For the complete documentation index, see llms.txt. This page is also available as Markdown.

OpsMx Code Scan

OpsMx Code Scan is an open-source static analysis tool used for identifying and fixing security issues in source code. It is designed to be fast, developer-friendly, and can be integrated into the development workflow. OpsMx Code Scan uses a pattern-based approach to detect and fix security vulnerabilities, coding errors, and other issues in codebases.

Usage of OpsMx Code Scan in Delivery Shield

  • Delivery Shield integrates with OpsMx Code Scan to perform static analysis on source code, identifying security vulnerabilities, code quality issues, and policy violations early in the development cycle.

  • Findings from OpsMx Code Scan scans are ingested and factored into the application's overall security score, alongside results from other SAST tools.

To Integrate OpsMx Code Scan:

  1. Navigate to Setup > Integrations.

  2. In the Source panel, click OpsMx Code Scan.

  3. The OpsMx Code Scan integration page is displayed. Click +New Account.

  1. In the popup that appears, enter the details for the following fields:

  1. Enter the Account Name.

  2. Enable SAST Scan.

  3. Select the Teams and the corresponding Environments from the dropdown for which you want the integration to be available. The integration will be available for the selected teams and environment only. You can select up to 5 teams for the integration to be displayed.

  • An example is given below for reference:

  • In the example above,

  • If Team 1, Team 2, and Team 3 are selected, only applications associated with these teams can access the integration. Any applications belonging to other teams, such as Team 4, will not have access to this account.

  • Even if the user who created this account is also an admin for Team 4, the integration account remains restricted and is not available for Team 4.

  • Access to the account is strictly limited to the specified Teams and Environments selected during account creation.

  • For Organization Admins:

    • When an Organization Admin creates an account without selecting specific Teams and Environments, the account will be universally applicable, granting access to all teams and all environments by default.

  • For Team Admins with Multiple Teams:

    • If a Team Admin who manages multiple teams creates an account without specifying particular Teams and Environments, the account will only be accessible to the teams for which the logged-in user holds admin privileges.

  1. Click Save. The tool is integrated in the source stage.

  2. You can edit the entered values by clicking the Edit option as shown below:

  1. Do the necessary changes and click Update. The new values get updated.

  1. To delete the integration, click the Delete button.

Last updated