- Checkmarx Documentation
- Checkmarx One
- Checkmarx One User Guide
- Configuring Account Settings
- Global Account Settings
- IaC Security Scanner Parameters
IaC Security Scanner Parameters
The parameters that will be defined for the IaC Security scanner will be applied to all the Projects running IaC Security scans.
The table below presents all the optional parameters and their optional values.
Notice
CLI flags are submitted on the scan level with the scan create command. API configs can be configured on the account or project level using the Configuration API or on the scan level as part of the request body of the POST /scans API. When using the POST /scans API the scan.config.kics prefix is left out.
Parameter | Values | Notes | CLI | API |
|---|---|---|---|---|
Folder/file filter | Allow users to select specific folders or files to include or exclude from the code-scanning process. |
|
| scan.config.kics.filter {
"key": "scan.config.kics.filter",
"value": "*.java",
"allowOverride": true
} |
Platforms |
| NoticeConfigure one or more platforms, separated by a comma. The parameter means you only want to run scans (queries) for those platforms. For example, Ansible, CloudFormation, Dockerfile WarningAny mistake in the platform characters will cause an error. |
| scan.config.kics.platforms {
"key": "scan.config.kics.platforms",
"value": "GRPC",
"allowOverride": true
} |
Preset Name | All the available IaC Security Presets that exist in the system | There are no Checkmarx Default Presets now. For more information on IaC presets, see here. WarningThe preset ID for IaC Security must be a valid UUID. Once you create one, you can copy the PresetID from the IaC Presets page. |