如何在GitLab同流水线后续步骤获取gl-sast-report.json工件?
解决GitLab流水线后续步骤无法获取
gl-sast-report.json工件的问题 问题根源
GitLab的reports:sast字段是用于将报告提交到安全仪表盘的专用工件类型,这类工件不会自动作为普通工件传递给后续流水线步骤。因此即使你在parse-sast-report中配置了dependencies,也无法直接访问到gl-sast-report.json。
解决方案
需要修改nodejs-scan-sast的工件配置,将gl-sast-report.json同时声明为普通工件(通过paths字段),这样后续步骤就能通过依赖关系获取到该文件。
修改后的完整配置
# GitLab Stuff stages: - ".pre" - test - build - ".post" nodejs-scan-sast: stage: test artifacts: reports: sast: - gl-sast-report.json # 添加以下paths配置,将报告作为普通工件上传 paths: - gl-sast-report.json # 可选:设置工件过期时间,避免占用存储空间 expire_in: 1 week rules: - if: "$SAST_DISABLED == 'true' || $SAST_DISABLED == '1'" when: never - if: "$SAST_EXCLUDED_ANALYZERS =~ /nodejs-scan/" when: never - if: "$CI_COMMIT_BRANCH" exists: - "**/package.json" variables: SEARCH_MAX_DEPTH: 4 SAST_ANALYZER_IMAGE_TAG: 4 SAST_ANALYZER_IMAGE: "$SECURE_ANALYZERS_PREFIX/nodejs-scan:$SAST_ANALYZER_IMAGE_TAG" script: - "/analyzer run" extends: ".sast-analyzer" allow_failure: true image: name: "$SAST_ANALYZER_IMAGE" # My Stuff parse-sast-report: image: pcfens/sast-parser stage: build dependencies: - nodejs-scan-sast # 可选:如果nodejs-scan-sast允许失败,可添加以下配置确保即使前序任务失败也能执行(若失败时有工件生成) # needs: # - job: nodejs-scan-sast # allow_failure: true script: - pwd - ls -lAh . - python /app/parse-sast.py gl-sast-report.json artifacts: paths: - sast_report.html
关键改动说明
- 在
nodejs-scan-sast的artifacts中新增paths: [gl-sast-report.json],将报告文件标记为普通工件,允许后续步骤通过依赖拉取。 - 可选添加
expire_in字段,设置工件自动过期时间,优化存储空间使用。 - 如果
nodejs-scan-sast设置了allow_failure: true,且需要在该任务失败时仍执行parse-sast-report,可以将dependencies替换为needs并配置allow_failure: true,确保失败时也能拉取到生成的工件(如果有的话)。
内容的提问来源于stack exchange,提问作者Nick
相关产品推荐
相关产品推荐

