Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

additional bd flags rapid #37

Open
ukv001 opened this issue Oct 10, 2022 · 0 comments
Open

additional bd flags rapid #37

ukv001 opened this issue Oct 10, 2022 · 0 comments

Comments

@ukv001
Copy link

ukv001 commented Oct 10, 2022

Hej synopsys Action people,

I have been using this detect action for quite a bit for intelligent scans, and now I am looking to really start using rapid scans.
We have a few severities we have mitigated in our project as per the BDSA, but it still gives CVE errors.
So in the projects we simply set these CVE's to mitigated, but with the current implementation of RAPID scan mode, ALL is selected by default by the bd scanner it self.
So I would like to add
--detect.blackduck.rapid.compare.mode=BOM_COMPARE_STRICT
--detect.project.name=NodeGoat
--detect.project.version.name=main-dev
as per the https://community.synopsys.com/s/article/Black-Duck-Rapid-Scan documentation.

There are now 3 options I could fork the project and make the changes my self, I could get access to commit including creating a new branch here, or you could make the changes to add these extra bd parameters.
I would personally prefer not to fork, as that is not really sharing with the world.
Or I could simply use the cli in my own actions.

Brgds

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant