Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Contrast Verify Action

This action verifies an application that's onboarded to Contrast by determining whether the application violates a Job Outcome Policy or threshold of open vulnerabilities.

Inputs

Input NameDescriptionRequired
apiKeyContrast User/Service Account API KeyYes
orgIdContrast Organization IDYes
apiUrlURL of your Contrast Teamserver Instance (must begin with https:// or http://)No, defaults to https://app.contrastsecurity.com
serviceKeyContrast User or Service Account service keyYes, unless authHeader is passed
authHeaderContrast User or Service Account authorization headerYes, if username and serviceKey not passed
userNameContrast User or Service Account usernameYes, if authHeader not passed
appIdID of the application to verify againstYes, if appName not passed
appNameName of the application to verify againstYes, if appId not passed
buildNumberThe build number or app version tag to filter vulnerabilities byNo
failThresholdNumber of vulnerabilities that are needed to fail the build (not used if there is a defined job outcome policy)No, defaults to 0
jobStartTimeFilter vulnerabilities first found after this timestamp (formatted in milliseconds since the epoch)No, defaults to 0
severitiesComma separated list of vulnerability severities to consider (not used if there is a defined job outcome policy). Values allowed are CRITICAL, HIGH, MEDIUM, LOW and NOTENo, defaults to CRITICAL,HIGH

Example usage

name: Test and Verifyon:
push:
branches:
- mainpull_request:
jobs:
test_and_verify:
runs-on: ubuntu-lateststeps:
# check out project
- uses: actions/checkout@v2# record start time so we can verify only newly found vulnerabilities
- name: Define job start timerun: | import os, time n = int(round(time.time() * 1000)) print(f"jobStartTime={n}", file=open(os.environ["GITHUB_OUTPUT"], "a"))shell: pythonid: set-job-start-time# steps to build and run integration tests# - name: Run tests#
- name: Contrast Verifyuses: Contrast-Security-OSS/integration-verify-github-action@mainwith:
apiKey: ${{ secrets.CONTRAST_API_KEY }}orgId: <organization id>apiUrl: https://app.contrastsecurity.comauthHeader: ${{ secrets.CONTRAST_AUTH_HEADER }}appName: App_Name_Here#appId: or app_uuid_here if knownjobStartTime: "${{ steps.set-job-start-time.outputs.jobStartTime }}"

Job Start Time and Build Number

As shown above, the jobStartTime input value can be generated with a script step, running prior to your tests. This approach is useful when you want to consider only new vulnerabilities found by this action run, for example in a pull request.

You may also pass a buildNumber input which will filter for vulnerabilities found in specific builds. The agent must be started with this same build number provided via the CONTRAST__APPLICATION__VERSION environment variable, or equivalent YAML/System Properties.

If both jobStartTime and buildNumber are provided, the step will consider only vulnerabilities found since the specified start time, and with the provided buildNumber.

Use outside of GitHub Actions

This integration is available as a Docker image which allows it to be used in other environments outside of GitHub Actions, for example, in GitLab pipelines. For more details, see Container Documentation.

Logging

Debug log messages are only made visible when GitHub Actions debug logging is enabled.

Proxy / Custom TLS Certificates

A HTTP or HTTPS proxy may be used, by setting the environment variables HTTP_PROXY and HTTPS_PROXY respectively. The value should be the full proxy URL, including authorization details if required.

If your environment requires custom certificate(s) to be trusted, these may be provided via the input caFile in pem format.

Development Setup

  1. Run python -m venv venv to setup a virtual environment
  2. Run . venv/bin/activate to activate the virtual environment
  3. Run pip install -r requirements-dev.txt to install development dependencies (will also include app dependencies)
  4. Run pre-commit install to setup the pre-commit hook which handles formatting

About

GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities

Topics

Resources

Security policy

Stars

5 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - Contrast-Security-OSS/integration-verify-github-action: GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities · GitHub
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Contrast Verify Action

This action verifies an application that's onboarded to Contrast by determining whether the application violates a Job Outcome Policy or threshold of open vulnerabilities.

