Fossa step configuration
Scan code repositories with Fossa.
You can ingest scan results from Fossa. For a description of the high-level workflow, go to Run an ingestion scan in an STO Pipeline.
Fossa step settings for STO scans
The recommended workflow is to add a Fossa step to a Security Tests or CI Build stage and then configure it as described below.
Scan
Scan Mode
Scan Configuration
Target
Type
Target and Variant Detection
Name
Variant
Workspace (repository)
Ingestion File
The Fossa JSON results file to ingest.
Log Level
Fail on Severity
Additional Configuration
Advanced settings
Proxy settings
YAML pipeline example
This pipeline pulls a Fossa JSON data file from a GitHub repo and then ingests it.
Last updated
Was this helpful?