{"id":3074,"date":"2022-10-18T16:25:17","date_gmt":"2022-10-18T07:25:17","guid":{"rendered":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/?p=3074"},"modified":"2022-10-29T22:22:38","modified_gmt":"2022-10-29T13:22:38","slug":"devsecops-pipeline-with-zap-snyk","status":"publish","type":"post","link":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/blog\/2022\/10\/18\/devsecops-pipeline-with-zap-snyk\/","title":{"rendered":"OWASP ZAP\u3068Snyk\u3092\u5229\u7528\u3057\u305fDevSecOps CI\/CD \u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3092\u69cb\u7bc9\u3057\u3066\u307f\u307e\u3057\u3087\u3046"},"content":{"rendered":"
\u7686\u69d8\u3001\u521d\u3081\u307e\u3057\u3066\uff0110\u67081\u65e5\u5165\u793e\u306e\u30a2\u30fc\u30ce\u30eb\u30c9\u3068\u7533\u3057\u307e\u3059\u3002\u30dd\u30fc\u30e9\u30f3\u30c9\u51fa\u8eab\u3067\u3001\u5c02\u9580\u9818\u57df\u306fAWS\u4e0a\u306e\u30a4\u30f3\u30d5\u30e9\u69cb\u7bc9\u3001IaC\u3001DevSecOps\u3067\u3059\u3002<\/p>\n
\u3055\u3066\u65e9\u901f\u3067\u3059\u304c\u3001\u3053\u306e\u30d6\u30ed\u30b0\u8a18\u4e8b\u3067\u306f\u3001SCA, SAST, DAST\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c4\u30fc\u30eb\u3092\u7d71\u5408\u3057\u305f\u3001\u30b5\u30f3\u30d7\u30eb\u306eDevSecOps CI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3092\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002SCA\u3068SAST\u306b\u306fSnyk<\/a>\u3092\u3001DAST\u306b\u306fOWASP ZAP<\/a>\u3092\u63a1\u7528\u3057\u307e\u3059\u3002<\/p>\n \u203b\u3053\u306e\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u306f\u3001AWS\u306e\u4ee5\u4e0b\u306e\u8a18\u4e8b\u306b\u57fa\u3065\u3044\u3066\u3044\u307e\u3059\uff1a SCA<\/strong> \u3068\u306f\u3001\u300cSoftware Composition Analysis\u300d\u306e\u7701\u7565\u3067\u3001\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u69cb\u6210\u5206\u6790\u3092\u610f\u5473\u3057\u307e\u3059\u3002SCA\u30c4\u30fc\u30eb\u306f\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u5185\u3067\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u30e9\u30a4\u30d6\u30e9\u30ea\u3084\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u306a\u3069\u306e\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u5206\u6790\u3057\u3001\u305d\u308c\u3089\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306e\u8106\u5f31\u6027\u3084\u30e9\u30a4\u30bb\u30f3\u30b9\u306e\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u3092\u691c\u8a3c\u3057\u307e\u3059\u3002\u3055\u3089\u306b\u3001\u30b3\u30f3\u30c6\u30ca\u74b0\u5883\u306e\u3088\u3046\u306a\u73fe\u4ee3\u7684\u306a\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3\u306b\u9069\u7528\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u3001\u975e\u516c\u958b\u30b3\u30f3\u30c6\u30ca\u304a\u3088\u3073Docker Hub\u306a\u3069\u306e\u516c\u5171\u30ec\u30b8\u30b9\u30c8\u30ea\u304b\u3089\u5229\u7528\u3067\u304d\u308b\u30b3\u30f3\u30c6\u30ca\u5185\u306e\u516c\u958b\u3055\u308c\u305f\u8106\u5f31\u6027\u3092\u81ea\u52d5\u7684\u306b\u691c\u51fa\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n \u3088\u304f\u4f7f\u308f\u308c\u308bSCA\u30c4\u30fc\u30eb\uff1a SAST<\/strong>\u3068\u306f\u3001\u300cStatic Application Security