<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shiftleft CICD Integration in DevSecOps</title>
    <link>https://community.checkpoint.com/t5/DevSecOps/Shiftleft-CICD-Integration/m-p/215751#M133</link>
    <description>&lt;P&gt;Can shiftleft be used for on premise security or just cloud?&amp;nbsp; We are using Kubernetes &amp;amp; podman on premise.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2024 16:31:39 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2024-05-30T16:31:39Z</dc:date>
    <item>
      <title>Shiftleft CICD Integration</title>
      <link>https://community.checkpoint.com/t5/DevSecOps/Shiftleft-CICD-Integration/m-p/111841#M51</link>
      <description>&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6235297645001w480h270r441" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6235297645001" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6235297645001w480h270r441');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/6235297645001"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;In this post, we are going to show how to integrate Shiflett into a modern CI/CD orchestrator like &lt;A href="https://about.gitlab.com/" target="_blank" rel="noopener"&gt;Gitlab&lt;/A&gt;. We will take the perspective of an application developer that integrates Shiftleft blades into the CI/CD pipeline and how leverages Shiftleft information to start solving vulnerabilities detected in the code, container image that the pipeline build as well as an infrastructure project that uses Terraform.&lt;/P&gt;
&lt;P&gt;The following is a short description of Shiftleft modules also known as blades:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;code-scan&lt;/STRONG&gt;: Using as input a directory that contains a Git repository, Shiftleft will scan it for vulnerabilities, weak coding practices, sensitive content, and malicious files among other categories&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;image-scan&lt;/STRONG&gt;: Using as input a&amp;nbsp; container image, compressed into a file, this blade will apply all the capabilities already provided by code-scan and will add on top of that the scanning of OS-level packages included in the container image.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;iac-assessment&lt;/STRONG&gt;: In combination with CloudGuard, Infrastructure as code assessment allows users to apply policies to their Terraform projects. The mechanism to define those rules is by making use of &lt;A href="https://sc1.checkpoint.com/documents/CloudGuard_Dome9/Documentation/PostureManagement/GSL.html" target="_blank" rel="noopener"&gt;CloudGuard Governance Specification Language&lt;/A&gt; (GSL). A high-level, human-friendly language.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 25 Feb 2021 17:20:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/DevSecOps/Shiftleft-CICD-Integration/m-p/111841#M51</guid>
      <dc:creator>ivanmar</dc:creator>
      <dc:date>2021-02-25T17:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Shiftleft CICD Integration</title>
      <link>https://community.checkpoint.com/t5/DevSecOps/Shiftleft-CICD-Integration/m-p/215751#M133</link>
      <description>&lt;P&gt;Can shiftleft be used for on premise security or just cloud?&amp;nbsp; We are using Kubernetes &amp;amp; podman on premise.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 16:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/DevSecOps/Shiftleft-CICD-Integration/m-p/215751#M133</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2024-05-30T16:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Shiftleft CICD Integration</title>
      <link>https://community.checkpoint.com/t5/DevSecOps/Shiftleft-CICD-Integration/m-p/216501#M134</link>
      <description>&lt;P&gt;Yes if you're running a locally hosted solution like Gitlab or Jenkins it can work there too - you just need to authenticate it against your CloudGuard solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 11:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/DevSecOps/Shiftleft-CICD-Integration/m-p/216501#M134</guid>
      <dc:creator>StuartGreen</dc:creator>
      <dc:date>2024-06-05T11:55:40Z</dc:date>
    </item>
  </channel>
</rss>

