Add SBOM generation into Checkmarx step
G
Ginger Aardvark
We are able to run Checkmarx scan in the pipeline using Harness built-in Checkmarx step. The security findings are ingested properly, but the Checkmarx SBOM is not automatically ingested. I've tried to solve this in the follow ways:
I looked for a checkbox in the Checkmarx step to include SBOM, but it does not seem to have one. I think other scanners may have this, but not the Checkmarx step. This would be ideal solution, can Harness add it?
I tried to configure Checkmarx CLI arguments so that it would write the SBOM on disk and in a subsequent step I could ingest it. But this does not work because Harness Checkmarx step assumes report-format is JSON, not SBOM and in a specific location. Checkmarx CLI does not seem to allow multiple output formats.
I considered whether or not we can make a subsequent request to Checkmarx API to download SBOM, but Harness Checkmarx step does not make scan ID available in output.
I'm not yet able to find a way to do this without dropping the Harness Checkmarx step directly and instead writing custom code.”
We leverage checkmarks as our primary security testing tool. This tool has the ability to generate an S-bomb, and we would like to do so using the tool that we have. We will then inject the S-bomb in a later SCS step, but it seems that Harness does not allow generating the S-bomb in the built-in checkmark step
We would also like Harness to output the scan ID in the checkmark step so that we can potentially download the SBOM from the checkmarks tool for later ingestion in an SCS step