Skip to content

CxFlow

CxFlow #172

Workflow file for this run

name: CxFlow
on:
push:
branches: [ master ]
pull_request:
branches: [ master ]
schedule:
- cron: '39 15 * * 1'
permissions:
contents: read
jobs:
build:
name: CHECKMARX
permissions:
contents: read
issues: write
pull-requests: write
security-events: write
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Checkmarx CxFlow Action
uses: itsKedar/checkmarx-cxflow-github-action@a1b5819d73ce07f251148e89b37e615cdef67199
env:
#SCA_SCARESOLVERADDPARAMETERS_CUSTOM-PARAMETER : "--gradle-parameters=-Paws.codeartifact.username=${{ github.repository_owner }} -Paws.codeartifact.token=${{ github.repository_owner }}"
#SCA_SCARESOLVERADDPARAMETERS_LOG-LEVEL : Debug
#JIRA_FIELDS_0_JIRA_DEFAULT_VALUE : APPSEC-2371
#JIRA_FIELDS_0_JIRA_FIELD_NAME : "Epic Link"
#JIRA_FIELDS_0_JIRA_FIELD_TYPE : text
#JIRA_FIELDS_0_TYPE : static
CXFLOW_PROJECTCUSTOMFIELD : "git:git test,kedar:bhujade,test:test1"
with:
project: ${{ github.repository }}-PR
team: ${{ secrets.CHECKMARX_TEAMS }}
checkmarx_url: ${{ secrets.CHECKMARX_URL }}
checkmarx_username: ${{ secrets.CHECKMARX_USERNAME }}
checkmarx_password: ${{ secrets.CHECKMARX_PASSWORD }}
checkmarx_client_secret: ${{ secrets.CHECKMARX_CLIENT_SECRET }}
scanners: sast
incremental: false
#extra_certificates: .
break_build: true
scan_custom_field_key: "test"
scan_custom_field_value: "test"
preset: 'Checkmarx Default'
bug_tracker: GitHub
sca_api_url: ${{ secrets.SCA_API_URL }}
sca_app_url: ${{ secrets.SCA_APP_URL }}
sca_access_control_url: ${{ secrets.SCA_ACCESS_CONTROL_URL }}
sca_tenant: ${{ secrets.SCA_TENANT }}
sca_username: ${{ secrets.SCA_USERNAME }}
sca_password: ${{ secrets.SCA_PASSWORD }}
jira_url : 'https://kedarbhujade.atlassian.net'
jira_username : '[email protected]'
jira_token : ${{ secrets.JIRA_TOKEN }}
jira_project : 'APPSEC'
jira_issue_type : 'Bug'
jira_open_transition : 'In Progress'
jira_close_transition : 'Done'
jira_open_status : 'Selected for Development,In Progress'
jira_closed_status : 'Done'
params: '--github --checkmarx.settings-override=true --namespace=${{ github.repository_owner }} --repo-name=${{ github.event.repository.name }} --branch=${{ github.ref_name }} --merge-id=${{ github.event.number }} --logging.level.com.checkmarx.*=DEBUG'