CI/CD Security Support MatrixΒΆ
Get a quick overview of integration types and security features supported across major CI/CD platforms. Use this matrix to pick the right tools for your DevOps workflows and to confirm the security coverage you need.
Integration TypesΒΆ
These are the three supported methods for integrating CI/CD tools with AccuKnox :-
Description: A workflow file is a configuration file within the CI/CD tool where you define the steps of your build, test, and deploy pipeline. It allows you to automate tasks using specific syntax and structure (often YAML or JSON).
Description: This method refers to using external plugins to extend the functionality of the CI/CD tool. Plugins integrate the tool with third-party services or features, such as code scanning, security checks, or deployment to cloud platforms.
Description: Native integration is the built-in capability of AccuKnox to connect directly with CI/CD tools and platforms, with no external plugin. This method utilizes the internal features of AccuKnox to interact with and manage security policies, scans, and assessments within the CI/CD pipeline.
| CI/CD Tool | Workflow file (Direct Steps) | Plugin Support |
|---|---|---|
| Available | Available | |
| Available | Available | |
| Available | Available | |
| Available | Available | |
| Available | Coming Soon | |
| Available | Available | |
| Available | Available | |
| Available | Coming Soon | |
| Available | Coming Soon |
| Repository | Native Integration (IaC) |
|---|---|
| GitHub | Available |
| GitLab | Available |
| Bitbucket | Available |
| Azure Repos | Coming Soon |
Feature Support Table (Plugins)ΒΆ
| CI/CD Tool | SAST | DAST | IaC Scanning | Container Scanning | Secrets Scanning | CI/CD Pipeline Monitoring |
|---|---|---|---|---|---|---|
| Available | Available | Available | Available | Available | Available | |
| Available | Available | Available | Available | Available | Coming Soon | |
| Available | Available (authenticated and unauthenticated) | Available | Available | Available | Coming Soon | |
| Available | Available | Available | Available | Available | Coming Soon | |
| Available | Available | Available | Available | Available | Coming Soon | |
| Available | Available | Available | Available | Available | Coming Soon | |
| Coming Soon | Coming Soon | Coming Soon | Coming Soon | Coming Soon | Coming Soon |
Every Scan Type Each CI/CD Platform SupportsΒΆ
This table lists each scan component against each supported CI/CD platform. A tick means the component ships today. N/A means it is not offered on that platform.
| Component | GitHub Actions | GitLab | BitBucket | Azure DevOps | Circle CI | AWS CodePipeline | Jenkins | Google Codebuild | Bamboo CI |
|---|---|---|---|---|---|---|---|---|---|
| SQ SAST | β | β | β | β | β | N/A | N/A | β | N/A |
| SAST | β | β | β | β | β | β | β | β | β |
| DAST | β | β | β | β | β | β | β authenticated and unauthenticated | β | β |
| IaC | β | β | β | β | β | β | β | β | β |
| Container Scan | β | β | β | β | β | β | β | β | β |
| Secret Scan | β | β | β | β | β | β | β | β | β |
| xBOM | β | β | β | β | N/A | N/A | N/A | N/A | N/A |
| Unified Scan (SAST, IaC, Secrets, SCA, ML Scan, API Discovery, SBOM) | β | β | β | β | N/A | N/A | β | N/A | N/A |
| CX Scan | β | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A |
| Pipeline Script | N/A | N/A | β | β | N/A | N/A | β | N/A | N/A |
| App based | β | β | β | N/A | N/A | N/A | N/A | N/A | N/A |
Jenkins DAST runs against a login-protected application as well as a public one. Set the credentials in the pipeline step to scan behind a login.
The IDE Extension Runs in VS Code, Cursor, and IntelliJΒΆ
| Component | VS Code | Cursor | IntelliJ |
|---|---|---|---|
| IDE Extension | β | β | β |
See AccuKnox Code Security for the IDE for the install steps and the scan engines each editor runs.