Filters

CLEAR ALL

Search Results ()

Filter Icon

Search Results ()

    All Plugins (172)

    Filter Icon

    Quick Info

    Product icon
    Product
    DevOps Deploy (HCL Launch)
    Plugin type icon
    Type
    plugin
    Compatibility icon
    Compatibility
    HCL Launch version 7.0 or later
    created by icon
    Created by
    HCL Software
    Website icon
    Website
    Published Date
    March 2nd, 2023
    Last Updated
    May 11th, 2023

    Description

    HCL AppScan on Cloud (ASoC) is an application security offering that allows you to scan on prem, web, and mobile applications for security vulnerabilities. The plugin allows you to run all supported types of scans and manage ASoC presences. Presences allow you to run scans on apps that are not connected to the internet or require a proxy server to make a connection.

    Quick Info

    Product icon
    Product
    DevOps Deploy (HCL Launch)
    Plugin type icon
    Type
    plugin
    Compatibility icon
    Compatibility
    HCL Launch version 7.0 or later
    created by icon
    Created by
    HCL Software
    Website icon
    Website
    Published Date
    March 2nd, 2023
    Last Updated
    May 11th, 2023

    launch-asoc--14.1152459.zip

    Uploaded: 02-Mar-2023 07:05

    Release Notes

      Fixed a json parser related issue.
      Base appscan url property added for all steps.

    Summary

    HCL Launch can process the output of the ASoC plugin and treat the build accordingly.

    If your build was deployed successfully to a lower-level environment but failed the Dynamic ASoC scan with high severity issues, HCL Launch will automatically rollback to the last deployed version and mark the build with a status indicating there are problems. If ASoC identifies lesser severity issues in your build, HCL Launch with slap a deployment warning onto it but leave it installe don the target machines. And if ASoC spots no major issues, HCL Launch will give that version an app status that signifies it’s passed all AppScan scans. In other words, HCL Launch creates environment gates that can prevent deployments to Prod or other high-level environments if it doesnot pass AppScan approval.

    Installation

    See Installing plugins in HCL Launch for installing and removing plugins.

    History

    The following table describes the changes made in each plugin version.

    Plugin history details
    Version Description
    14
    • Fixed a json parser related issue.
    • Base appscan url property added for all stepsLog4j and Jettison dependency updated.
    13
    • Plugin renamed to HCL AppScan on Cloud.
    • Preemptively renew login token after one hour when waiting for Scan completion. ASoC default token timeout is two hours.
    • Added new Scan Name property to the Start Dynamic Analyzer ASoC Scan step.
    12 Updated to the new ASoC domain cloud.appscan.com.
    11 Set high, medium, low, informational issue count output properties on dynamic scan.
    10
    • Complete rewrite of former plugin to fix broken scan steps.
    • Added Application ID property to scan steps.
    • Changed authentication to API tokens as opposed to HCL IDs.
    • Added support for scan templates for DAST/MAST scans.
    • Added steps for creating, deleting, starting, and stopping presences.
    • Added support for running scans on private applications using presences.
    • Added third credential for DAST/MAST scans.
    • Added support for Staging and Production DAST scans.
    9 Remove old deprecated projectLocation and workspaceScheme fields from Start iOS Scan step (ipaFileLocation already replaced them).
    8 Add testPolicy to Start Dynamic Analyzer ASoC Scan step. Migrate the Start iOS Analyzer ASoC Scan from working with IPAX generator, to working with ipa file.
    7 Add step Start iOS Analyzer ASoC Scan.
    6 Rename the step “Start Mobile Analyzer Scan” into Start Android Mobile Analyzer ASoC Scan.
    5 Rename plugin from Application Security Testing (Smartcloud Exchange) to IBM Application Security on Cloud and add support for running a DAST(Domain Verification not supported) and SAST scans.
    4 Upgrade to http-builder-0.7.2-uc.jar, and change our portal domain from appscan.bluemix.net to appscan.ibmcloud.com
    3 Changing our portal domain from appscan.ibmcloud.com to appscan.bluemix.net (and adding hidden experimental feature PSS).
    2 Migrate internal logic to work with cloud V2 APIs.
    1 Initial release of the plug-in.

     

    Steps

    HCL Launch AppScan Enterprise – Process Steps

    HCL Launch has a free installable plugin for AppScan on Cloud. This plug-in includes steps to do each of the following on the AppScan server:

    • Create ASoC Presence
    • Delete ASoC Presence
    • Start ASoC Presence
    • Start Android Mobile Analyzer ASoC Scan
    • Start Dynamic Analyzer ASoC Scan
    • Start Static Analyzer ASoC Scan
    • Start iOS Analyzer ASoC Scan
    • Stop ASoC Presence

    Each HCL Launch plugin step must be configured with the ASoC Application ID, Key ID, and Key Secret.

    The static analyzer step also requires an IRX file, which points to either the IRX file to be uploaded for scanning, or the directory that contains the files or other locations to scan. The field accepts scan configuration files, eclipse workspaces, as well as .jar, .war, and .ear file types. In addition to the Application ID, Key ID, and Key Secret, the dynamic analyzer step requires the URL for the location to scan. If the page requires a login, the application login credentials must also be provided.