Skip to content

Commit

Permalink
Merge pull request #482 from pulibrary/add_bearer_to_ci
Browse files Browse the repository at this point in the history
Add bearer to CI
  • Loading branch information
christinach authored Sep 18, 2024
2 parents 444bffc + 8bf1ee0 commit 81ee68a
Show file tree
Hide file tree
Showing 2 changed files with 45 additions and 0 deletions.
12 changes: 12 additions & 0 deletions .circleci/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,17 @@ jobs:
- run:
name: Run Rspec
command: bundle exec rspec
bearer:
docker:
- image: cimg/ruby:3.2
environment:
# Set to default branch of your repo
DEFAULT_BRANCH: main
steps:
- checkout
- run: curl -sfL https://raw.githubusercontent.com/Bearer/bearer/main/contrib/install.sh | sh -s -- -b /tmp
- run: CURRENT_BRANCH=$CIRCLE_BRANCH SHA=$CIRCLE_SHA1 /tmp/bearer scan .

workflows:
version: 2
build_accept_deploy:
Expand All @@ -82,3 +93,4 @@ workflows:
matrix:
parameters:
ruby-version: ["3.1.3"]
- bearer
33 changes: 33 additions & 0 deletions bearer.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
disable-version-check: false
log-level: info
report:
fail-on-severity: critical,high,medium,low
format: ""
no-color: false
output: ""
report: security
severity: critical,high,medium,low,warning
rule:
disable-default-rules: false
only-rule: []
# Tickets to remediate these rules and remove from this stanza:
# ruby_rails_open_redirect - https://github.com/pulibrary/DSS/issues/479
# ruby_rails_password_length - https://github.com/pulibrary/DSS/issues/480
# ruby_rails_default_encryption - https://github.com/pulibrary/DSS/issues/481
skip-rule: [ruby_rails_open_redirect, ruby_rails_password_length, ruby_rails_default_encryption]
scan:
context: ""
data_subject_mapping: ""
disable-domain-resolution: true
domain-resolution-timeout: 3s
exit-code: -1
external-rule-dir: []
force: false
hide_progress_bar: false
internal-domains: []
parallel: 0
quiet: false
scanner:
- sast
skip-path: []
skip-test: true

0 comments on commit 81ee68a

Please sign in to comment.