Inputs

Input NameDescriptionRequired
apiKeyContrast User/Service Account API KeyYes
orgIdContrast Organization IDYes
apiUrlURL of your Contrast Teamserver Instance (must begin with https:// or http://)No, defaults to https://app.contrastsecurity.com
serviceKeyContrast User or Service Account service keyYes, unless authHeader is passed
authHeaderContrast User or Service Account authorization headerYes, if username and serviceKey not passed
userNameContrast User or Service Account usernameYes, if authHeader not passed
appIdID of the application to verify againstYes, if appName not passed
appNameName of the application to verify againstYes, if appId not passed
buildNumberThe build number or app version tag to filter vulnerabilities byNo
failThresholdNumber of vulnerabilities that are needed to fail the build (not used if there is a defined job outcome policy)No, defaults to 0
jobStartTimeFilter vulnerabilities first found after this timestamp (formatted in milliseconds since the epoch)No, defaults to 0
severitiesComma separated list of vulnerability severities to consider (not used if there is a defined job outcome policy). Values allowed are CRITICAL, HIGH, MEDIUM, LOW and NOTENo, defaults to CRITICAL,HIGH

Example usage

name: Test and Verifyon:
push:
branches:
- mainpull_request:
jobs:
test_and_verify:
runs-on: ubuntu-lateststeps:
# check out project
- uses: actions/checkout@v2# record start time so we can verify only newly found vulnerabilities
- name: Define job start timerun: | import os, time n = int(round(time.time() * 1000)) print(f"jobStartTime={n}", file=open(os.environ["GITHUB_OUTPUT"], "a"))shell: pythonid: set-job-start-time# steps to build and run integration tests# - name: Run tests#
- name: Contrast Verifyuses: Contrast-Security-OSS/integration-verify-github-action@mainwith:
apiKey: ${{ secrets.CONTRAST_API_KEY }}orgId: <organization id>apiUrl: https://app.contrastsecurity.comauthHeader: ${{ secrets.CONTRAST_AUTH_HEADER }}appName: App_Name_Here#appId: or app_uuid_here if knownjobStartTime: "${{ steps.set-job-start-time.outputs.jobStartTime }}"

Job Start Time and Build Number

As shown above, the jobStartTime input value can be generated with a script step, running prior to your tests. This approach is useful when you want to consider only new vulnerabilities found by this action run, for example in a pull request.

You may also pass a buildNumber input which will filter for vulnerabilities found in specific builds. The agent must be started with this same build number provided via the CONTRAST__APPLICATION__VERSION environment variable, or equivalent YAML/System Properties.

If both jobStartTime and buildNumber are provided, the step will consider only vulnerabilities found since the specified start time, and with the provided buildNumber.

Use outside of GitHub Actions

This integration is available as a Docker image which allows it to be used in other environments outside of GitHub Actions, for example, in GitLab pipelines. For more details, see Container Documentation.

Logging

Debug log messages are only made visible when GitHub Actions debug logging is enabled.

Proxy / Custom TLS Certificates

A HTTP or HTTPS proxy may be used, by setting the environment variables HTTP_PROXY and HTTPS_PROXY respectively. The value should be the full proxy URL, including authorization details if required.

If your environment requires custom certificate(s) to be trusted, these may be provided via the input caFile in pem format.

Development Setup

  1. Run python -m venv venv to setup a virtual environment
  2. Run . venv/bin/activate to activate the virtual environment
  3. Run pip install -r requirements-dev.txt to install development dependencies (will also include app dependencies)
  4. Run pre-commit install to setup the pre-commit hook which handles formatting

About

GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities

Topics

Resources

Security policy

Stars

5 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Contrast-Security-OSS/integration-verify-github-action: GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities · GitHub
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Contrast Verify Action

This action verifies an application that's onboarded to Contrast by determining whether the application violates a Job Outcome Policy or threshold of open vulnerabilities.

