Artifact scans with Wiz
Scan artifacts with Wiz. Orchestration and Ingestion modes supported.
You can easily set up a Wiz step to run automated scans in a Harness pipeline. This step scans the container image you specify using the Wiz CLI. Then it correlates, deduplicates, and ingests the scan results into STO. You can see your scan results in the Vulnerabilities tab of the pipeline execution.
Important notes for running Wiz scans in STO
You can set up your STO scan images and pipelines to run scans as non-root and establish trust for your proxies using custom certificates. For more information, go to Configure your pipeline to use STO images from private registry.
If you use Wiz for Gov or GovCloud on Linux/macOS, configure
WIZ_ENVenvironment variable in your wiz stage settings.For
app.wiz.us(Wiz for Gov, FedRAMP), setWIZ_ENV=fedramp.For
gov.wiz.io(GovCloud), setWIZ_ENV=gov.
Set-up workflows
Wiz step settings reference
The recommended workflow is to add a Wiz step to a Security Tests or CI Build stage and then configure it as described below.
Scan
Scan Mode
Target
Type
Target and Variant Detection
Name
The identifier for the target such jsmith/myalphaservice. Descriptive target names make it much easier to navigate your scan data in the STO UI.
It is good practice to specify a baseline for every target.
Variant
Workspace
Container image
Type
Domain
Name
Tag/Digest
Access ID
Access Token
Ingestion File
The path to your scan results when running an Ingestion scan, for example /shared/scan_results/wiz.latest.json.
The data file must be in a supported format for the scanner.
The data file must be accessible to the scan step. It's good practice to save your results files to a shared path in your stage. In the visual editor, go to the stage where you're running the scan. Then go to Overview > Shared Paths. You can also add the path to the YAML stage definition like this:
Authentication
Access ID
This is your client-id to authenticate with the Wiz CLI.
Access Token
This is your client-secret to authenticate with the Wiz CLI.
You should create a Harness text secret with your encrypted token and reference the secret using the format <+secrets.getValue("my-access-token")>. For more information, go to Add and Reference Text Secrets.
Log Level
Additional CLI flags
Passing CLI flags is an advanced feature. Some flags might not work in the context of STO. You should test your flags and arguments thoroughly before you use them in your production environment.
Fail on Severity
Settings
You can add more settings to the scan step as needed.
Additional Configuration
Advanced settings
View Wiz policy failures
Proxy settings
Last updated
Was this helpful?