03-11-2022 04:39 PM - edited 03-14-2022 09:27 AM
Code Security on Prisma Cloud enables you to add security checks to your existing IaC (Infrastructure-as-Code) model.
The Code Security capabilities include creating custom build policies, integrating a wide variety of code repositories and continuous integration and continuous delivery (CI/CD) workflows to secure cloud infrastructure, and applications.
Once your code repositories are integrated, you can modify your configuration to specify how Prisma Cloud scans your code.
A. Select Settings > Code Configuration to configure your integrated repository.
B. Enable repositories to scan.
C. Enter paths to exclude from the repository.
D Select Add Rule to add the rule with excluded paths to your code configuration.
2. Enable Code Reviews:
A. Select Settings > Code Configuration to configure your integrated repository.
B. Enable repositories you want to scan.
C. Select the fail severity of the policy.
D. Then add a rule.
4. Enable notifications:
A. Select Settings > Code Security Configuration and enable Notifications.
B. Set up your notification preferences.
1. Enable repositories you want to scan.
2. Select the name or ID of the integration.
3. Select the policy severity threshold.
C. Add Rule to add more granular notification configuration.
D. Save your changes.
5. Enable Tagging Bot:
A. Select Settings > Code Configuration and enable repositories you want to scan.
B. Enable repositories you want to scan.
1. Select from repositories.
Enter paths to exclude from the repository.
2. Type paths to exclude within the selected repository.
Save to exclude the path from the scan.
The next step from here would be Integrate
Please visit Customer Support for additional assistance.