Inputs

Input NameDescriptionRequired
apiKeyContrast User/Service Account API KeyYes
orgIdContrast Organization IDYes
apiUrlURL of your Contrast Teamserver Instance (must begin with https:// or http://)No, defaults to https://app.contrastsecurity.com
serviceKeyContrast User or Service Account service keyYes, unless authHeader is passed
authHeaderContrast User or Service Account authorization headerYes, if username and serviceKey not passed
userNameContrast User or Service Account usernameYes, if authHeader not passed
appIdID of the application to verify againstYes, if appName not passed
appNameName of the application to verify againstYes, if appId not passed
buildNumberThe build number or app version tag to filter vulnerabilities byNo
failThresholdNumber of vulnerabilities that are needed to fail the build (not used if there is a defined job outcome policy)No, defaults to 0
jobStartTimeFilter vulnerabilities first found after this timestamp (formatted in milliseconds since the epoch)No, defaults to 0
severitiesComma separated list of vulnerability severities to consider (not used if there is a defined job outcome policy). Values allowed are CRITICAL, HIGH, MEDIUM, LOW and NOTENo, defaults to CRITICAL,HIGH

Example usage

name: Test and Verifyon:
push:
branches:
- mainpull_request:
jobs:
test_and_verify:
runs-on: ubuntu-lateststeps:
# check out project
- uses: actions/checkout@v2# record start time so we can verify only newly found vulnerabilities
- name: Define job start timerun: | import os, time n = int(round(time.time() * 1000)) print(f"jobStartTime={n}", file=open(os.environ["GITHUB_OUTPUT"], "a"))shell: pythonid: set-job-start-time# steps to build and run integration tests# - name: Run tests#
- name: Contrast Verifyuses: Contrast-Security-OSS/integration-verify-github-action@mainwith:
apiKey: ${{ secrets.CONTRAST_API_KEY }}orgId: <organization id>apiUrl: https://app.contrastsecurity.comauthHeader: ${{ secrets.CONTRAST_AUTH_HEADER }}appName: App_Name_Here#appId: or app_uuid_here if knownjobStartTime: "${{ steps.set-job-start-time.outputs.jobStartTime }}"

Job Start Time and Build Number

As shown above, the jobStartTime input value can be generated with a script step, running prior to your tests. This approach is useful when you want to consider only new vulnerabilities found by this action run, for example in a pull request.

You may also pass a buildNumber input which will filter for vulnerabilities found in specific builds. The agent must be started with this same build number provided via the CONTRAST__APPLICATION__VERSION environment variable, or equivalent YAML/System Properties.

If both jobStartTime and buildNumber are provided, the step will consider only vulnerabilities found since the specified start time, and with the provided buildNumber.

Use outside of GitHub Actions

This integration is available as a Docker image which allows it to be used in other environments outside of GitHub Actions, for example, in GitLab pipelines. For more details, see Container Documentation.

Logging

Debug log messages are only made visible when GitHub Actions debug logging is enabled.

Proxy / Custom TLS Certificates

A HTTP or HTTPS proxy may be used, by setting the environment variables HTTP_PROXY and HTTPS_PROXY respectively. The value should be the full proxy URL, including authorization details if required.

If your environment requires custom certificate(s) to be trusted, these may be provided via the input caFile in pem format.

Development Setup

  1. Run python -m venv venv to setup a virtual environment
  2. Run . venv/bin/activate to activate the virtual environment
  3. Run pip install -r requirements-dev.txt to install development dependencies (will also include app dependencies)
  4. Run pre-commit install to setup the pre-commit hook which handles formatting

About

GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities

Topics

Resources

Security policy

Stars

5 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Contrast-Security-OSS/integration-verify-github-action: GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities · GitHub
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Contrast Verify Action

This action verifies an application that's onboarded to Contrast by determining whether the application violates a Job Outcome Policy or threshold of open vulnerabilities.