Testing\u300d\u306e\u7701\u7565\u3067\u3001\u9759\u7684\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u30fb\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30fb\u30c6\u30b9\u30c8\u3092\u610f\u5473\u3057\u307e\u3059\u3002SAST\u306e\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u306f\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u3001\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u3001\u307e\u305f\u306f\u30d0\u30a4\u30ca\u30ea\u5185\u306e\u8106\u5f31\u6027\u3092\u884c\u5358\u4f4d\u3067\u81ea\u52d5\u7684\u306b\u30c1\u30a7\u30c3\u30af\u3057\u3001OWASP Top10\u306a\u3069\u306eWeb\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30ea\u30b9\u30af\u30e9\u30f3\u30ad\u30f3\u30b0\u306b\u63b2\u8f09\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8106\u5f31\u6027\u3092\u3001\u958b\u767a\u30d7\u30ed\u30bb\u30b9\u306e\u65e9\u3044\u6bb5\u968e\u3067\u691c\u51fa\u3059\u308b\u3053\u3068\u3092\u53ef\u80fd\u306b\u3057\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u958b\u767a\u8005\u306f\u30b3\u30fc\u30c9\u304c\u672c\u756a\u74b0\u5883\u306b\u30c7\u30d7\u30ed\u30a4\u3055\u308c\u308b\u524d\u306b\u6b20\u9665\u3084\u30ea\u30b9\u30af\u3092\u7279\u5b9a\u3057\u3001\u8106\u5f31\u6027\u3092\u4fee\u6b63\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u30a2\u30d7\u30ed\u30fc\u30c1\u306f\u3001\u300c\u30b7\u30d5\u30c8\u30ec\u30d5\u30c8\u30a2\u30d7\u30ed\u30fc\u30c1\u300d\u3068\u547c\u3070\u308c\u307e\u3059\u3002 \u3088\u304f\u4f7f\u308f\u308c\u308bSAST\u30c4\u30fc\u30eb\uff1a DAST<\/strong>\u3068\u306f\u3001\u300cDynamic Application Security Testing\u300d\u306e\u7701\u7565\u3067\u3001\u52d5\u7684\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u30fb\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30fb\u30c6\u30b9\u30c8\u3092\u610f\u5473\u3057\u307e\u3059\u3002DAST\u306e\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u306f\u3001\u5b9f\u884c\u4e2d\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u5bfe\u8a71\u3057\u3001\u305d\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u8106\u5f31\u6027\u3092\u691c\u51fa\u3059\u308b\u3053\u3068\u3092\u76ee\u7684\u3068\u3057\u3066\u3044\u307e\u3059\u3002 \u3088\u304f\u4f7f\u308f\u308c\u308bDAST\u30c4\u30fc\u30eb\uff1a \u3067\u306f\u3001SCA\u3001SAST\u3001DAST\u306e\u30c4\u30fc\u30eb\u3092\u7d71\u5408\u3057\u305f\u30b5\u30f3\u30d7\u30eb\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3092\u898b\u3066\u307f\u307e\u3057\u3087\u3046\u3002<\/p>\n \u4eca\u56de\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3\u306eCI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3092\u30c7\u30d7\u30ed\u30a4\u3057\u307e\u3059\u3002Snyk\u3068ZAP\u306e\u4ed6\u306b\u3001CI\/CD\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3068\u3057\u3066CircleCI\u3092\u3001\u30b3\u30f3\u30c6\u30ca\u30a4\u30e1\u30fc\u30b8\u306e\u4fdd\u5b58\u5148\u3068\u3057\u3066Amazon ECR\u3092\u5229\u7528\u3057\u307e\u3059\u3002 \u3053\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3092\u9032\u3081\u308b\u306b\u306f\u3001\u4ee5\u4e0b\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u5fc5\u8981\u306b\u306a\u308a\u307e\u3059\u306d\u3002\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u4f5c\u6210\u306f\u7c21\u5358\u306a\u4f5c\u696d\u306a\u306e\u3067\u3001\u3053\u3053\u3067\u306f\u8a73\u7d30\u3092\u7701\u304d\u307e\u3059\u3002 \u3053\u306e\u30ea\u30dd\u30b8\u30c8\u30ea<\/a>\u3092\u30d5\u30a9\u30fc\u30af\u3057\u307e\u3059\u3002\u691c\u8a3c\u7528\u306e\u8106\u5f31\u306a\u30a2\u30d7\u30ea\u3068\u3001CircleCI\u4e0a\u3067CI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u8a2d\u5b9a\u3092\u542b\u3093\u3067\u3044\u307e\u3059\u3002<\/p>\n \u4e0a\u8a18\u30b9\u30c6\u30c3\u30d7\u3067\u30d5\u30a9\u30fc\u30af\u3057\u305f\u30ea\u30dd\u30b8\u30c8\u30ea\u3092CircleCI \u306b\u9023\u643a\u3055\u305b\u3001\u65b0\u898f\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n <\/p>\n Amazon Elastic Container Registry\uff08ECR\uff09\u306e\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8\u30ea\u30dd\u30b8\u30c8\u30ea\u3092\u4f5c\u6210\u3057\u3001\u300czap-snyk-circleci\u300d\u3068\u3044\u3046\u540d\u524d\u3092\u3064\u3051\u307e\u3059\uff08\u540d\u524d\u304c\u7570\u306a\u3063\u3066\u3044\u3066\u3082\u69cb\u3044\u307e\u305b\u3093\uff09\u3002ECR\u306eURL\u3092\u30e1\u30e2\u3057\u3066\u304a\u304d\u307e\u3059\u3002 ECR\u3078\u306e\u8aad\u53d6\u308a\/\u66f8\u8fbc\u307f\u6a29\u9650\u306e\u3042\u308bIAM\u30e6\u30fc\u30b6\u30fc\u3092\u4f5c\u6210\u3057\u307e\u3059\uff08Programmatic access\u3067\u826f\u3044\u3067\u3059\uff09\u3002 \u305d\u306e\u30e6\u30fc\u30b6\u30fc\u306eAWS_ACCESS_KEY_ID\u3068AWS_SECRET_ACCESS_KEY\u3092\u4fdd\u5b58\u3057\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<\/li>\n<\/ol>\n Snyk\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u767b\u9332\u307e\u305f\u306f\u30ed\u30b0\u30a4\u30f3\u3057\u3001API\u30c8\u30fc\u30af\u30f3\u3092\u767a\u884c\u3057\u307e\u3059 \u30c8\u30fc\u30af\u30f3\u767a\u884c\u624b\u9806\uff1a <\/p>\n CircleCI\u306eProject Settings\u753b\u9762\u3067\u3001\u4ee5\u4e0b\u306e\u74b0\u5883\u5909\u6570\u3092\u8a2d\u5b9a\u3057\u307e\u3059\uff1a<\/p>\n <\/p>\n \u4ee5\u4e0a\u3067\u8a2d\u5b9a\u304c\u5b8c\u4e86\u3067\u3059\u3002<\/p>\n \u4e0a\u8a18\u2460\u2461\u306e\u624b\u9806\u306b\u6cbf\u3063\u3066\u6b63\u3057\u304f\u8a2d\u5b9a\u3092\u884c\u3044\u3001GitHub\u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u306b\u30b3\u30fc\u30c9\u3092\u30d7\u30c3\u30b7\u30e5\u3059\u308b\u3068CI\/CD\u304c\u81ea\u52d5\u7684\u306b\u52d5\u304d\u51fa\u3057\u307e\u3059\uff01\u3057\u304b\u3057\u3001\u6700\u5f8c\u306e\u30b9\u30c6\u30fc\u30b8\u3067\u30d3\u30eb\u30c9\u304c\u5931\u6557\u3057\u3066\u3057\u307e\u3044\u307e\u3059\u306d\u3001\u3001\u3001\u3002<\/p>\n <\/p>\n \u306a\u305c\u3053\u306e\u3088\u3046\u306a\u3053\u3068\u304c\u8d77\u3053\u308b\u306e\u304b\u3001\u6b21\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u3054\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n \u3053\u3053\u3067\u3001\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u306e\u30b3\u30f3\u30d5\u30a3\u30ae\u30e5\u30ec\u30fc\u30b7\u30e7\u30f3YAML\u30d5\u30a1\u30a4\u30eb\u3092\u53c2\u7167\u3057\u306a\u304c\u3089\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u306e\u69cb\u6210\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002<\/p>\n .circleci\/config.yml<\/a>\u3092\u898b\u306a\u304c\u3089\u304a\u8aad\u307f\u304f\u3060\u3055\u3044\u3002<\/p>\n jobs: sast_dast_scan_docker_image\uff0835\u884c\u76ee\uff09<\/p>\n \u21aa\ufe0eaws-ecr\/build-and-push-image\uff0841\u884c\u76ee\uff09 \u21aa\ufe0esnyk\/scan\uff0848\u884c\u76ee\uff09 <\/p>\n \u203b \u4eca\u56de\u306f50\u884c\u76ee\u306e\u95a2\u6570fail-on-issues\u3092false\u306b\u8a2d\u5b9a\u3057\u3066\u3044\u307e\u3059\u306d\u3002\u305d\u3046\u3059\u308b\u3053\u3068\u306b\u3088\u3063\u3066\u3001\u8106\u5f31\u6027\u304c\u767a\u898b\u3055\u308c\u3066\u3082CI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u306e\u5b9f\u884c\u304c\u7d99\u7d9a\u3055\u308c\u307e\u3059\u3002 