Skip to content

Commit 5994e56

Browse files
lavakush07Harness
authored andcommitted
feat: [STO-10697]: Add External Policy Failures (#100911)
* 1c797c Final change * 09fd44 Update overview page * 67330a Add External Policy Failures
1 parent 288aa2c commit 5994e56

File tree

2 files changed

+18
-2
lines changed

2 files changed

+18
-2
lines changed

docs/security-testing-orchestration/overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ In addition, DevOps and security teams need to act on the information provided f
6060
Harness STO enables DevOps and security teams to shift-left security testing:
6161

6262
* **Test:** Test code, OSS libraries, containers, and live apps with popular security scanners as part of the CI/CD Pipeline. Harness orchestrates the scanners to ensure that scanning is timely and easy to apply.
63-
* **Remediate:** Repair security vulnerabilities by empowering developers with a prioritized list that is intelligently deduplicated across all scanners. Harness provides dashboards with clear security vulnerabilities identified.
63+
* **Remediate:** Repair security vulnerabilities by empowering developers with an intelligently deduplicated, prioritized list of vulnerabilities within each scanner. Harness provides dashboards that clearly highlight identified security vulnerabilities.
6464
* **Govern:** Use governance policies and real-time security dashboards for ensuring critical security issues never make it to production. You can apply [Harness existing OPA policy governance](/docs/platform/governance/policy-as-code/harness-governance-overview) to enforce your security testing practices.
6565

6666
With Harness STO, you are scanning at any stage in the CI/CD Pipeline, and providing developers with deduplicated and prioritized vulnerabilities.

docs/security-testing-orchestration/view-security-test-results/view-scan-results.md

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,23 @@ You can filter issues using multiple criteria in the **Vulnerabilities** tab:
6565
- **Stage**: Filter by pipeline stages.
6666
- **Step**: Filter by pipeline steps.
6767
- **Scanner**: Filter issues by specific scanners.
68-
- **Issue Type**: Filter by issue types (e.g., SAST, DAST, SCA, IaC, Secret etc.).
68+
- **Issue Type**: Filter by issue types (e.g., SAST, DAST, SCA, IaC, Secret, [External Policy Failure](/docs/security-testing-orchestration/view-security-test-results/view-scan-results#external-policy-failure), etc.).
69+
70+
71+
### External Policy Failures
72+
73+
External Policy Failures indicate that a policy or compliance rule defined in the security scanner did not pass during the scan. These issues reflect policies defined by organization, such as assurance policies, quality gates, or compliance rules, and are not security vulnerabilities.
74+
75+
External policy failures are surfaced in Harness STO as a distinct **Issue Type** so that you can view External Policy Failures alongside other scan results.
76+
77+
Scanners that currently support External Policy Failures:
78+
79+
1. [Aqua Security](/docs/security-testing-orchestration/sto-techref-category/aquasec-scanner-reference#configure-external-policy-failures)
80+
2. [Wiz](/docs/security-testing-orchestration/sto-techref-category/wiz/artifact-scans-with-wiz#configure-external-policy-failures)
81+
3. [SonarQube](/docs/security-testing-orchestration/sto-techref-category/sonarqube-sonar-scanner-reference#configure-external-policy-failures)
82+
4. [Prisma Cloud](/docs/security-testing-orchestration/sto-techref-category/prisma-cloud-scanner-reference#configure-external-policy-failures)
83+
5. [Anchore](/docs/security-testing-orchestration/sto-techref-category/anchore-enterprise-scanner-reference#configure-external-policy-failures)
84+
6. [Veracode](/docs/security-testing-orchestration/sto-techref-category/veracode-scanner-reference#configure-external-policy-failures)
6985

7086
### Severity-based filtering
7187

0 commit comments

Comments
 (0)