Tenable step configuration
Scan application instances with Tenable.
You can scan your container images and application instances using Tenable and then ingest the results from Harness.
Workflow descriptions
Custom Scan step settings for Tenable scans in STO
The recommended workflow is to add a Custom Scan step to a Security or Build stage and then configure it as described below.
Scanner settings
These settings are all required.
Product name
Key
Value
Scan type
The target type to scan.
Key
Value
Must be one of the following.
Policy type
The scan mode to use.
Key
Value
Product config name
Key
Value
Use the legacy Nessus scan inside tenableIO:
Target and variant
Instance
Product access
These settings are available to access your Tenable instance when policy_type is orchestratedScan.
You should create Harness text secrets for your encrypted passwords/tokens and reference them using the format <+secrets.getValue("my-access-token")>.
Product access keys
Ingestion file
Fail on Severity
Proxy settings
Last updated
Was this helpful?