Inputs

Input NameDescriptionRequired
apiKeyContrast User/Service Account API KeyYes
orgIdContrast Organization IDYes
apiUrlURL of your Contrast Teamserver Instance (must begin with https:// or http://)No, defaults to https://app.contrastsecurity.com
serviceKeyContrast User or Service Account service keyYes, unless authHeader is passed
authHeaderContrast User or Service Account authorization headerYes, if username and serviceKey not passed
userNameContrast User or Service Account usernameYes, if authHeader not passed
appIdID of the application to verify againstYes, if appName not passed
appNameName of the application to verify againstYes, if appId not passed
buildNumberThe build number or app version tag to filter vulnerabilities byNo
failThresholdNumber of vulnerabilities that are needed to fail the build (not used if there is a defined job outcome policy)No, defaults to 0
jobStartTimeFilter vulnerabilities first found after this timestamp (formatted in milliseconds since the epoch)No, defaults to 0
severitiesComma separated list of vulnerability severities to consider (not used if there is a defined job outcome policy). Values allowed are CRITICAL, HIGH, MEDIUM, LOW and NOTENo, defaults to CRITICAL,HIGH

Example usage

name: Test and Verifyon:
push:
branches:
- mainpull_request:
jobs:
test_and_verify:
runs-on: ubuntu-lateststeps:
# check out project
- uses: actions/checkout@v2# record start time so we can verify only newly found vulnerabilities
- name: Define job start timerun: | import os, time n = int(round(time.time() * 1000)) print(f"jobStartTime={n}", file=open(os.environ["GITHUB_OUTPUT"], "a"))shell: pythonid: set-job-start-time# steps to build and run integration tests# - name: Run tests#
- name: Contrast Verifyuses: Contrast-Security-OSS/integration-verify-github-action@mainwith:
apiKey: ${{ secrets.CONTRAST_API_KEY }}orgId: <organization id>apiUrl: https://app.contrastsecurity.comauthHeader: ${{ secrets.CONTRAST_AUTH_HEADER }}appName: App_Name_Here#appId: or app_uuid_here if knownjobStartTime: "${{ steps.set-job-start-time.outputs.jobStartTime }}"

Job Start Time and Build Number

As shown above, the jobStartTime input value can be generated with a script step, running prior to your tests. This approach is useful when you want to consider only new vulnerabilities found by this action run, for example in a pull request.

You may also pass a buildNumber input which will filter for vulnerabilities found in specific builds. The agent must be started with this same build number provided via the CONTRAST__APPLICATION__VERSION environment variable, or equivalent YAML/System Properties.

If both jobStartTime and buildNumber are provided, the step will consider only vulnerabilities found since the specified start time, and with the provided buildNumber.

Use outside of GitHub Actions

This integration is available as a Docker image which allows it to be used in other environments outside of GitHub Actions, for example, in GitLab pipelines. For more details, see Container Documentation.

Logging

Debug log messages are only made visible when GitHub Actions debug logging is enabled.

Proxy / Custom TLS Certificates

A HTTP or HTTPS proxy may be used, by setting the environment variables HTTP_PROXY and HTTPS_PROXY respectively. The value should be the full proxy URL, including authorization details if required.

If your environment requires custom certificate(s) to be trusted, these may be provided via the input caFile in pem format.

Development Setup

  1. Run python -m venv venv to setup a virtual environment
  2. Run . venv/bin/activate to activate the virtual environment
  3. Run pip install -r requirements-dev.txt to install development dependencies (will also include app dependencies)
  4. Run pre-commit install to setup the pre-commit hook which handles formatting

About

GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities

Topics

Resources

Security policy

Stars

5 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - Contrast-Security-OSS/integration-verify-github-action: GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities · GitHub
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Contrast Verify Action

This action verifies an application that's onboarded to Contrast by determining whether the application violates a Job Outcome Policy or threshold of open vulnerabilities.

