Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions gsast-core/gsast_core/configs/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@
SERVER_CHECK_PROJECT_STATUS_INTERVAL,
SERVER_JOB_TIMEOUT,
SERVER_JOB_RESULT_TTL,
REDIS_SCAN_RESULTS_TTL,
REDIS_CACHE_DB,
REDIS_TASKS_DB,
REDIS_RULES_DB,
Expand Down
2 changes: 2 additions & 0 deletions gsast-core/gsast_core/configs/defaults.py
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,8 @@
SERVER_JOB_TIMEOUT: str = '15m' # minutes
SERVER_JOB_RESULT_TTL: int = 3 * 60 * 60 * 24 # seconds

REDIS_SCAN_RESULTS_TTL: int = 7 * 24 * 60 * 60 # 7 days in seconds

REDIS_CACHE_DB: int = 0
REDIS_TASKS_DB: int = 1
REDIS_RULES_DB: int = 2
Expand Down
3 changes: 3 additions & 0 deletions gsast-core/gsast_core/sastlib/results_storage.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
from typing import Dict, Optional, Any, List
from pathlib import Path
from redis.client import Redis
from gsast_core.configs import REDIS_SCAN_RESULTS_TTL
from gsast_core.utils.safe_logging import log


Expand Down Expand Up @@ -57,10 +58,12 @@ def store_scan_results(scans_redis: Redis, scan_id: str, project_url: str, scann
'scanner_type': scanner_type,
'updated_at': str(int(time.time()))
})
scans_redis.expire(results_key, REDIS_SCAN_RESULTS_TTL)

# Add this project to the scan's project list
projects_key = f"{scan_id}:projects"
scans_redis.sadd(projects_key, project_url)
scans_redis.expire(projects_key, REDIS_SCAN_RESULTS_TTL)

log.info(f"Successfully stored {len(results_paths)} {scanner_type} results for {project_url}")
return True
Expand Down
4 changes: 4 additions & 0 deletions helm/gsast/templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,10 @@ Common environment variables for both API and Worker
- name: NO_PROXY
value: {{ .Values.environment.noProxy }}
{{- end }}
{{- if .Values.environment.trufflehogOnlyVerified }}
- name: TRUFFLEHOG_ONLY_VERIFIED
value: {{ .Values.environment.trufflehogOnlyVerified | quote }}
{{- end }}
- name: GITHUB_API_TOKEN
valueFrom:
secretKeyRef:
Expand Down
4 changes: 4 additions & 0 deletions helm/gsast/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,10 @@ environment:
httpsProxy: null
noProxy: null

# TruffleHog configuration
# Set to "false" to include unverified secrets, "true" for only verified secrets
trufflehogOnlyVerified: "true"

# Custom GitLab CA configuration
customGitlabCA:
enabled: false
Expand Down
Loading