, SCA, IaC, SBOM and secret
conviso sast run [options] run the SAST scanner
conviso sca run [options] run the SCA scanner
conviso iac run [options] run the IaC scanner
conviso sbom generate [options] generate the SBOM
conviso secret run [options] run the secret scanner
conviso container run <image> scan a container image (not part of ast)
conviso <command> dry-run the same scan, no platform writes
...

Successfully ran freestyle step: AST Hello
```

Expand Down Expand Up @@ -113,7 +114,7 @@ conviso_sample:
type: "freestyle"
image: "convisoappsec/convisoast"
commands:
- "conviso ast run --vulnerability-auto-close"
- "conviso ast run"
stage: "test"
working_directory: "/codefresh/volume/${{CF_REPO_NAME}}"
```
Expand Down
Loading