Pipeline Scan JSON to JUNIT XML

Has anyone written a parser to convert the Pipeline Scan JSON output file to the JUNIT XML file format for easier visibility of results within the CI pipeline.

My particular use case is for Gitlab CE (hence no sec dashboard) and it would be nice to have the results presented under the pipeline test tab for easy consumption by the devs.

 

Thanks,

 

Michael

 

@Integrations Group​ 


  • Anthony Fielding (Veracode)

    Hi @MClarkson676368 (Community Member)​,

    The Pipeline Scan offering is intended only for breaking the CI build and not for flaw results as it intentionally does not contain the detail required for remediation or any Software Composition Analysis vulnerabilities. I advise you retrieve the flaws for presentation only from the Policy Scan, with which we have a number of existing integrations for (https://community.veracode.com/s/integrations), including GitLab (https://community.veracode.com/s/knowledgeitem/gitlab-ci-MCEKSYPRWL35BRTGOVI55SK5RI4A). You may also wish to import these results into other popular issue tracking products such as JIRA etc. I hope this helps answer your question.

     

    Thanks,

    Anthony Fielding

    Expand Post
  • MClarkson676368 (Community Member)

    Hi @Anthony Fielding (Veracode)​ ,

     

    Thanks for your response, we are using a pipeline scan in dev/feature branches against our policy file for rapid SAST results (Policy scan performed on master branch, we are also utilising Agent SCA in all branches). We have other testing modalities in the Gitlab CI/CD pipeline that present their results as JUNIT so they are available to the developer under the Gitlab pipeline test tab for convenience and easy consumption (no need to switch context to other platforms/dashboards to interpret results).

    I'm confused as to why you see the pipeline scan does not contain detail for remediation, as we have issue creation enabled and the issues created by pipeline scan seem to give similar if not identical information to the Policy scan flaw details. So I was hoping that the results from the pipeline scan (json report) could be parsed to junit format so the developers could see the results along with the other non Veracode scan results to complement the issue creation, to limit context switching.

     

    Ultimately where all flaws from all testing modalities with correlation and deduplication should exist is still something we are battling with.

     

    Michael

    Expand Post
    • Anthony Fielding (Veracode)

      Hi @MClarkson676368 (Community Member)​,

      With each month we are improving the capabilities of our pipeline scanner. I was unaware we had deployed the enhanced flaw details but see that is now the case. My recommendation is still to go off the Policy Scan because of the following reasons to name a few:

      1. Policy scan takes into account mitigations which the pipeline scanner will not. A mitigation would likely be required to move forward with a CWE 73 flaw.
      2. Another reason would be for the Data Paths which are only available within the Triage Flaws area of the Analysis Centre for a Policy Scan.
      3. Policy scans produce reports which serve as documentation to prove compliance and evidence improvement and maturity of the product.

       

      You may wish to suggest we support JUNIT format for the Pipeline scanner results, over in the Ideas section of the Community (https://community.veracode.com/s/ideas) where you will be able to track your suggestion as it gets considered by Veracode.

       

      Thanks,

      Anthony

      Expand Post
  • DBasu874440 (Community Member)

    Hello @MClarkson676368 (Community Member)​ , Thank you for the feedback. I am a Product Manager and would love to learn more about the problem you mentioned (present results for easy consumption by devs). Sending you a quick email requesting time to discuss in depth.

     

    Deepro.

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.