SCA Findings¶
SCA (Software Composition Analysis) scanners on BoostSecurity for GitLab can be set up by enabling one or more specialized SCA scanners. Follow these simple steps to configure it:
- Navigate to the Scanner Coverage page.
-
Click on Select all repositories for GitLab to install the SCA scanner on all GitLab resources.
You can choose to select particular GitLab organizations or repositories.
-
Click on the Provisioning button at the top right of the page.
-
Scroll down to the SCA section of the scanners and select any SCA scanners. BoostSecurity Nancy, Npm-audit, and Trivy are good options.
You may notice that some scanners are grayed out and cannot be selected. This is because additional configurations must be completed to enable the selection of these scanners, e.g.,
-
Click the Complete button.
That's it!! You've successfully configured SCA scanners for your GitLab repositories.
-
The SCA scanners are now provisioned and awaiting the first scan.
-
Click on the
Scanners
tab and scroll to the SCA section. -
Click the Trigger Scan button, and any findings on the result will appear in the findings page.