This commit is contained in:
aswin-in-philips 2023-02-17 11:40:11 +05:30
parent fd601df0f7
commit a9def5ea4d
2 changed files with 6 additions and 5 deletions

View File

@ -104,13 +104,13 @@ jobs:
/bin/bash -c \
"(cd /code && \
/app/detect.sh \
--blackduck.url=https://blackduck.philips.com \
--blackduck.url='https://blackduck.philips.com' \
--blackduck.api.token=${{ secrets.BLACKDUCK_TOKEN }} \
--blackduck.trust.cert=true \
--detect.policy.check=true \
--detect.source.path=/code \
--detect.project.name=edifoundation-apigatewaytokenauthenticator \
--detect.project.version.name=1.0 \
--detect.project.name='edifoundation-apigatewaytokenauthenticator' \
--detect.project.version.name='1.0' \
--detect.blackduck.signature.scanner.individual.file.matching=ALL \
--detect.bom.aggregate.name={agregator})"

View File

@ -26,9 +26,10 @@ try {
& sourceanalyzer -b $FortifyBuildId -clean -logfile "$PSScriptRoot\fortify-clean.txt"
& sourceanalyzer -Xmx8G -b $FortifyBuildId "$RepositoryRoot\contrib"
& sourceanalyzer -Xmx8G -b $FortifyBuildId -gopath $RepositoryRoot -goroot $RepositoryRoot "$RepositoryRoot\**\*.go"
& sourceanalyzer -b $FortifyBuildId -show-files
& sourceanalyzer -Xmx8G -b $FortifyBuildId -Dcom.fortify.sca.Phase0HigherOrder.Languages=go -scan -f $FortifyFprPath -logfile "$PSScriptRoot\fortify-scan.txt"
#& sourceanalyzer -Xmx8G -b $FortifyBuildId -Dcom.fortify.sca.Phase0HigherOrder.Languages=go -scan -f $FortifyFprPath -logfile "$PSScriptRoot\fortify-scan.txt"
& sourceanalyzer -Xmx8G -b $FortifyBuildId -logfile "$PSScriptRoot\fortify-scan.txt" -scan -f $FortifyFprPath
#Upload fpr reports to fortify server
Write-Output "Uploading '$FortifyFprPath' of '$FortifyProjectId' with version '$FortifyVersionId' to '$PublishURL'"