From b7851d84afd0876af62d99afe6f8360daa25cbe8 Mon Sep 17 00:00:00 2001 From: ondrejrozsypal Date: Mon, 6 Jan 2020 12:36:45 +0100 Subject: [PATCH 1/3] add ws config --- wss-unified-agent.config | 45 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) create mode 100644 wss-unified-agent.config diff --git a/wss-unified-agent.config b/wss-unified-agent.config new file mode 100644 index 0000000..d467ff6 --- /dev/null +++ b/wss-unified-agent.config @@ -0,0 +1,45 @@ +############################################################### +# WhiteSource Unified-Agent configuration file +############################################################### +# GENERAL SCAN MODE: Files and Package Managers +############################################################### +# Organization vitals +###################### + +projectToken=b1ff0bfa17a3414ba02e04689ccb8231098e1d03c58d4feba271bc19638065d2 + +# Change the below URL to your WhiteSource server. +# Use the 'WhiteSource Server URL' which can be retrieved +# from your 'Profile' page on the 'Server URLs' panel. +# Then, add the '/agent' path to it. +wss.url=https://app.whitesourcesoftware.com/agent + +############ +# Policies # +############ +checkPolicies=true +forceCheckAllDependencies=false +forceUpdate=false +forceUpdate.failBuildOnPolicyViolation=false +#updateInventory=false + +########### +# General # +########### +#log.level=debug + +######################################## +# Package Manager Dependency resolvers # +######################################## + + +########################################################################################### +# Includes/Excludes Glob patterns - Please use only one exclude line and one include line # +########################################################################################### +includes=**/*.zip **/*.tar.gz **/*.egg **/*.whl **/*.py + +#Exclude file extensions or specific directories by adding **/*. or **//** +excludes=**/*sources.jar **/*javadoc.jar + +case.sensitive.glob=false +followSymbolicLinks=true From 32d2d9661592cc4d8306b04f53ccac0a96a765ec Mon Sep 17 00:00:00 2001 From: ondrejrozsypal Date: Mon, 6 Jan 2020 12:48:56 +0100 Subject: [PATCH 2/3] add cci config --- .circleci/config.yml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 .circleci/config.yml diff --git a/.circleci/config.yml b/.circleci/config.yml new file mode 100644 index 0000000..bd7c0bd --- /dev/null +++ b/.circleci/config.yml @@ -0,0 +1,42 @@ +version: 2.1 + +executors: + java: + description: "A regular executor based on openjdk image" + docker: + - image: circleci/openjdk:8-jdk + +jobs: + whitesource-scan: + executor: java + + steps: + - checkout + + - run: + name: Install pip + command: | + sudo apt-get update + sudo apt-get install -y python-pip + - run: + name: Download latest WhiteSource Unified Agent + command: curl -LJO https://github.com/whitesource/unified-agent-distribution/releases/latest/download/wss-unified-agent.jar + - run: + name: Run WhiteSource scan + command: java -jar wss-unified-agent.jar -d ~/project -c ~/project/wss-unified-agent.config -apiKey ${API_KEY} + - store_artifacts: + path: ~/project/whitesource + +workflows: + version: 2 + security-scan: + # triggers: + # - schedule: + # cron: "0 1 * * 0" + # filters: + # branches: + # only: + # master + jobs: + - whitesource-scan: + context: whitesource From b14397ef5c159722fe396310b36913c4bbe6cc2b Mon Sep 17 00:00:00 2001 From: ondrejrozsypal Date: Mon, 6 Jan 2020 15:18:25 +0100 Subject: [PATCH 3/3] test update cci --- .circleci/config.yml | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/.circleci/config.yml b/.circleci/config.yml index bd7c0bd..d20caa5 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -29,14 +29,18 @@ jobs: workflows: version: 2 + commit: + jobs: + - whitesource-scan: + context: whitesource security-scan: - # triggers: - # - schedule: - # cron: "0 1 * * 0" - # filters: - # branches: - # only: - # master + triggers: + - schedule: + cron: "0 1 * * 0" + filters: + branches: + only: + master jobs: - whitesource-scan: context: whitesource