如何在GitLab中自动可视化Gitleaks JSON扫描结果?
GitLab CI/CD中Gitleaks密钥扫描结果可视化问题
当前配置与问题
我在.gitlab-ci.yml中使用Gitleaks执行密钥扫描,扫描生成JSON格式的gl-secret-detection-report.json文件,流水线配置如下:
gitleaks: stage: security image: name: zricethezav/gitleaks entrypoint: [""] script: - gitleaks detect --verbose --report-format=json --report-path=gl-secret-detection-report.json artifacts: reports: secret_detection: gl-secret-detection-report.json paths: - gl-secret-detection-report.json
任务运行正常,文件已作为工件存储,但JSON报告在GitLab中无法以用户友好的可视化方式展示。
需求
- 实现GitLab内自动可视化Gitleaks的JSON输出,比如通过安全标签、合并请求组件或自定义HTML视图
- 无需每次手动下载并打开JSON文件
- 可利用GitLab的自定义报告、仪表板或HTML工件等功能
疑问
若需要将Gitleaks输出转换为GitLab预期的密钥检测schema,是否有现成工具或脚本?
已尝试操作
我曾尝试在.gitlab-ci.yml中添加以下内容,启用GitLab SAST和密钥检测模板:
include: - template: Security/SAST.gitlab-ci.yml - template: Security/Secret-Detection.gitlab-ci.yml
内容的提问来源于stack exchange,提问作者Der Mimox
相关产品推荐
相关产品推荐

