CloudBees continuous security integrates security seamlessly into your CI/CD process. It conducts event-based security scans from a single control pane, ensuring every commit is checked for vulnerabilities, license risks, and secrets, without requiring any developer configuration.
By shifting security to earlier in the development lifecycle and automatically enforcing policies, you enhance your application security posture and minimize production risks, eliminating the need for fragmented, tool-specific checks.
Benefits
-
Automate security checks: Reduce manual intervention and ensures consistency.
-
Streamline issue management: Provide a centralized view for efficient issue resolution.
-
Foster innovation: Allows developers to focus on delivering value without being bogged down by security concerns.
Technical requirements
-
SCM integration (GitHub or Bitbucket) for enabling security scans.
-
Private network access, if the SCM is not publicly accessible.
For full details and environment guidance, refer to CloudBees Unify technical requirements.
Configure continuous security
To configure continuous security:
-
Integrate your GitHub or Bitbucket repository with CloudBees Unify. For more information, refer to SCM integrations.
-
Create a component. Link your repository to a new Unify component to enable scanning. For more information, refer to Manage components.
-
Push code changes to automatically trigger security scans, including SAST, SCA, and secret scanning. No pipeline configuration is required.
-
Use Unify’s security views to address or escalate issues:
For triage details, refer to Triage findings.
Next steps
To enhance your understanding and further leverage CloudBees Unify capabilities, explore the other CloudBees Unify quickstarts.