Home / Companies / Harness / Blog / Post Details
Content Deep Dive

Vulnerability Scanning in your CI/CD Pipeline - Part Two

Blog post from Harness

Post Details
Company
Date Published
Author
Ravi Lachhman
Word Count
1,351
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

Integrating vulnerability scanning into CI/CD pipelines using Harness and Nexus IQ is a strategy aimed at enhancing security by preventing the deployment of artifacts with severe vulnerabilities. The process involves using Harness to operationalize Nexus IQ's vulnerability scanning, allowing for the deployment of hygienic artifacts only. The setup includes managing secrets through Harness Secrets Manager, setting up workflow variables, and creating workflows for scanning artifacts, interpreting scan results, and deploying applications. By programmatically interpreting scan results and incorporating them into a Harness Pipeline, users can automate the detection of severe vulnerabilities and halt deployments if necessary. This integration exemplifies a DevSecOps approach, shifting security practices towards development and self-service while ensuring application security testing evolves alongside modern software development practices.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 18 244 43 26 -15%
Kubernetes 2 794 116 43 -38%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.