# Include in your .gitlab-ci.yml: # include: # - remote: 'https://lysbor.example.com/agent/lysbor-gitlab-ci.yml' # your Lysbor instance serves the agent # and set LYSBOR_URL, LYSBOR_API_KEY (masked), LYSBOR_PROJECT in Settings > CI/CD > Variables. # LYSBOR_OPTS: "" (SBOM only), "--sast", "--trivy" or "--all". # LYSBOR_INCLUDE_DEV: "true" (default, npm devDependencies included like GitHub's dependency graph) or "false". lysbor-scan: stage: test image: python:3.11-slim variables: SYFT_VERSION: "v1.52.0" TRIVY_VERSION: "v0.74.0" LYSBOR_TARGET: "." LYSBOR_FAIL_ON: "none" LYSBOR_INCLUDE_DEV: "true" LYSBOR_OPTS: "--all" SEMGREP_SEND_METRICS: "off" before_script: - apt-get update -qq && apt-get install -y -qq --no-install-recommends bash curl jq ca-certificates git >/dev/null - curl -sSfL -o /usr/local/bin/lysbor-scan "${LYSBOR_URL%/}/agent/lysbor-scan.sh" && chmod +x /usr/local/bin/lysbor-scan # Release archives, SHA-256 verified against the published checksums (no script piped into a shell). - case " $LYSBOR_OPTS " in *--trivy*|*--all*) lysbor-scan install-tools syft trivy ;; *) lysbor-scan install-tools syft ;; esac - case " $LYSBOR_OPTS " in *--sast*|*--all*) pip install --quiet semgrep ;; esac script: - lysbor-scan $LYSBOR_OPTS "$LYSBOR_TARGET" allow_failure: false