Is it possible to integrate Checkmarx Static Application Security Testing (SAST) tool into Gitlab Continuous Integration (CI) Pipeline for static security scanning?
I have been using Checkmarx with TeamCity and Jenkins pipeline with their Plugin. However, for GitLab pipeline, we need to use REST APIs/ CLI. I would prefer using CLI over REST APIs as CLI provides more functionality that can be used for pipeline decisions.
You can check their Wiki- https://checkmarx.atlassian.net/wiki/spaces/KC/pages/5767170/CxSAST+API+Guide https://checkmarx.atlassian.net/wiki/spaces/KC/pages/52560015/CxConsole+CxSAST+CLI
You can always raise a support ticket for getting the recommended approach by Checkmarx.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With