run:<\/p>\n \u21aa\ufe0ename: Run docker container\uff0856\u884c\u76ee\uff09 \u21aa\ufe0ename: ZAP baseline test of application\uff0860\u884c\u76ee\uff09 store_artifacts \n<\/li>\n run: Check result of ZAP scan and fail pipeline if exit code was 1 \u2191\u3053\u308c\u304c\u307e\u3055\u306b\u30b5\u30f3\u30d7\u30eb\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3067\u8d77\u3053\u3063\u305f\u3053\u3068\u3067\u3001\u6700\u5f8c\u306e\u30b9\u30c6\u30fc\u30b8\u304c\u5931\u6557\u3057\u305f\u7406\u7531\u3067\u3059\u306d\uff01<\/p>\n \u3061\u306a\u307f\u306b\u3001\u30ea\u30dd\u30b8\u30c8\u30ea\u306e\u30eb\u30fc\u30c8\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u3042\u308b zap-baseline.conf \u30d5\u30a1\u30a4\u30eb\u3092\u3044\u3058\u308c\u3070\u3001\u3069\u306e\u30b9\u30ad\u30e3\u30f3\u30eb\u30fc\u30eb\u3067\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3092\u5931\u6557\u3055\u305b\u308b\u304b\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<\/li>\n<\/ol>\n OWASP ZAP\u306f\u3001OWASP\u56e3\u4f53\u306e\u6700\u91cd\u8981\u306a\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e\u4e00\u3064\u3067\u3059\u3002Web\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u8106\u5f31\u6027\u3092\u767a\u898b\u3059\u308b\u305f\u3081\u306e\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u3001\u30af\u30ed\u30b9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306eDAST\u30c4\u30fc\u30eb\u3067\u3059\u3002<\/p>\n ZAP\u3067\u306f\u3001\uff13\u7a2e\u985e\u306e\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u53ef\u80fd\u3067\u3059\u3002<\/p>\n ZAP\u3092CI\/CD\u30d7\u30ed\u30bb\u30b9\u306b\u7d44\u307f\u8fbc\u3080\u305f\u3081\u306e\u4e00\u756a\u7c21\u5358\u306a\u65b9\u6cd5\u306f\u3001Docker\u30a4\u30e1\u30fc\u30b8\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u3067\u3059\u3002 \u4ee5\u4e0b\u306f\u3001Docker\u3092\u5229\u7528\u3057\u305f\u5834\u5408\u306e\u57fa\u672c\u7684\u306a\u30b3\u30de\u30f3\u30c9\u3067\u3059\uff1a \u4e0a\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3092\u3088\u304f\u898b\u308b\u3068\u3001ZAP\u306e\u30a6\u30a3\u30fc\u30af\u30ea\u30fc\u30ea\u30ea\u30fc\u30b9\uff08 \u6700\u5f8c\u306b \u30b9\u30ad\u30e3\u30f3\u7d50\u679c\u306e\u30ec\u30dd\u30fc\u30c8\u3092\u30d5\u30a1\u30a4\u30eb\u306b\u51fa\u529b\u3059\u308b\u3053\u3068\u306f\u53ef\u80fd\u3067\u3059\uff01 HTML\u3068JSON\u306e\u30ec\u30dd\u30fc\u30c8\u51fa\u529b\u3092\u542b\u3081\u305f\u30b3\u30de\u30f3\u30c9\u4f8b\uff1a \u203b\u30ec\u30dd\u30fc\u30c8\u51fa\u529b\u306e\u969b\u306b\u306f\u30b3\u30f3\u30c6\u30ca\u30c7\u30a3\u30ec\u30af\u30c8\u30ea \u3053\u306e\u8a18\u4e8b\u3067\u306f\u3001DevSecOps\u306e\u30b5\u30f3\u30d7\u30eb\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u306b\u3064\u3044\u3066\u7d39\u4ecb\u3057\u307e\u3057\u305f\u3002<\/p>\n \u307e\u305a\u3001SCA\u3001SAST\u3001DAST\u3068\u3044\u3063\u305f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c4\u30fc\u30eb\u306e\u7570\u306a\u308b\u30ab\u30c6\u30b4\u30ea\u30fc\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u307e\u3057\u305f\u3002<\/p>\n \u6b21\u306b\u3001DevSecOps\u306eCI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u306e\u30b5\u30f3\u30d7\u30eb\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3\u3092\u63d0\u793a\u3057\u3001\u305d\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306b\u5fc5\u8981\u306a\u30b9\u30c6\u30c3\u30d7\u3092\u8aac\u660e\u3057\u307e\u3057\u305f\u3002<\/p>\n \u305d\u306e\u5f8c\u3001\u30d0\u30c3\u30af\u30b0\u30e9\u30a6\u30f3\u30c9\u3067\u4f55\u304c\u8d77\u304d\u3066\u3044\u308b\u304b\u3092\u3088\u308a\u6df1\u304f\u7406\u89e3\u3059\u308b\u305f\u3081\u306b\u3001CircleCI\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306b\u3064\u3044\u3066\u89e3\u8aac\u3057\u307e\u3057\u305f\u3002<\/p>\n \u6700\u5f8c\u306b\u3001OWASP ZAP\u306e\u4f7f\u7528\u306b\u95a2\u3059\u308b\u57fa\u672c\u7684\u306a\u77e5\u8b58\u3092\u5171\u6709\u3057\u307e\u3057\u305f\u3002<\/p>\n \u7686\u69d8\u306e\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306b\u304a\u3044\u3066DevSecOps\u306e\u30aa\u30fc\u30c8\u30e1\u30fc\u30b7\u30e7\u30f3\u3092\u5c0e\u5165\u3059\u308b\u969b\u306e\u53c2\u8003\u3068\u306a\u308c\u3070\u5e78\u3044\u3067\u3059\uff01<\/p>\n","protected":false},"excerpt":{"rendered":" \u306f\u3058\u3081\u306b \u7686\u69d8\u3001\u521d\u3081\u307e\u3057\u3066\uff0110\u67081\u65e5\u5165\u793e\u306e\u30a2\u30fc\u30ce\u30eb\u30c9\u3068\u7533\u3057\u307e\u3059\u3002\u30dd\u30fc\u30e9\u30f3\u30c9\u51fa\u8eab\u3067\u3001\u5c02\u9580\u9818\u57df\u306fAWS\u4e0a\u306e\u30a4\u30f3\u30d5\u30e9\u69cb\u7bc9\u3001IaC\u3001DevSecOps\u3067\u3059\u3002 \u3055\u3066\u65e9\u901f\u3067\u3059\u304c\u3001\u3053\u306e\u30d6\u30ed\u30b0\u8a18\u4e8b\u3067\u306f\u3001SCA, SAST, DAST\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c4\u30fc\u30eb\u3092\u7d71\u5408\u3057\u305f\u3001\u30b5\u30f3\u30d7\u30eb\u306eDevSecOps CI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3092\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002SCA\u3068SAST\u306b\u306fSnyk\u3092\u3001DAST\u306b\u306fOWASP ZAP\u3092\u63a1\u7528\u3057\u307e\u3059\u3002 \u203b\u3053 […]<\/p>\n","protected":false},"author":31,"featured_media":3133,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[18],"tags":[344,44,387,434,32],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/3074"}],"collection":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/comments?post=3074"}],"version-history":[{"count":28,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/3074\/revisions"}],"predecessor-version":[{"id":3144,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/3074\/revisions\/3144"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/media\/3133"}],"wp:attachment":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/media?parent=3074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/categories?post=3074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/tags?post=3074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}
\nhttps:\/\/aws.amazon.com\/blogs\/publicsector\/create-a-secure-and-fast-devsecops-pipeline-with-circleci\/<\/a><\/p>\nSCA, SAST, DAST\u3068\u306f\u4f55\uff1f<\/h2>\n
\n\u30fbSnyk<\/a>
\n\u30fbClair<\/a>
\n\u30fbBlack Duck<\/a>
\n\u30fbVeracode SCA<\/a>
\n\u306a\u3069\u3002<\/p>\n
