KICS
GitLab Analyzer for Infrastructure as Code (IaC) projects
AppSec Portal Importer Name: GitLab KICS
GitLab KICS (Keeping Infrastructure as Code Secure) is a tool for identifying security vulnerabilities and policy violations in infrastructure code (IaC). It supports various IaC formats, such as Terraform, Kubernetes, AWS CloudFormation, and Azure Resource Manager templates. KICS helps identify issues in infrastructure code, enabling developers and operations teams to mitigate potential risks.
Curl example
In this command, the following parameters are used:
-X POST
: specifies the HTTP method to be used (in this case, POST)-H "Authorization: Token <authorization_token>"
: specifies the authorization token obtained from AppSec Portal.-H "Content-Type: multipart/form-data"
: specifies the content type of the request.-F "file=@<report_file_path>"
: specifies the path to the report file generated by the scanner.-F "product_name=<product_name>"
: specifies the name of the product being scanned.-F "product_type=<product_type>"
: specifies the type of the product being scanned.-F "scanner_name=<scanner_name>"
: specifies the name of the scanner used to generate the report (GitLab KICS)-F "branch=<branch_name>"
: (optional) specifies the name of the branch in the source code repository (if applicable) This parameter is particularly useful when you want to associate the scan results with a specific branch in your repository. If not provided, the scan will be associated with the default branch
Last updated