To use this action an active NowSecure Platform account is required. If you are not an existing NowSecure Platform customer, please contact us.
Note: If you are upgrading from a previous version of the NowSecure Action, please see Migrating to V3.
-
Get a token from your NowSecure platform instance. More information on this can be found in the NowSecure Support Portal
-
Identify the ID of the group in NowSecure Platform that you want your assessment to be included in. More information on this can be found in the NowSecure Support Portal.
-
Add a GitHub Actions Secret to your project named,
NS_TOKENand add the token created above. -
(For GHAS integration) An active GitHub account (cloud or on-prem) with an active Advanced Security feature
Note: The NowSecure action is dependent upon the results of the NowSecure assessment. If the assessment fails, the action will also fail.
For the easiest setup, see the example annotated workflow in this repository's ./github/workflows/ directory.
Note: The NowSecure Action leverages ripgrep. For Ubuntu images, add a step for
apt-get install -y ripgrep
After the stage that builds your application, create a new stage called scan:
scan:
runs-on: ubuntu-latest
outputs:
report_id: ${{ steps.upload.outputs.report_id }}
# The stage that builds the application.
needs: build
steps:
- name: Checkout repository
uses: actions/checkout@v5
# Replace with whatever pulls the application file before we upload.
- name: Download application
uses: actions/download-artifact@v5
with:
name: app
- name: Install ripgrep
run: sudo apt-get install -y ripgrep
- id: upload
name: NowSecure upload app
uses: nowsecure/nowsecure-action/upload-app@v5
with:
platform_token: ${{ secrets.NS_TOKEN }}
# TODO: Replace application path.
app_file: "example.apk"
# TODO: Replace the Group ID.
group_id: ${{ vars.GROUP_ID }}Then introduce another stage, called process which retrieves the results from the NowSecure Platform and converts the results to SARIF for GHAS:
process:
if: ${{ needs.scan.outputs.report_id }}
runs-on: ubuntu-latest
# The above stage we introduced.
needs: scan
steps:
- name: Checkout repository
uses: actions/checkout@v5
- name: NowSecure download report
uses: nowsecure/nowsecure-action/convert-sarif@v3
timeout-minutes: 60
with:
report_id: ${{ needs.scan.outputs.report_id }}
platform_token: ${{ secrets.NS_TOKEN }}
group_id: ${{ vars.GROUP_ID }}
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: NowSecure.sarif