\nSAST\u306e\u5229\u70b9\u306f\u3001\u30b3\u30fc\u30c9\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c1\u30a7\u30c3\u30af\u3092\u884c\u3046\u305f\u3081\u306b\u5b9f\u884c\u4e2d\u306e\u30a2\u30d7\u30ea\u30b5\u30fc\u30d0\u30fc\u3092\u5fc5\u8981\u3068\u305b\u305a\u3001\u624b\u52d5\u306e\u30b3\u30fc\u30c9\u30ec\u30d3\u30e5\u30fc\u3084\u4fb5\u5165\u30c6\u30b9\u30c8\u306e\u3088\u3046\u306b\u901f\u5ea6\u3092\u843d\u3068\u3059\u3053\u3068\u304c\u306a\u3044\u70b9\u3067\u3059\u3002<\/p>\n
\n\u30fbSnyk<\/a>
\n\u30fbSonarqube<\/a>
\n\u30fbVeracode SAST<\/a>
\n\u306a\u3069\u3002<\/p>\n
\nSAST\u3068\u306e\u4e3b\u306a\u9055\u3044\u306f\u3001DAST\u30c4\u30fc\u30eb\u3092\u4f7f\u3063\u3066\u8106\u5f31\u6027\u3092\u691c\u51fa\u3059\u308b\u305f\u3081\u306b\u306f\u3001Web\u30b5\u30fc\u30d0\u30fc\u3001\u4eee\u60f3\u30de\u30b7\u30f3\u3001\u30b3\u30f3\u30c6\u30ca\u306a\u3069\u306b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u89e3\u6790\u306e\u969b\u306b\u5b9f\u884c\u4e2d\u306e\u72b6\u614b\u306b\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u70b9\u3067\u3059\u3002
\nDAST\u30c4\u30fc\u30eb\u306f\u30a6\u30a7\u30d6\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u901a\u4fe1\u3092\u30d7\u30ed\u30ad\u30b7\u3057\u3001\u30d6\u30e9\u30a6\u30b6\uff08\u30d5\u30ed\u30f3\u30c8\u30a8\u30f3\u30c9\uff09\u3068\u30b5\u30fc\u30d0\u30fc\uff08\u30d0\u30c3\u30af\u30a8\u30f3\u30c9\uff09\u306e\u9593\u306b\u4f4d\u7f6e\u3065\u3051\u3089\u308c\u307e\u3059\u3002\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u3092\u898b\u308b\u3053\u3068\u306a\u304f\u3001\u52d5\u7684\u89e3\u6790\u306f\u4fb5\u5165\u30c6\u30b9\u30c8\u306e\u3088\u3046\u306a\u653b\u6483\u3092\u30b7\u30df\u30e5\u30ec\u30fc\u30c8\u3057\u3001\u30cf\u30c3\u30ab\u30fc\u306e\u8996\u70b9\u304b\u3089\u60aa\u7528\u53ef\u80fd\u306a\u8106\u5f31\u6027\u3068\u30d3\u30b8\u30cd\u30b9\u30ed\u30b8\u30c3\u30af\u306e\u554f\u984c\u3092\u767a\u898b\u3057\u3001\u4fe1\u983c\u6027\u306e\u9ad8\u3044\u7d50\u679c\u3092\u51fa\u3057\u307e\u3059\u3002<\/p>\n
\n\u30fbOWASP ZAP<\/a>
\n\u30fbStackHawk<\/a>
\n\u30fbBurp Suite<\/a>
\n\u30fbArachni <\/a>
\n\u306a\u3069\u3067\u3059\u3002<\/p>\n\u691c\u8a3c\u74b0\u5883\u3068\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3<\/h2>\n
\n<\/p>\n
\n\u30fbGitHub
\n\u30fbCircleCI
\n\u30fbAWS
\n\u30fbSnyk
\n\u3061\u306a\u307f\u306b\u3001\u4e0a\u8a18\u30b5\u30fc\u30d3\u30b9\u306f\u7121\u6599\u7248\u3082\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n\u2460 \u4e8b\u524d\u6e96\u5099<\/h3>\n
GitHub<\/h5>\n
CircleCI<\/h5>\n
AWS<\/h5>\n
\n
\n
\n\u53c2\u7167\u8cc7\u6599\uff1ahttps:\/\/docs.aws.amazon.com\/ja_jp\/AmazonECR\/latest\/userguide\/repository-create.html<\/a><\/p>\n<\/li>\n
\n\u203bAWS\u304c\u63a8\u5968\u3059\u308b\u6700\u5c0f\u6a29\u9650\u30a2\u30af\u30bb\u30b9\u539f\u5247\u306b\u5f93\u3063\u3066\u3001\u524d\u306e\u30b9\u30c6\u30c3\u30d7\u3067\u4f5c\u6210\u3057\u305f\u30ea\u30dd\u30b8\u30c8\u30ea\u3078\u306e\u30a2\u30af\u30bb\u30b9\u306e\u307f\u3092\u8a31\u53ef\u3059\u308b\u3053\u3068\u304c\u63a8\u5968\u3055\u308c\u307e\u3059\u3002<\/p>\nSnyk<\/h5>\n
\nhttps:\/\/app.snyk.io\/login<\/a><\/p>\n
\nAccount Settings \u2192 General \u2192 Auth Token<\/p>\n\u2461 CircleCI\u306e\u8a2d\u5b9a<\/h3>\n
\n
\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u306e\u69cb\u6210<\/h2>\n
\n
\n\u30fb\u3053\u306e\u30b9\u30c6\u30c3\u30d7\u3067\u306f\u3001\u30b5\u30f3\u30d7\u30ebnode.js\u306e\u30a2\u30d7\u30ea\u3092\u30d3\u30eb\u30c9\u3057\u3001\u5358\u4f53\u30c6\u30b9\u30c8\u3092\u5b9f\u884c\u3057\u307e\u3059 <\/li>\n
