Complimentary 90-day, on-prem license available for entities involved in Covid19 response.
SUPPORT

24/5 Hotline Support Service

+44 (0)20 3588 3841

Open a Support Ticket

support@netsparker.com

Integrating Netsparker Enterprise with CircleCI

CircleCI is a continuous integration and delivery system that is used by software teams to allow them to build, test and deploy applications easier and quicker on multiple platforms. With an emphasis on speed and configurability, CircleCI is built to help users test their applications whenever they make changes to it, release it or deploy it.

This topic explains how to configure Netsparker Enterprise to send a detected vulnerability to CircleCI.

For further information, see What Systems Does Netsparker Integrate With?.

CircleCI Fields

This table lists and explains the CircleCI fields in the New CircleCI Integration window.

Button/Section/Field

Description

Scan Type

This is the type of scan:

  • Incremental
  • Full (With primary profile)
  • Full (With selected profile)

For further information, see Types of Scans.

Website

Click to select the URL of the website that will be scanned.

Scan Profile

Click to select the Scan Profile that will be used. (If you selected Full (With primary profile) as the Scan Type, this is not displayed.)

Parameters

Add the information in this script to the corresponding fields in the config.yml file in your project. Use variables for Netsparker Enterprise and API credentials.

How to Generate and Use Netsparker Enterprise’s CircleCI Integration Orbs

Netsparker Enterprise uses GitHub for integration with CircleCI. First, create a config.yml in your project’s root directory. CircleCI will read it each time it runs a build.

Here is a sample config.yaml file:

Click here to access the Netsparker Enterprise orb on CircleCI.

In the following steps, you'll learn how to access these areas in Netsparker Enterprise.

How to Generate Netsparker Enterprise’s CircleCI Integration Scripts

  1. Log in to Netsparker Enterprise.
  2. From the main menu, select Integrations, then New Integration.

  1. From the Continuous Integration Systems section, click CircleCI.
    1. The CircleCI Integration window is displayed.

  1. From the Integration Script Generator section, complete the fields:
    • From the Scan Type field, select an option
    • From the Website dropdown, select a target
    • From the Scan Profile dropdown, select an option
  2. From the Parameters field, add the parameters in this script to the corresponding fields in the config.yml file in your project. Use variables for Netsparker Enterprise API credentials.
  3. Next, before using the plug-in, you need an API Key of a user with Start Scan privileges to start scanning with Netsparker Enterprise:

    • Select [Your Name] (top right window), then API Settings. The API Settings window is displayed.

    • In the Current Password field, enter your current password.
    • Click Submit.
    • Your User ID and Token are displayed.
    • Add these values to your project (see Import Project Environment Variables).

How to Use Netsparker Enterprise's CircleCI Integration Script

Request read/write access to make your experience seamless on CircleCI. CircleCI easily integrates with GitHub and GitHub Enterprise.
  1. Log in to CircleCI with your Github account.
  2. Set up your project.
  3. The config.yml file that you created in the root directory of your project will be read each time the CircleCI assembly runs.
  4. If you have configured your settings correctly, your scan will begin in Netsparker Enterprise.

  1. Scans initiated by CircleCI will display the CircleCI icon in the Website column.
  2. You can also view the Continuous Integration Details of the build you are browsing by clicking Report. Click Technical Report, then Summary.

Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO