As an alternative to the Black Duck Security Scan Template, the Bridge CLI can be downloaded and directly executed in a GitLab pipeline. It has all the functionality of the template, but you must add a step to download the Bridge CLI from blackduck-repo.
To find out more about the Black Duck Security Scan Template and what it can do, take a look at the overview page.
Prerequisites
In addition to a GitLab repo, you need Polaris access before you start this workflow.
If the application doesn't already exist in Polaris, Bridge will try and create it before triggering a CI scan. If you have concurrent subscription / team member enabled, the application creation will be successful. If you have parallel subscription, application creation will fail. To create it manually consult create the relevant applications in Polaris.
We recommend the following reading before you start:
- The Black Duck Security Scan Template prerequisites page
- Polaris prerequisites
- Fix pull requests (Fix PRs)
- Using SCA Fix PRs with Bridge
- Reference: using the Black Duck Security Scan Template with Polaris
- Additional GitLab Parameters