gitlab.com - Configure SAST analyzers CI to trigger blocking bridge non ...
www.practical-devsecops.com - Software Supply Chain Security Training
medium.com - Implementing Trufflehog in Gitlab CI/CD pipeline
docs.gitlab.com - Secret detection
github.com - analysis-tools-dev/static-analysis
medium.com - Security Analysis and Validation of Generative-AI- ...
stages:
- build
- test
- secrets
build-job:
stage: build
image: python:3.9
script:
- apt-get update && apt-get install -y ruby bundler
- python -m venv venv
- source venv/bin/activate
- pip install --upgrade pip
- pip install -r requirements.txt
- bundle install
test-job:
stage: test
image: python:3.9
dependencies:
- build
script:
- source venv/bin/activate
- pip install bandit
- bandit -r . -o bandit_report.txt -f txt # Python static analysis
- gem install brakeman -N
- brakeman -o brakeman_report.txt # Rails static analysis
artifacts:
paths:
- bandit_report.txt
- brakeman_report.txt
expire_in: 1 week
secrets--job:
stage: secrets
image: python:3.9
dependencies:
- test
script:
- source venv/bin/activate
- pip install trufflehog
- trufflehog filesystem . --output trufflehog_report.json
artifacts:
paths:
- trufflehog_report.json
expire_in: 1 week
This GitLab CI/CD pipeline performs static analysis for both Python and Ruby on Rails projects, followed by secret analysis.
build: Sets up environments for both Python (using venv) and Ruby/Rails (installing bundler and dependencies).
test:
Runs Bandit for Python static analysis, generating a text report bandit_report.txt.
Runs Brakeman for Rails static analysis, generating a text report brakeman_report.txt.
Both reports are saved as artifacts.
False Positive Analysis: For both Bandit and Brakeman, the generated reports should be reviewed. False positives (identified issues that are not actual vulnerabilities) can be suppressed or marked as such in configuration files if the tools support it, or through comments if the report format allows. GitLab's Secret Detection also allows marking detections as false positives in the UI [4].
secrets:
Runs TruffleHog to scan the file system for secrets like API keys and passwords [3].
The findings are saved in trufflehog_report.json as an artifact. This helps in identifying potential security leaks in the codebase.