
MClarkson676368 (Community Member) asked a question.
Has anyone written a parser to convert the Pipeline Scan JSON output file to the JUNIT XML file format for easier visibility of results within the CI pipeline.
My particular use case is for Gitlab CE (hence no sec dashboard) and it would be nice to have the results presented under the pipeline test tab for easy consumption by the devs.
Thanks,
Michael
.png)
Hi @MClarkson676368 (Community Member),
The Pipeline Scan offering is intended only for breaking the CI build and not for flaw results as it intentionally does not contain the detail required for remediation or any Software Composition Analysis vulnerabilities. I advise you retrieve the flaws for presentation only from the Policy Scan, with which we have a number of existing integrations for (https://community.veracode.com/s/integrations), including GitLab (https://community.veracode.com/s/knowledgeitem/gitlab-ci-MCEKSYPRWL35BRTGOVI55SK5RI4A). You may also wish to import these results into other popular issue tracking products such as JIRA etc. I hope this helps answer your question.
Thanks,
Anthony Fielding
Hi @Anthony Fielding (Veracode) ,
Thanks for your response, we are using a pipeline scan in dev/feature branches against our policy file for rapid SAST results (Policy scan performed on master branch, we are also utilising Agent SCA in all branches). We have other testing modalities in the Gitlab CI/CD pipeline that present their results as JUNIT so they are available to the developer under the Gitlab pipeline test tab for convenience and easy consumption (no need to switch context to other platforms/dashboards to interpret results).
I'm confused as to why you see the pipeline scan does not contain detail for remediation, as we have issue creation enabled and the issues created by pipeline scan seem to give similar if not identical information to the Policy scan flaw details. So I was hoping that the results from the pipeline scan (json report) could be parsed to junit format so the developers could see the results along with the other non Veracode scan results to complement the issue creation, to limit context switching.
Ultimately where all flaws from all testing modalities with correlation and deduplication should exist is still something we are battling with.
Michael
Hi @MClarkson676368 (Community Member),
With each month we are improving the capabilities of our pipeline scanner. I was unaware we had deployed the enhanced flaw details but see that is now the case. My recommendation is still to go off the Policy Scan because of the following reasons to name a few:
You may wish to suggest we support JUNIT format for the Pipeline scanner results, over in the Ideas section of the Community (https://community.veracode.com/s/ideas) where you will be able to track your suggestion as it gets considered by Veracode.
Thanks,
Anthony
Hello @MClarkson676368 (Community Member) , Thank you for the feedback. I am a Product Manager and would love to learn more about the problem you mentioned (present results for easy consumption by devs). Sending you a quick email requesting time to discuss in depth.
Deepro.