Add a security scan job のフィールドリファレンスです。
Trivy scan フィールド
| Field | 意味 |
|---|
| Job name | scan job の名前。 |
| Apply Security Gate When Vulnerabilities Are Detected At | Critical、High、Medium、Low のいずれか 1 つ以上の深刻度。 |
| When Security Gate Fails | Fail pipeline、または Continue with warning。 |
SonarQube scan フィールド
| Field | 意味 |
|---|
| Job name | scan job の名前。 |
| SonarQube Connection | Manage credentials で作成済みの接続を選択するか、新規に追加します。 |
| Project key | SonarQube 上でのプロジェクトの一意な識別子。例: fpt-cloud:web-portal。 |
| Quality Gate | 有効にすると、webhook 経由で Pipeline が SonarQube の Quality Gate と結果を照合します。 |
See also