STO Integration for Sonar, Veracode Windows Pipeline
long-term
L
Lavender Armadillo
We have done STO Sonar integration for our dotnet services and it has been working fine.
We are trying to do the same for our windows services, but I'm getting the below error in the Initialize step,
'Back-off pulling image "gcr.io/gcr-prod/harness/sto-plugin:latest"'
As suggested in the ticket (https://support.harness.io/hc/en-us/requests/63663), I'm applying Ingestion method for the Sonar and Veracode STO evaluations.
Later, we came to know that STO ingestion with Windows OS is only supported when you run the build on Harness cloud. But we are running on our own k8s cluster.
Hence I'm submitting this feature request to get the STO support for windows.
Regards,
Janish
Log In
Pritesh Chandaliya
We added support for CheckmarxOne - https://developer.harness.io/docs/security-testing-orchestration/sto-techref-category/checkmarx/checkmarxone-scanner-reference/
Just wanted to inform as it was brought up in the thread. Thanks!
Btw is this still a requirement to support ingestion mode for windows on a non harness hosted infra or you are unblocked on it already?
L
Late Toucan
Pritesh Chandaliya thanks . Do we have Sonarqube , gitleaks , SBOM and wiz support in windows Windows AMD 64 harness cloud ?
Pritesh Chandaliya
After confirming with the customer, the request is to support all the scanners and SBOM for orchestration mode.
L
Late Toucan
Pritesh Chandaliya  CheckmarxOne , SonarQube , GitLeaks and SBOM needs support in Windows AMD64 Harness Cloud . Wiz is also needed
Pritesh Chandaliya
long-term
Pritesh Chandaliya
pending feedback
Lavender Armadillo did you try the ingestion mode for SonarQube , GitLeaks already?
Pritesh Chandaliya
complete
Please let us know if any questions
Pritesh Chandaliya
Lavender Armadillo we do support for SonarQube , GitLeaks. Today cxone is not supported in any of the infra, we are working on it this quarter. Let me know if you face any issue. 
Regarding SBOM Pranay Shah can help more.
L
Late Toucan
Pritesh Chandaliya CheckmarxOne , SonarQube , GitLeaks and SBOM needs support in Windows AMD64 Harness Cloud - any idea when this support will be provided ?
Autopilot
Merged in a post:
CheckmarxOne , SonarQube , GitLeaks and SBOM needs support in Windows AMD64 Harness Cloud
L
Late Toucan
CheckmarxOne , SonarQube , GitLeaks and SBOM needed support in Harness Cloud Windows AMD 64 . These STO's currently have support only in Linux architecture and they dont work in Windows . Need these STO's to support Windows Architecture in Harness Cloud .
Pritesh Chandaliya
There is no plans on our side to support Windows 2019, can you please provide info on whether have you decided to upgrade the windows server?
If not, then we need to prioritize this efforts, which is a big task for us as we do not have infra on our side to test out 2019 windows server to start with. Please keep us informed to take necessary steps on unblocking you. Lavender Armadillo
Pritesh Chandaliya
Lavender Armadillo can you please provide us the version of windows?
Windows 2019 is supposed to be end of support already and there is extended support for few more years. Refer to their post here: https://answers.microsoft.com/en-us/windowserver/forum/all/server-2019-support/7d0297fa-a0ab-46ce-8874-8d2c91d61762
Can you please provide answers:
- Are you planning to ever upgrade their infra to windows latest version?
- What does your timeline looks like for upgrade (1 year, 2 year or more)?
- Is this an adoption blocker for the customer? Do you have any workaround for it today?
Load More
→