Inputs

Input NameDescriptionRequired
apiKeyContrast User/Service Account API KeyYes
orgIdContrast Organization IDYes
apiUrlURL of your Contrast Teamserver Instance (must begin with https:// or http://)No, defaults to https://app.contrastsecurity.com
serviceKeyContrast User or Service Account service keyYes, unless authHeader is passed
authHeaderContrast User or Service Account authorization headerYes, if username and serviceKey not passed
userNameContrast User or Service Account usernameYes, if authHeader not passed
appIdID of the application to verify againstYes, if appName not passed
appNameName of the application to verify againstYes, if appId not passed
buildNumberThe build number or app version tag to filter vulnerabilities byNo
failThresholdNumber of vulnerabilities that are needed to fail the build (not used if there is a defined job outcome policy)No, defaults to 0
jobStartTimeFilter vulnerabilities first found after this timestamp (formatted in milliseconds since the epoch)No, defaults to 0
severitiesComma separated list of vulnerability severities to consider (not used if there is a defined job outcome policy). Values allowed are CRITICAL, HIGH, MEDIUM, LOW and NOTENo, defaults to CRITICAL,HIGH

Example usage

name: Test and Verifyon:
push:
branches:
- mainpull_request:
jobs:
test_and_verify:
runs-on: ubuntu-lateststeps:
# check out project
- uses: actions/checkout@v2# record start time so we can verify only newly found vulnerabilities
- name: Define job start timerun: | import os, time n = int(round(time.time() * 1000)) print(f"jobStartTime={n}", file=open(os.environ["GITHUB_OUTPUT"], "a"))shell: pythonid: set-job-start-time# steps to build and run integration tests# - name: Run tests#
- name: Contrast Verifyuses: Contrast-Security-OSS/integration-verify-github-action@mainwith:
apiKey: ${{ secrets.CONTRAST_API_KEY }}orgId: <organization id>apiUrl: https://app.contrastsecurity.comauthHeader: ${{ secrets.CONTRAST_AUTH_HEADER }}appName: App_Name_Here#appId: or app_uuid_here if knownjobStartTime: "${{ steps.set-job-start-time.outputs.jobStartTime }}"

Job Start Time and Build Number

As shown above, the jobStartTime input value can be generated with a script step, running prior to your tests. This approach is useful when you want to consider only new vulnerabilities found by this action run, for example in a pull request.

You may also pass a buildNumber input which will filter for vulnerabilities found in specific builds. The agent must be started with this same build number provided via the CONTRAST__APPLICATION__VERSION environment variable, or equivalent YAML/System Properties.

If both jobStartTime and buildNumber are provided, the step will consider only vulnerabilities found since the specified start time, and with the provided buildNumber.

Use outside of GitHub Actions

This integration is available as a Docker image which allows it to be used in other environments outside of GitHub Actions, for example, in GitLab pipelines. For more details, see Container Documentation.

Logging

Debug log messages are only made visible when GitHub Actions debug logging is enabled.

Proxy / Custom TLS Certificates

A HTTP or HTTPS proxy may be used, by setting the environment variables HTTP_PROXY and HTTPS_PROXY respectively. The value should be the full proxy URL, including authorization details if required.

If your environment requires custom certificate(s) to be trusted, these may be provided via the input caFile in pem format.

Development Setup

  1. Run python -m venv venv to setup a virtual environment
  2. Run . venv/bin/activate to activate the virtual environment
  3. Run pip install -r requirements-dev.txt to install development dependencies (will also include app dependencies)
  4. Run pre-commit install to setup the pre-commit hook which handles formatting

About

GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities

Topics

Resources

Security policy

Stars

5 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Contrast-Security-OSS/integration-verify-github-action: GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities · GitHub
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Contrast Verify Action

This action verifies an application that's onboarded to Contrast by determining whether the application violates a Job Outcome Policy or threshold of open vulnerabilities.

