Add cache steps to security stages
long-term
Pritesh Chandaliya
updated the status to
long-term
P
Psychological Firefly
yes, correct. the caching for s3/gcs would be great. ideally also cache intelligence, but I understand that is a feature from another module that may not be easy to integrate
Pritesh Chandaliya
Is the ask is to add these cache steps in the "Security" Stage of the Harness pipeline? Psychological Firefly
Photo Viewer
View photos in a modal
P
Psychological Firefly
I'm looking for caching of the application dependencies in the case of running an SCA scan using ingest mode. In this case, scanners like Snyk and XRay will use maven/gradle/pip etc to pull all the app's dependencies to the pod before initiating a scan. If we can cache these dependencies, it would greatly speed up SCA scans of this nature.
Pritesh Chandaliya
updated the status to
pending feedback
Pritesh Chandaliya
updated the status to
under review
I am not sure why would the cache be helpful for STO steps?
STO if using orchestration, extraction mode, it runs the scan on the scanner side - that means caching on scanner side is useful here.
In case of Ingestion mode, caching is not required because the final report (vulnerability report grabbed from the scanner) is provided directly.
Am I understanding incorrectly or if there is some info missing, can you please provide more context. Thanks!