\n\u30fb\u3053\u3053\u3067\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u306b\u5bfe\u3057\u3066Snyk\u3067SCA\u306e\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u307e\u3059<\/li>\n
\n\u3000 \u30fb\u3053\u3053\u3067Docker\u306e\u30a4\u30e1\u30fc\u30b8\u3092\u30d3\u30eb\u30c9\u3057\u3001ECR\u306b\u30d7\u30c3\u30b7\u30e5\u3057\u307e\u3059<\/p>\n
\n\u3000\u30fbECR\u306e\u30a4\u30e1\u30fc\u30b8\u306b\u5bfe\u3057\u3066\u3001Snyk\u3067SAST\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u307e\u3059
\n\u3000\u30fb\u30b9\u30ad\u30e3\u30f3\u306e\u7d50\u679c\u306fCircleCI\u307e\u305f\u306fSnyk\u306eUI\u3067\u78ba\u8a8d\u3067\u304d\u307e\u3059<\/p>\n
\n\u3053\u306e\u3088\u3046\u306a\u52d5\u4f5c\u306f\u3001\u4eca\u56de\u306e\u691c\u8a3c\u74b0\u5883\u3067\u306f\u554f\u984c\u3042\u308a\u307e\u305b\u3093\u304c\u3001\u672c\u756a\u306e\u30ef\u30fc\u30af\u30ed\u30fc\u30c9\u306b\u304a\u3044\u3066\u306f\u8106\u5f31\u6027\u3092\u653e\u7f6e\u3059\u308b\u3053\u3068\u306f\u5371\u967a\u3067\u3059\u306e\u3067\u3001fail-on-issues\u3092true\u306b\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3092\u63a8\u5968\u3057\u307e\u3059\u3002<\/p>\n<\/li>\n
\n\u3000\u30fbDAST\u306e\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306b\u30a2\u30d7\u30ea\u30b3\u30f3\u30c6\u30ca\u3092\u8d77\u52d5\u3057\u307e\u3059<\/p>\n
\n\u3000\u30fbZAP\u306eDocker\u30a4\u30e1\u30fc\u30b8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059
\n\u3000\u30fb\u30b9\u30ad\u30e3\u30f3\u5bfe\u8c61\u306e\u30a2\u30d7\u30ea\u30b3\u30f3\u30c6\u30ca\u306b\u5bfe\u3057\u3066ZAP\u3067\u30d9\u30fc\u30b9\u30e9\u30a4\u30f3\u306eDAST\u30b9\u30ad\u30e3\u30f3\u203b\u3092\u5b9f\u884c\u3057\u307e\u3059
\n\u3000\u3000 \u203b\u30d9\u30fc\u30b9\u30e9\u30a4\u30f3\u30b9\u30ad\u30e3\u30f3\u3068\u306f\u4f55\u304b\u3001\u6700\u5f8c\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u3054\u8aac\u660e\u3057\u307e\u3059\uff01
\n\u3000\u30fb\u30b9\u30ad\u30e3\u30f3\u7d50\u679c\u30ec\u30dd\u30fc\u30c8\u3092HTML\u3068JSON\u5f62\u5f0f\u3067\u4fdd\u5b58\u3057\u307e\u3059\uff08\u4ed6\u306bwiki\u3068XML\u306e\u5f62\u5f0f\u304c\u51fa\u529b\u53ef\u80fd\uff09
\n\u3000\u30fb\u30b9\u30ad\u30e3\u30f3\u306e\u7d42\u4e86\u30b3\u30fc\u30c9\u3092\u4fdd\u5b58\u3057\u3066\u304a\u304d\u307e\u3059
\n\u3000\u3000\u2192 \u7d42\u4e86\u30b3\u30fc\u30c9 1 \u306f\uff0c\u5c11\u306a\u304f\u3068\u3082 1 \u3064\u306e FAIL \u304c\u691c\u51fa\u3055\u308c\u305f\u3053\u3068\u3092\u793a\u3057\u307e\u3059\u3002
\n\u3000\u3000\u2192 \u7d42\u4e86\u30b3\u30fc\u30c9 2\u30683\u306fWARN\u306a\u3069\u3092\u793a\u3057\u3001\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3092\u5207\u65ad\u3057\u307e\u305b\u3093\u3002<\/p>\n<\/li>\n
\n\u30fbZAP\u30b9\u30ad\u30e3\u30f3\u7d50\u679c\u306e\u30ec\u30dd\u30fc\u30c8\u3092CircleCI\u30a2\u30fc\u30c6\u30a3\u30d5\u30a1\u30af\u30c8\u3068\u3057\u3066\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u307e\u3059<\/p>\n
\n\u30fbZAP\u30b9\u30ad\u30e3\u30f3\u306e\u7d42\u4e86\u30b3\u30fc\u30c9\u3092\u78ba\u8a8d\u3057\u30011\u306e\u5834\u5408\uff08\uff1d\u30b3\u30f3\u30c6\u30ca\u306b\u306f\u8106\u5f31\u6027\u304c\u691c\u51fa\u3055\u308c\u305f\uff09\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u3092\u5931\u6557\u3055\u305b\u307e\u3059\u3002<\/p>\n\u304a\u307e\u3051\uff1aOWASP ZAP\u306e\u57fa\u790e<\/h2>\n
ZAP\u306e\u6982\u8981<\/h3>\n
