filmov
tv
GitLab 17.2 - Expanded Support of Custom Rulesets in Pipeline Secret Detection (Remote Application)
Показать описание
In Gitlab 17.2, we have expanded support of custom rulesets in pipeline secret detection. This makes it easier to manage workflows such as sharing ruleset configurations across multiple projects.
You can use two new types of passthroughs to configure remote rulesets:
* git: Pull the configuration from a remote Git repository
* url: Fetch the configuration using HTTP
Note: You can also extend the default configuration with a remote ruleset by using one of those new types of passthroughs.
Additionally, the analyzer now supports:
* Chaining up to 20 passthroughs into a single configuration to replace predefined rules
* Including environment variables in passthroughs
* Setting a timeout when loading a passthrough
* Validating TOML syntax in ruleset configuration
OUTLINE
00:00 - Introduction
00:37 - Expanded Support of Custom Ruleset Feature Overview
01:13 - Creating a Custom Ruleset
01:40 - Applying a Custom Ruleset Remotely
02:04 - Remotely Applied Custom Ruleset in Action (Merge Request)
02:47 - Remotely Applied Custom Ruleset in Action (Vulnerability Report)
02:57 - Conclusion
USEFUL LINKS
DEMO PROJECTS:
Thanks for watching! Be sure to subscribe and follow @awkwardferny and @gitlab on twitter for similar content.
You can use two new types of passthroughs to configure remote rulesets:
* git: Pull the configuration from a remote Git repository
* url: Fetch the configuration using HTTP
Note: You can also extend the default configuration with a remote ruleset by using one of those new types of passthroughs.
Additionally, the analyzer now supports:
* Chaining up to 20 passthroughs into a single configuration to replace predefined rules
* Including environment variables in passthroughs
* Setting a timeout when loading a passthrough
* Validating TOML syntax in ruleset configuration
OUTLINE
00:00 - Introduction
00:37 - Expanded Support of Custom Ruleset Feature Overview
01:13 - Creating a Custom Ruleset
01:40 - Applying a Custom Ruleset Remotely
02:04 - Remotely Applied Custom Ruleset in Action (Merge Request)
02:47 - Remotely Applied Custom Ruleset in Action (Vulnerability Report)
02:57 - Conclusion
USEFUL LINKS
DEMO PROJECTS:
Thanks for watching! Be sure to subscribe and follow @awkwardferny and @gitlab on twitter for similar content.