Filters

Search Results ()

Search Results ()

    All Plugins (150)

    Quick Info

    Product
    HCL Accelerate
    Type
    plugin
    Compatibility
    HCL Accelerate version 2.4 or later
    Created by
    HCL Software
    Website
    Published Date
    April 29th, 2022
    Last Updated
    April 29th, 2022

    Description

    • The Snyk plugin scans Github , GitLab or Bitbucket repositories and pulls security alerts into HCL Accelerate. This vulnerability information is available as various metrics and charts in the metrics bar and dashboard. In addition, you can leverage these values in your pipeline for automated gates and deployments.
    • The Snyk Plugin works with existing GitHub plugin , GitLab plugin and Bitbucket plugin to scan and link against known repositories. Its recommend to install and configure the existing GitHub , GitLab or Bitbucket Plugin before you install the Snyk plugin.
    • Snyk scan should be performed on the repositories and should have separate projects. Automated pull requests generated by Snyk will be also visible in the Value Stream .

    Quick Info

    Product
    HCL Accelerate
    Type
    plugin
    Compatibility
    HCL Accelerate version 2.4 or later
    Created by
    HCL Software
    Website
    Published Date
    April 29th, 2022
    Last Updated
    April 29th, 2022

    Summary

    The Snyk plugin imports repository vulnerability data from Snyk server into HCL Accelerate. It scans for existing GitHub , Gitlab or Bitbucket integrations and retrieves data only for those particular repositories . The Plugin works on organisational level and imports data for entire organisation . It can import data from multiple organisations .

    Compatibility

    This plugin is compatible with HCL Accelerate version 2.4 or later. The plugin works on top of GitHub , Gitlab or Bitbucket Plugin so at least one integration should be already there .

    History

    The following table describes the changes made in each plugin version.

    Plugin history details
    Version Description
    1.0.1 Initial release.

    Usage

    To use the Snyk plugin, the plugin must be loaded only if you an existing GitHub / GitLab / Bitbucket integration . The Snyk data is imported only if Snyk scan is performed on the repositories .

    Integration type

    The Snyk plugin supports scheduled event integration which are listed in the following table.

    Scheduled events
    Name Description
    SyncSnykDataEvent
    Queries the Snyk data for the organisation.

    Integration

    The method to integrate the plugin:

    • Using the user interface

    The tables in the Configuration properties topic describe the properties used to define the integration.

    Using the user interface

    1. From the Plugins page, click Settings > Integrations > Plugins.
    2. Under the Action column for the plugin, click Add Integration.
    3. On the Add Integration page enter values for the fields used to configure the integration and define communication.
    4. Click Save.

    Configuration Properties

    The following tables describe the properties used to configure the integration.

    • The General Configuration Properties table describes configuration properties used by all plugin integrations.
    • The Snyk Plugin Configuration Properties table describes the Snyk configuration properties that define the connection and communications with the Snyk server.

    Some properties might not be displayed in the user interface, to see all properties enable the Show Hidden Properties field.

    General Configuration properties
    Name Description Required Property Name
    Integration Name An assigned name to the value stream. Yes name
    Logging Level The level of Log4j messages to display in the log file. Valid values are: all, debug, info, warn, error, fatal, off, and trace. No loggingLevel
    HCL Accelerate User Access Key An auto-generated user access key provides credentials for communicating with the HCL Accelerate server. Yes NA

    Snyk Plugin Properties
    Name Type Description Required
    Personal Access Token String The token to use to authenticate with the Snyk server. Yes
    Organisation IDs
    String At least one Snyk organisation ID should be provided . For adding multiple IDs , separate IDs by a line . Yes
    Project Names
    String Add Snyk project names to run plugin for specific projects (line separated) . By default it will get data for all projects in the organisation . No