sast-scan icon indicating copy to clipboard operation
sast-scan copied to clipboard

Docker run doesn't recognize the token

Open 0GiS0 opened this issue 1 year ago • 1 comments

Hi all!

I'm trying to scan a .NET project but sast-scanner requires the token for that. If I choose sl it works perfectly:

export SHIFTLEFT_ACCESS_TOKEN=$SL_TOKEN
sl analyze --app shiftleft-csharp-demo --csharp --wait netcoreWebapi.csproj

But If I try to use the container It seems It doesn't receive the token in the env that It expects:

docker run --rm -e "WORKSPACE=${PWD}" -e SHIFTLEFT_ACCESS_TOKEN="$SL_TOKEN" -v $PWD:/app shiftleft/scan scan --src /app --out_dir /app/reports

image

Any thoughts?

Thank you so much!!

0GiS0 avatar Oct 09 '23 09:10 0GiS0

Try also setting the SHIFTLEFT_ORG_ID environment variable to your organization ID, then it should proceed further.

Are you interested in the specific output of this tool? sl is generally better supported.

Ferada avatar Oct 10 '23 06:10 Ferada