diff --git a/README.md b/README.md index 8b2ff68..353f59f 100644 --- a/README.md +++ b/README.md @@ -25,3 +25,4 @@ where `` is the latest released tag or `main`. | `image_prefix` | `$CI_TEMPLATE_REGISTRY_HOST/security-products` | Define where all Docker image are pulled from | | `image_suffix` | `""` | Used by `semgrep-sast` job only | | `excluded_analyzers` | `""` | Comma separated list of analyzers that should not run | +| `run_kubesec_sast` | `"false"` | Set it to `"true"` to run `kubesec-sast` job | diff --git a/template.yml b/template.yml index ab80d48..4ed97b2 100644 --- a/template.yml +++ b/template.yml @@ -8,6 +8,8 @@ spec: default: "" excluded_analyzers: default: "" + run_kubesec_sast: + default: 'false' --- .sast-analyzer: @@ -75,8 +77,7 @@ kubesec-sast: when: never - if: '"$[[ inputs.excluded_analyzers ]]" =~ /kubesec/' when: never - - if: $CI_COMMIT_BRANCH && - $SCAN_KUBERNETES_MANIFESTS == 'true' + - if: '$CI_COMMIT_BRANCH && "$[[ inputs.run_kubesec_sast ]]" == "true"' .mobsf-sast: extends: .sast-analyzer