Inputs

Input NameDescriptionRequired
apiKeyContrast User/Service Account API KeyYes
orgIdContrast Organization IDYes
apiUrlURL of your Contrast Teamserver Instance (must begin with https:// or http://)No, defaults to https://app.contrastsecurity.com
serviceKeyContrast User or Service Account service keyYes, unless authHeader is passed
authHeaderContrast User or Service Account authorization headerYes, if username and serviceKey not passed
userNameContrast User or Service Account usernameYes, if authHeader not passed
appIdID of the application to verify againstYes, if appName not passed
appNameName of the application to verify againstYes, if appId not passed
buildNumberThe build number or app version tag to filter vulnerabilities byNo
failThresholdNumber of vulnerabilities that are needed to fail the build (not used if there is a defined job outcome policy)No, defaults to 0
jobStartTimeFilter vulnerabilities first found after this timestamp (formatted in milliseconds since the epoch)No, defaults to 0
severitiesComma separated list of vulnerability severities to consider (not used if there is a defined job outcome policy). Values allowed are CRITICAL, HIGH, MEDIUM, LOW and NOTENo, defaults to CRITICAL,HIGH

Example usage

name: Test and Verifyon:
push:
branches:
- mainpull_request:
jobs:
test_and_verify:
runs-on: ubuntu-lateststeps:
# check out project
- uses: actions/checkout@v2# record start time so we can verify only newly found vulnerabilities
- name: Define job start timerun: | import os, time n = int(round(time.time() * 1000)) print(f"jobStartTime={n}", file=open(os.environ["GITHUB_OUTPUT"], "a"))shell: pythonid: set-job-start-time# steps to build and run integration tests# - name: Run tests#
- name: Contrast Verifyuses: Contrast-Security-OSS/integration-verify-github-action@mainwith:
apiKey: ${{ secrets.CONTRAST_API_KEY }}orgId: <organization id>apiUrl: https://app.contrastsecurity.comauthHeader: ${{ secrets.CONTRAST_AUTH_HEADER }}appName: App_Name_Here#appId: or app_uuid_here if knownjobStartTime: "${{ steps.set-job-start-time.outputs.jobStartTime }}"

Job Start Time and Build Number

As shown above, the jobStartTime input value can be generated with a script step, running prior to your tests. This approach is useful when you want to consider only new vulnerabilities found by this action run, for example in a pull request.

You may also pass a buildNumber input which will filter for vulnerabilities found in specific builds. The agent must be started with this same build number provided via the CONTRAST__APPLICATION__VERSION environment variable, or equivalent YAML/System Properties.

If both jobStartTime and buildNumber are provided, the step will consider only vulnerabilities found since the specified start time, and with the provided buildNumber.

Use outside of GitHub Actions

This integration is available as a Docker image which allows it to be used in other environments outside of GitHub Actions, for example, in GitLab pipelines. For more details, see Container Documentation.

Logging

Debug log messages are only made visible when GitHub Actions debug logging is enabled.

Proxy / Custom TLS Certificates

A HTTP or HTTPS proxy may be used, by setting the environment variables HTTP_PROXY and HTTPS_PROXY respectively. The value should be the full proxy URL, including authorization details if required.

If your environment requires custom certificate(s) to be trusted, these may be provided via the input caFile in pem format.

Development Setup

  1. Run python -m venv venv to setup a virtual environment
  2. Run . venv/bin/activate to activate the virtual environment
  3. Run pip install -r requirements-dev.txt to install development dependencies (will also include app dependencies)
  4. Run pre-commit install to setup the pre-commit hook which handles formatting

About

GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities

Topics

Resources

Security policy

Stars

5 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Contrast-Security-OSS/integration-verify-github-action: GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities · GitHub
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Contrast Verify Action

This action verifies an application that's onboarded to Contrast by determining whether the application violates a Job Outcome Policy or threshold of open vulnerabilities.

