2020-08-24 14:10:19 -04:00
|
|
|
.dast_conf:
|
|
|
|
tags:
|
|
|
|
- prm
|
|
|
|
# For scheduling dast job
|
|
|
|
extends:
|
2021-04-20 14:09:37 -04:00
|
|
|
- .reports:rules:schedule-dast
|
2020-08-24 14:10:19 -04:00
|
|
|
image:
|
2022-05-30 14:08:57 -04:00
|
|
|
name: "${REGISTRY_HOST}/security-products/dast:$DAST_VERSION"
|
2020-08-24 14:10:19 -04:00
|
|
|
resource_group: dast_scan
|
|
|
|
variables:
|
|
|
|
DAST_USERNAME_FIELD: "user[login]"
|
|
|
|
DAST_PASSWORD_FIELD: "user[password]"
|
2022-05-30 08:08:23 -04:00
|
|
|
DAST_SUBMIT_FIELD: "name:button"
|
2020-08-24 14:10:19 -04:00
|
|
|
DAST_FULL_SCAN_ENABLED: "true"
|
2021-10-05 14:13:27 -04:00
|
|
|
DAST_VERSION: 2
|
|
|
|
GIT_STRATEGY: none
|
2020-08-24 14:10:19 -04:00
|
|
|
# -Xmx is used to set the JVM memory to 6GB to prevent DAST OutOfMemoryError.
|
|
|
|
DAST_ZAP_CLI_OPTIONS: "-Xmx6144m"
|
|
|
|
before_script:
|
|
|
|
- 'export DAST_WEBSITE="${DAST_WEBSITE:-$(cat environment_url.txt)}"'
|
|
|
|
- 'export DAST_AUTH_URL="${DAST_WEBSITE}/users/sign_in"'
|
|
|
|
- 'export DAST_PASSWORD="${REVIEW_APPS_ROOT_PASSWORD}"'
|
|
|
|
# Help pages are excluded from scan as they are static pages.
|
|
|
|
# profile/two_factor_auth is excluded from scan to prevent 2FA from being turned on from user profile, which will reduce coverage.
|
2021-10-05 14:13:27 -04:00
|
|
|
- 'DAST_EXCLUDE_URLS="${DAST_WEBSITE}/help/.*,${DAST_WEBSITE}/-/profile/two_factor_auth,${DAST_WEBSITE}/users/sign_out"'
|
2020-10-14 05:08:46 -04:00
|
|
|
# Exclude the automatically generated monitoring project from being tested due to https://gitlab.com/gitlab-org/gitlab/-/issues/260362
|
2021-10-05 14:13:27 -04:00
|
|
|
- 'export DAST_EXCLUDE_URLS="${DAST_EXCLUDE_URLS},${DAST_WEBSITE}/gitlab-instance-.*"'
|
2020-08-24 14:10:19 -04:00
|
|
|
needs: ["review-deploy"]
|
|
|
|
stage: dast
|
|
|
|
# Default job timeout set to 90m and dast rules needs 2h to so that it won't timeout.
|
2022-05-30 08:08:23 -04:00
|
|
|
timeout: 3h
|
2020-09-14 11:09:28 -04:00
|
|
|
# Add retry because of intermittent connection problems. See https://gitlab.com/gitlab-org/gitlab/-/issues/244313
|
|
|
|
retry: 1
|
2020-08-24 14:10:19 -04:00
|
|
|
artifacts:
|
|
|
|
paths:
|
|
|
|
- gl-dast-report.json # GitLab-specific
|
|
|
|
reports:
