As an alternative to the Black Duck Security Scan Template, the Bridge CLI can be downloaded and directly executed in a GitLab pipeline. It has all the functionality of the template, but you must add a step to download the Bridge CLI from blackduck-repo.
To find out more about the Black Duck Security Scan Template and what it can do, take a look at the overview page.
Prerequisites
-
In addition to a GitLab repo, you need Polaris access before you start this workflow.
-
If the application doesn't already exist in Polaris, Bridge will try and create it before triggering a CI scan. If you have concurrent subscription / team member enabled, the application creation will be successful. If you have parallel subscription, application creation will fail. To create it manually consult create the relevant applications in Polaris.
-
We recommend the following reading before you start:
- The Black Duck Security Scan Template prerequisites page
- Polaris prerequisites
- Fix pull requests (Fix PRs)
- Using SCA Fix PRs with Bridge
- Reference: using the Black Duck Security Scan Template with Polaris
- Additional GitLab Parameters