To scan using Veracode Software Composition Analysis
agent-based scanning, add the following to the
after_script step in your
after_script: - curl -sSL https://download.sourceclear.com/ci.sh | sh
- Commit the change to start a build for your repository.
Veracode SCA performs an agent-based scan, displaying results to your agent-based scanning environment.
If you want to add Veracode SCA agent-based scanning scanning to other repositories, add the installation and scan code above to any .gitlab-ci.yml files you want to scan, as well as the SRCCLR_API_TOKEN environment variable and you can perform scans on each new build.