|
|
|
|
dast: gl-dast-report.json
|
|
|
|
expire_in: 1 week # GitLab-specific
|
2021-10-07 14:11:28 -04:00
|
|
|
allow_failure: true
|
2020-08-24 14:10:19 -04:00
|
|
|
|
|
|
|
# DAST scan with a subset of Release scan rules.
|
2021-10-05 14:13:27 -04:00
|
|
|
# ZAP rule details can be found at https://www.zaproxy.org/docs/alerts/
|
|
|
|
|
2022-05-30 08:08:23 -04:00
|
|
|
dast:anti-clickjacking-header:
|
2020-08-24 14:10:19 -04:00
|
|
|
extends:
|
|
|
|
- .dast_conf
|
|
|
|
variables:
|
|
|
|
DAST_USERNAME: "user1"
|
2022-05-30 08:08:23 -04:00
|
|
|
DAST_ONLY_INCLUDE_RULES: "10020"
|
2020-08-24 14:10:19 -04:00
|
|
|
script:
|
2021-10-05 14:13:27 -04:00
|
|
|
- /analyze
|
2020-08-24 14:10:19 -04:00
|
|
|
|
2022-05-30 08:08:23 -04:00
|
|
|
dast:xss-persistant:
|
2020-08-24 14:10:19 -04:00
|
|
|
extends:
|
|
|
|
- .dast_conf
|
|
|
|
variables:
|
|
|
|
DAST_USERNAME: "user2"
|
2022-05-30 08:08:23 -04:00
|
|
|
DAST_ONLY_INCLUDE_RULES: "40014"
|
2020-08-24 14:10:19 -04:00
|
|
|
script:
|
2021-10-05 14:13:27 -04:00
|
|
|
- /analyze
|
2020-08-24 14:10:19 -04:00
|
|
|
|
2022-05-30 08:08:23 -04:00
|
|
|
dast:insecure-http-method:
|
2020-08-24 14:10:19 -04:00
|
|
|
extends:
|
|
|
|
- .dast_conf
|
|
|
|
variables:
|
|
|
|
DAST_USERNAME: "user3"
|
2022-05-30 08:08:23 -04:00
|
|
|
DAST_ONLY_INCLUDE_RULES: "90028"
|
2020-08-24 14:10:19 -04:00
|
|
|
script:
|
2021-10-05 14:13:27 -04:00
|
|
|
- /analyze
|
2020-08-24 14:10:19 -04:00
|
|
|
|
2022-05-30 08:08:23 -04:00
|
|
|
dast:server-side-template-inj:
|
2020-08-24 14:10:19 -04:00
|
|
|
extends:
|
|
|
|
- .dast_conf
|
|
|
|
variables:
|
|
|
|
DAST_USERNAME: "user4"
|
2022-05-30 08:08:23 -04:00
|
|
|
DAST_ONLY_INCLUDE_RULES: "90035"
|
2020-08-24 14:10:19 -04:00
|
|
|
script:
|
2021-10-05 14:13:27 -04:00
|
|
|
- /analyze
|
2020-08-24 14:10:19 -04:00
|
|
|
|
2022-05-30 08:08:23 -04:00
|
|
|
dast:server-side-template-inj-blind:
|
2021-10-05 14:13:27 -04:00
|
|
|
extends:
|
|
|
|
- .dast_conf
|
|
|
|
variables:
|
|
|
|
DAST_USERNAME: "user5"
|
2022-05-30 08:08:23 -04:00
|
|
|
DAST_ONLY_INCLUDE_RULES: "90035"
|
2021-10-05 14:13:27 -04:00
|
|
|
script:
|
|
|
|
- /analyze
|
2020-08-24 14:10:19 -04:00
|
|
|
|
2022-05-30 08:08:23 -04:00
|
|
|
dast:session-fixation:
|
2020-08-24 14:10:19 -04:00
|
|
|
extends:
|
|
|
|
- .dast_conf
|
|
|
|
variables:
|
2021-10-05 14:13:27 -04:00
|
|
|
DAST_USERNAME: "user6"
|
2022-05-30 08:08:23 -04:00
|
|
|
DAST_ONLY_INCLUDE_RULES: "40013"
|
2020-08-24 14:10:19 -04:00
|
|
|
script:
|
2021-10-05 14:13:27 -04:00
|
|
|
- /analyze
|
2020-08-24 14:10:19 -04:00
|
|
|
|
2022-05-30 08:08:23 -04:00
|
|
|
dast:xss-dombased:
|
2020-08-24 14:10:19 -04:00
|
|
|
extends:
|
|
|
|
- .dast_conf
|
|
|
|
variables:
|
2021-10-05 14:13:27 -04:00
|
|
|
DAST_USERNAME: "user10"
|
2022-05-30 08:08:23 -04:00
|
|
|
DAST_ONLY_INCLUDE_RULES: "40026"
|
2020-08-24 14:10:19 -04:00
|
|
|
script:
|
2021-10-05 14:13:27 -04:00
|
|
|
- /analyze
|