Skip to content

CI/CD Security Support MatrixΒΆ

Get a quick overview of integration types and security features supported across major CI/CD platforms. Use this matrix to pick the right tools for your DevOps workflows and to confirm the security coverage you need.

Integration TypesΒΆ

These are the three supported methods for integrating CI/CD tools with AccuKnox :-

Description: A workflow file is a configuration file within the CI/CD tool where you define the steps of your build, test, and deploy pipeline. It allows you to automate tasks using specific syntax and structure (often YAML or JSON).

Description: This method refers to using external plugins to extend the functionality of the CI/CD tool. Plugins integrate the tool with third-party services or features, such as code scanning, security checks, or deployment to cloud platforms.

Description: Native integration is the built-in capability of AccuKnox to connect directly with CI/CD tools and platforms, with no external plugin. This method utilizes the internal features of AccuKnox to interact with and manage security policies, scans, and assessments within the CI/CD pipeline.

CI/CD Tool Workflow file (Direct Steps) Plugin Support
GitHub Actions GitHub Actions Available Available
GitLab CI/CD GitLab CI/CD Available Available
Jenkins Jenkins Available Available
Azure DevOps Azure DevOps Available Available
AWS CodePipeline AWS CodePipeline Available Coming Soon
Bitbucket Bitbucket Available Available
CircleCI CircleCI Available Available
GCP Cloud Build GCP Cloud Build Available Coming Soon
Harness Harness Available Coming Soon

Repository Native Integration (IaC)
GitHub Available
GitLab Available
Bitbucket Available
Azure Repos Coming Soon

Feature Support Table (Plugins)ΒΆ

CI/CD Tool SAST DAST IaC Scanning Container Scanning Secrets Scanning CI/CD Pipeline Monitoring
GitHub Actions GitHub Actions Available Available Available Available Available Available
GitLab CI/CD GitLab CI/CD Available Available Available Available Available Coming Soon
Jenkins Jenkins Available Available (authenticated and unauthenticated) Available Available Available Coming Soon
Azure DevOps Azure DevOps Available Available Available Available Available Coming Soon
Bitbucket Bitbucket Available Available Available Available Available Coming Soon
CircleCI CircleCI Available Available Available Available Available Coming Soon
Harness Harness Coming Soon Coming Soon Coming Soon Coming Soon Coming Soon Coming Soon

Every Scan Type Each CI/CD Platform SupportsΒΆ

This table lists each scan component against each supported CI/CD platform. A tick means the component ships today. N/A means it is not offered on that platform.

Component GitHub Actions GitLab BitBucket Azure DevOps Circle CI AWS CodePipeline Jenkins Google Codebuild Bamboo CI
SQ SAST βœ“ βœ“ βœ“ βœ“ βœ“ N/A N/A βœ“ N/A
SAST βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“
DAST βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ authenticated and unauthenticated βœ“ βœ“
IaC βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“
Container Scan βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“
Secret Scan βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ βœ“
xBOM βœ“ βœ“ βœ“ βœ“ N/A N/A N/A N/A N/A
Unified Scan (SAST, IaC, Secrets, SCA, ML Scan, API Discovery, SBOM) βœ“ βœ“ βœ“ βœ“ N/A N/A βœ“ N/A N/A
CX Scan βœ“ N/A N/A N/A N/A N/A N/A N/A N/A
Pipeline Script N/A N/A βœ“ βœ“ N/A N/A βœ“ N/A N/A
App based βœ“ βœ“ βœ“ N/A N/A N/A N/A N/A N/A

Jenkins DAST runs against a login-protected application as well as a public one. Set the credentials in the pipeline step to scan behind a login.

The IDE Extension Runs in VS Code, Cursor, and IntelliJΒΆ

Component VS Code Cursor IntelliJ
IDE Extension βœ“ βœ“ βœ“

See AccuKnox Code Security for the IDE for the install steps and the scan engines each editor runs.