Configure Pipeline Script

We provide you with a pipeline script that you can use in the repository. 

To install the WAS Integration with Gitlab application, you need to create two configuration files:

Create docker-compose.yml

Perform the following steps:

  1. Create a new docker-compose.yml file to the root directory of your project.
  2. Paste the following .yml code into the newly created file and save it.

    docker-compose.yml

    version: "3"

    services:

    myapp:

        image: qualys/qwas_integration_cli:latest

        network_mode: "host"   

        volumes:

    - ./outputs:/home/app/outputs:rw

        environment:

    - PLATFORM=${PLATFORM:-}

    - QUALYS_USERNAME=${QUALYS_USERNAME:-}

    - QUALYS_PASSWORD=${QUALYS_PASSWORD:-}

    - WEBAPP_ID=${WEBAPP_ID:-}

    - SCAN_NAME=${SCAN_NAME:-}

    - SCAN_TYPE=${SCAN_TYPE:-}

    - AUTH_RECORD=${AUTH_RECORD:-none}

    - AUTH_RECORD_ID=${AUTH_RECORD_ID:-""}

    - OPTION_PROFILE=${OPTION_PROFILE:-useDefault}

    - OPTION_PROFILE_ID=${OPTION_PROFILE_ID:-""}

    - CANCEL_OPTION=${CANCEL_OPTION:-false}

    - CANCEL_HOURS=${CANCEL_HOURS:-0}

    - SEVERITY_CHECK=${SEVERITY_CHECK:-false}

    - SEVERITY_LEVEL=${SEVERITY_LEVEL:-0}

    - FAIL_ON_SCAN_ERROR=${FAIL_ON_SCAN_ERROR:-false}

    - WAIT_FOR_RESULT=${WAIT_FOR_RESULT:-true}

    - INTERVAL=${INTERVAL:-5}

    - EXCLUDE=${EXCLUDE:-0}

    - TIMEOUT=${TIMEOUT:-350}

    - FILE_TYPE=${FILE_TYPE:-PDF}

    - CLIENT_ID=${CLIENT_ID:-}

    - CLIENT_SECRET=${CLIENT_SECRET:-}

    - AUTH_TYPE=${AUTH_TYPE}

    - IDP_TOKEN_URL=${IDP_TOKEN_URL:-}

    - IDP_SCOPE=${IDP_SCOPE:-}

    - IDP_AUDIENCE=${IDP_AUDIENCE:-}

        ports:

    - "8080:8080"

Create .gitlab-ci.yml

You can use the Qualys template for WAS scans that are added to GitLab.

To use the template, perform the following steps:

  1. Create a new .gitlab-ci.yml file in the root directory of your project.
  2. Paste the following .yml code into the newly created file and save it.

    .gitlab-ci.yml

    stages:

    - test

    - setup

    - deploy

    - check_status

    variables:

    PLATFORM: ${PLATFORM:-}

    QUALYS_USERNAME: ${QUALYS_USERNAME:-}

    QUALYS_PASSWORD: ${QUALYS_PASSWORD:-}

    WEBAPP_ID: ${WEBAPP_ID:-}

    SCAN_NAME: ${SCAN_NAME:-}

    SCAN_TYPE: ${SCAN_TYPE:-}

    AUTH_RECORD: ${AUTH_RECORD:-none}

    AUTH_RECORD_ID: ${AUTH_RECORD_ID:-""}

    OPTION_PROFILE: ${OPTION_PROFILE:-useDefault}

    OPTION_PROFILE_ID: ${OPTION_PROFILE_ID:-""}

    CANCEL_OPTION: ${CANCEL_OPTION:-false}

    CANCEL_HOURS: ${CANCEL_HOURS:-0}

    SEVERITY_CHECK: ${SEVERITY_CHECK:-false}

    SEVERITY_LEVEL: ${SEVERITY_LEVEL:-0}

    FAIL_ON_SCAN_ERROR: ${FAIL_ON_SCAN_ERROR:-false}

    WAIT_FOR_RESULT: ${WAIT_FOR_RESULT:-true}

    INTERVAL: ${INTERVAL:-5}

    EXCLUDE: ${EXCLUDE:-0}

    TIMEOUT: ${TIMEOUT:-350}

    FILE_TYPE: ${FILE_TYPE:-PDF}

    CLIENT_ID: ${CLIENT_ID:-}

    CLIENT_SECRET: ${CLIENT_SECRET:-}

    AUTH_TYPE: ${AUTH_TYPE:-}

    IDP_TOKEN_URL: ${IDP_TOKEN_URL:-}  

    IDP_SCOPE: ${IDP_SCOPE:-}  

    IDP_AUDIENCE: ${IDP_AUDIENCE:-}

    include:

    - template: Security/SAST.gitlab-ci.yml

    setup_env:

    stage: setup

    script:

    - echo "Setting up environment..."

    - mkdir -p outputs

    - chmod -R 777 outputs

    artifacts:

        paths:

        - outputs

        expire_in: 240 hour

    only:

    - merge_requests

    - main

    deploy_app:

    stage: deploy

    image: docker:latest

    services:

    - docker:dind

    before_script:

    - apk add --no-cache docker-compose

    script:

    - echo "Starting Docker Compose..."

    - docker-compose up

    only:

    - merge_requests

    - main

    allow_failure: true

    artifacts:

        paths:

        - outputs/

        reports:

    sast: outputs/Qualys-WAS-SAST-Report.json

        expire_in: 240 hours

    sast:

    stage: test

    check_status:

    stage: check_status

    script:

        - |

    echo "Checking if outputs/exitCode.txt exists..."

    if [ -f outputs/exitCode.txt ]; then

    stored_exit_code=$(head -n 1 outputs/exitCode.txt)

    failure_reason=$(tail -n +2 outputs/exitCode.txt)

               

    echo "Stored exit code is: $stored_exit_code"

     

    if [ "$stored_exit_code" -eq 1 ]; then

              echo "Job failed. Reason:"

              echo "$failure_reason"

              exit 1

    else

              echo "Exit code is fine. Proceeding..."

              if [ -n "$failure_reason" ]; then

                echo "Additional Info:"

                echo "$failure_reason"

              fi

    fi

    else

    echo "exitCode.txt not found. Assuming success or skipping check."

    # Uncomment to enforce strict failure if file is missing

    # exit 1

    fi

     

Next step

Trigger Scan