Inputs

Input NameDescriptionRequired
apiKeyContrast User/Service Account API KeyYes
orgIdContrast Organization IDYes
apiUrlURL of your Contrast Teamserver Instance (must begin with https:// or http://)No, defaults to https://app.contrastsecurity.com
serviceKeyContrast User or Service Account service keyYes, unless authHeader is passed
authHeaderContrast User or Service Account authorization headerYes, if username and serviceKey not passed
userNameContrast User or Service Account usernameYes, if authHeader not passed
appIdID of the application to verify againstYes, if appName not passed
appNameName of the application to verify againstYes, if appId not passed
buildNumberThe build number or app version tag to filter vulnerabilities byNo
failThresholdNumber of vulnerabilities that are needed to fail the build (not used if there is a defined job outcome policy)No, defaults to 0
jobStartTimeFilter vulnerabilities first found after this timestamp (formatted in milliseconds since the epoch)No, defaults to 0
severitiesComma separated list of vulnerability severities to consider (not used if there is a defined job outcome policy). Values allowed are CRITICAL, HIGH, MEDIUM, LOW and NOTENo, defaults to CRITICAL,HIGH

Example usage

name: Test and Verifyon:
push:
branches:
- mainpull_request:
jobs:
test_and_verify:
runs-on: ubuntu-lateststeps:
# check out project
- uses: actions/checkout@v2# record start time so we can verify only newly found vulnerabilities
- name: Define job start timerun: | import os, time n = int(round(time.time() * 1000)) print(f"jobStartTime={n}", file=open(os.environ["GITHUB_OUTPUT"], "a"))shell: pythonid: set-job-start-time# steps to build and run integration tests# - name: Run tests#
- name: Contrast Verifyuses: Contrast-Security-OSS/integration-verify-github-action@mainwith:
apiKey: ${{ secrets.CONTRAST_API_KEY }}orgId: <organization id>apiUrl: https://app.contrastsecurity.comauthHeader: ${{ secrets.CONTRAST_AUTH_HEADER }}appName: App_Name_Here#appId: or app_uuid_here if knownjobStartTime: "${{ steps.set-job-start-time.outputs.jobStartTime }}"

Job Start Time and Build Number

As shown above, the jobStartTime input value can be generated with a script step, running prior to your tests. This approach is useful when you want to consider only new vulnerabilities found by this action run, for example in a pull request.

You may also pass a buildNumber input which will filter for vulnerabilities found in specific builds. The agent must be started with this same build number provided via the CONTRAST__APPLICATION__VERSION environment variable, or equivalent YAML/System Properties.

If both jobStartTime and buildNumber are provided, the step will consider only vulnerabilities found since the specified start time, and with the provided buildNumber.

Use outside of GitHub Actions

This integration is available as a Docker image which allows it to be used in other environments outside of GitHub Actions, for example, in GitLab pipelines. For more details, see Container Documentation.

Logging

Debug log messages are only made visible when GitHub Actions debug logging is enabled.

Proxy / Custom TLS Certificates

A HTTP or HTTPS proxy may be used, by setting the environment variables HTTP_PROXY and HTTPS_PROXY respectively. The value should be the full proxy URL, including authorization details if required.

If your environment requires custom certificate(s) to be trusted, these may be provided via the input caFile in pem format.

Development Setup

  1. Run python -m venv venv to setup a virtual environment
  2. Run . venv/bin/activate to activate the virtual environment
  3. Run pip install -r requirements-dev.txt to install development dependencies (will also include app dependencies)
  4. Run pre-commit install to setup the pre-commit hook which handles formatting

About

GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities

Topics

Resources

Security policy

Stars

5 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - Contrast-Security-OSS/integration-verify-github-action: GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities · GitHub
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Contrast Verify Action

This action verifies an application that's onboarded to Contrast by determining whether the application violates a Job Outcome Policy or threshold of open vulnerabilities.