\u30b9\u30ad\u30e3\u30f3\u306e\u7a2e\u985e<\/h3>\n
\n
\n
\n\u8981\u6ce8\u610f\uff1a\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u6240\u6709\u8005\u306e\u8a31\u53ef\u306a\u304f\u3001\u3053\u306e\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u306f\u9055\u6cd5\u884c\u70ba\u3068\u898b\u306a\u3055\u308c\u308b\u3002<\/li>\nZAP\u306e\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3059\u308b\u306b\u306f<\/h3>\n
\nZAP\u306eDocker\u30b3\u30f3\u30c6\u30ca\u306f\u3001\u4ee5\u4e0b4\u7a2e\u985e\u304c\u5229\u7528\u53ef\u80fd\u3067\u3059\u3002<\/p>\n\n
docker pull owasp\/zap2docker-stable<\/code><\/li>\n
docker pull owasp\/zap2docker-weekly<\/code><\/li>\n
docker pull owasp\/zap2docker-live<\/code><\/li>\n
docker pull owasp\/zap2docker-bare<\/code><\/li>\n<\/ul>\n
\ndocker run -t owasp\/zap2docker-weekly zap-baseline.py -t [URL]<\/code><\/p>\n
owasp\/zap2docker-weekly<\/code>\uff09\u3092\u4f7f\u7528\u3057\u3066\u30d9\u30fc\u30b9\u30e9\u30a4\u30f3\u30b9\u30ad\u30e3\u30f3\uff08
zap-baseline.py<\/code>\uff09\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\uff01
\n\u30d5\u30eb\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u305f\u3044\u5834\u5408\u3001zap-baseline.py<\/code>\u3092
zap-full-scan.py<\/code>\u306b\u7f6e\u304d\u63db\u3048\u308b\u3060\u3051\u3067\u3059\u3002
\nAPI\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3059\u308b\u306b\u306f\u3001zap-baseline.py<\/code>\u3092
zap-api-scan.py<\/code>\u306b\u7f6e\u304d\u63db\u307e\u3059\u3002
\n\u203bAPI\u30b9\u30ad\u30e3\u30f3\u306e\u5834\u5408\u3001\u3082\u3046\u5c11\u3057\u8907\u96d1\u3067\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u306e\u6307\u5b9a\u3082\u5fc5\u8981\u306b\u306a\u308a\u307e\u3059\u3002\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u53c2\u7167\u306b\u3057\u3066\u307f\u3066\u304f\u3060\u3055\u3044<\/a>\u3002<\/p>\n[URL]<\/code>\u306e\u90e8\u5206\u306f\u3001\u5bfe\u8c61URL\u307e\u305f\u306f\u30b5\u30fc\u30d0\u30fcIP\u306b\u66f8\u304d\u63db\u3048\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u306d\u3002\u4f8b\uff1a
https:\/\/www.example.com<\/code>\u3001
http:\/\/172.17.0.2:5000\/<\/code><\/p>\n
\u30ec\u30dd\u30fc\u30c8\u3092\u51fa\u529b\u3057\u305f\u3044\u304c\u3001\u3069\u3046\u3059\u308c\u3070\u826f\u3044\u306e\uff1f<\/h3>\n
\n\u5229\u7528\u53ef\u80fd\u306a\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3068\u3001\u5fc5\u8981\u306a\u30b3\u30de\u30f3\u30c9\u30d5\u30e9\u30b0\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u306b\u306a\u308a\u307e\u3059\u3002
\n-r report.html<\/code>\uff1aHTML \u30ec\u30dd\u30fc\u30c8\u306e\u51fa\u529b\u3002
\n-w report.md<\/code>\uff1aWiki \u30ec\u30dd\u30fc\u30c8\u306e\u51fa\u529b\u3002
\n-x report.xml<\/code>\uff1aXML \u30ec\u30dd\u30fc\u30c8\u306e\u51fa\u529b\u3002
\n-J report.json<\/code>\uff1aJSON \u30ec\u30dd\u30fc\u30c8\u306e\u51fa\u529b\u3002<\/p>\n
\ndocker run -v \/tmp:\/zap\/wrk\/:rw -t owasp\/zap2docker-weekly zap-baseline.py -t http:\/\/172.17.0.2:8080 -r report.html -J report.json<\/code><\/p>\n
\/zap\/wrk<\/code>\u3092\u30de\u30a6\u30f3\u30c8\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u4e0a\u8a18\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3068\u3001\u30ec\u30dd\u30fc\u30c8\u30d5\u30a1\u30a4\u30eb\u304c\/tmp\u306b\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002<\/p>\n
\u307e\u3068\u3081<\/h2>\n