Inputs

Input NameDescriptionRequired
apiKeyContrast User/Service Account API KeyYes
orgIdContrast Organization IDYes
apiUrlURL of your Contrast Teamserver Instance (must begin with https:// or http://)No, defaults to https://app.contrastsecurity.com
serviceKeyContrast User or Service Account service keyYes, unless authHeader is passed
authHeaderContrast User or Service Account authorization headerYes, if username and serviceKey not passed
userNameContrast User or Service Account usernameYes, if authHeader not passed
appIdID of the application to verify againstYes, if appName not passed
appNameName of the application to verify againstYes, if appId not passed
buildNumberThe build number or app version tag to filter vulnerabilities byNo
failThresholdNumber of vulnerabilities that are needed to fail the build (not used if there is a defined job outcome policy)No, defaults to 0
jobStartTimeFilter vulnerabilities first found after this timestamp (formatted in milliseconds since the epoch)No, defaults to 0
severitiesComma separated list of vulnerability severities to consider (not used if there is a defined job outcome policy). Values allowed are CRITICAL, HIGH, MEDIUM, LOW and NOTENo, defaults to CRITICAL,HIGH

Example usage

name: Test and Verifyon:
push:
branches:
- mainpull_request:
jobs:
test_and_verify:
runs-on: ubuntu-lateststeps:
# check out project
- uses: actions/checkout@v2# record start time so we can verify only newly found vulnerabilities
- name: Define job start timerun: | import os, time n = int(round(time.time() * 1000)) print(f"jobStartTime={n}", file=open(os.environ["GITHUB_OUTPUT"], "a"))shell: pythonid: set-job-start-time# steps to build and run integration tests# - name: Run tests#
- name: Contrast Verifyuses: Contrast-Security-OSS/integration-verify-github-action@mainwith:
apiKey: ${{ secrets.CONTRAST_API_KEY }}orgId: <organization id>apiUrl: https://app.contrastsecurity.comauthHeader: ${{ secrets.CONTRAST_AUTH_HEADER }}appName: App_Name_Here#appId: or app_uuid_here if knownjobStartTime: "${{ steps.set-job-start-time.outputs.jobStartTime }}"

Job Start Time and Build Number

As shown above, the jobStartTime input value can be generated with a script step, running prior to your tests. This approach is useful when you want to consider only new vulnerabilities found by this action run, for example in a pull request.

You may also pass a buildNumber input which will filter for vulnerabilities found in specific builds. The agent must be started with this same build number provided via the CONTRAST__APPLICATION__VERSION environment variable, or equivalent YAML/System Properties.

If both jobStartTime and buildNumber are provided, the step will consider only vulnerabilities found since the specified start time, and with the provided buildNumber.

Use outside of GitHub Actions

This integration is available as a Docker image which allows it to be used in other environments outside of GitHub Actions, for example, in GitLab pipelines. For more details, see Container Documentation.

Logging

Debug log messages are only made visible when GitHub Actions debug logging is enabled.

Proxy / Custom TLS Certificates

A HTTP or HTTPS proxy may be used, by setting the environment variables HTTP_PROXY and HTTPS_PROXY respectively. The value should be the full proxy URL, including authorization details if required.

If your environment requires custom certificate(s) to be trusted, these may be provided via the input caFile in pem format.

Development Setup

  1. Run python -m venv venv to setup a virtual environment
  2. Run . venv/bin/activate to activate the virtual environment
  3. Run pip install -r requirements-dev.txt to install development dependencies (will also include app dependencies)
  4. Run pre-commit install to setup the pre-commit hook which handles formatting

About

GitHub Action to verify an application by determining whether the application violates a job outcome policy or threshold of open vulnerabilities

Topics

Resources

Security policy

Stars

5 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages