Skip to content

Commit 834dab6

Browse files
authored
Merge pull request #2882 from thc202/update-data
Update data
2 parents 482e5ce + f4eebe3 commit 834dab6

File tree

8 files changed

+149
-0
lines changed

8 files changed

+149
-0
lines changed
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
---
2+
# This page was generated from the add-on.
3+
title: Scan Policies
4+
type: userguide
5+
weight: 1
6+
cascade:
7+
addon:
8+
id: scanpolicies
9+
version: 0.1.0
10+
---
11+
12+
# Scan Policies
13+
14+
This add-on provides a set of Scan Policies tuned for different purposes.
15+
16+
These policies are initialised as detailed in the relevant pages, but you can tune them as required.
17+
18+
* [Default Policy](/docs/desktop/addons/scan-policies/policy-default/) : the default policy, all installed active rules enabled
19+
* [Developer CICD Policy](/docs/desktop/addons/scan-policies/policy-dev-cicd/) : a policy intended for CI/CD use, focused on quick but higher risk issues
20+
* [Developer Standard Policy](/docs/desktop/addons/scan-policies/policy-dev-std/) : a policy directed at developers, meant to perform fairly quickly while providing a greater set of results than the CICD policy (intended for use in a dev environment)
21+
* [Developer Full Policy](/docs/desktop/addons/scan-policies/policy-dev-full/) : a developer focused policy, including a superset of the dev standard with a greater variety of potential findings and only minimal environmental/server related rules (intended for use in a dev environment)
22+
* [QA Standard Policy](/docs/desktop/addons/scan-policies/policy-qa-std/) : a quality assurance focused policy meant to perform fairly quickly while providing a greater set of results than developer policies, intended for use in a QA/staging environment
23+
* [QA Full Policy](/docs/desktop/addons/scan-policies/policy-qa-full/) : a more comprehensive quality assurance focused policy, including a superset of the QA standard with a greater variety of potential findings with more environmental/server related rules, intended for use in a QA/Staging environment
24+
* [API Policy](/docs/desktop/addons/scan-policies/policy-api/) : a policy focusing on issues likely to impact APIs and not UI.
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
# This page was generated from the add-on.
3+
title: API Policy
4+
type: userguide
5+
weight: 1
6+
---
7+
8+
# API Policy
9+
10+
A policy focusing on issues likely to impact APIs and not UI.
11+
12+
For the list of scan rules included see the [Alert Tag: POLICY_API](/alerttags/policy_api/) page.
13+
14+
Return to [main scan policies page](/docs/desktop/addons/scan-policies/).
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
# This page was generated from the add-on.
3+
title: Default Policy
4+
type: userguide
5+
weight: 2
6+
---
7+
8+
# Default Policy
9+
10+
A policy which enables all of the installed active scan rules.
11+
12+
Return to [main scan policies page](/docs/desktop/addons/scan-policies/).
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
---
2+
# This page was generated from the add-on.
3+
title: Developer CI/CD Policy
4+
type: userguide
5+
weight: 3
6+
---
7+
8+
# Developer CI/CD Policy
9+
10+
This policy is designed to be used by developers in a CI/CD pipeline.
11+
12+
* Recommended for running in CI/CD
13+
* No environmental / server related rules
14+
* No long running rules
15+
* No rules with high false positives
16+
* No timing attacks
17+
* No informational only rules
18+
* Minimal overlap
19+
20+
For the list of scan rules included see the [Alert Tag: POLICY_DEV_CICD](/alerttags/policy_dev_cicd/) page.
21+
22+
Return to [main scan policies page](/docs/desktop/addons/scan-policies/).
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
---
2+
# This page was generated from the add-on.
3+
title: Developer Full Policy
4+
type: userguide
5+
weight: 5
6+
---
7+
8+
# Developer Full Policy
9+
10+
A developer focused policy, including a superset of the [dev standard](/docs/desktop/addons/scan-policies/policy-dev-std/) with a greater variety of potential findings and only minimal environmental/server related rules, intended for use in a dev environment.
11+
12+
* A superset of Developer Standard
13+
* Intended to run in a dev environment
14+
* No rules with high false positives
15+
* No timing attacks
16+
* Minimal environmental / server related rules
17+
18+
For the list of scan rules included see the [Alert Tag: POLICY_DEV_FULL](/alerttags/policy_dev_full/) page.
19+
20+
Return to [main scan policies page](/docs/desktop/addons/scan-policies/).
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
---
2+
# This page was generated from the add-on.
3+
title: Developer Standard Policy
4+
type: userguide
5+
weight: 4
6+
---
7+
8+
# Developer Standard Policy
9+
10+
A developer focused policy meant to perform fairly quickly while providing a greater set of results than the CICD policy, intended for use in a dev environment.
11+
12+
* A superset of Developer CICD
13+
* Intended to run in a dev environment
14+
* No environmental / server related rules
15+
* No rules with high false positives
16+
* No timing attacks
17+
* No informational only rules
18+
* Can include longer running rules
19+
20+
For the list of scan rules included see the [Alert Tag: POLICY_DEV_STD](/alerttags/policy_dev_std/) page.
21+
22+
Return to [main scan policies page](/docs/desktop/addons/scan-policies/).
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
---
2+
# This page was generated from the add-on.
3+
title: QA Full Policy
4+
type: userguide
5+
weight: 7
6+
---
7+
8+
# QA Full Policy
9+
10+
A quality assurance focused policy, including a superset of the [QA standard](/docs/desktop/addons/scan-policies/policy-qa-std/) with a greater variety of potential findings with more environmental/server related rules, intended for use in a QA/Staging environment.
11+
12+
* Intended to run in a QA / Staging environment which is close to production
13+
* A superset of Developer Full (and QA Standard) but with more env / server rules enabled
14+
15+
For the list of scan rules included see the [Alert Tag: POLICY_QA_FULL](/alerttags/policy_qa_full/) page.
16+
17+
Return to [main scan policies page](/docs/desktop/addons/scan-policies/).
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
# This page was generated from the add-on.
3+
title: QA Standard Policy
4+
type: userguide
5+
weight: 6
6+
---
7+
8+
# QA Standard Policy
9+
10+
A quality assurance focused policy meant to perform fairly quickly while providing a greater set of results than developer policies, intended for use in a QA/staging environment.
11+
12+
* Intended to run in a QA / Staging environment which is close to production
13+
* A superset of Developer Standard but with important env / server rules enabled
14+
* Not env issues that should have been fixed by everyone
15+
16+
For the list of scan rules included see the [Alert Tag: POLICY_QA_STD](/alerttags/policy_qa_std/) page.
17+
18+
Return to [main scan policies page](/docs/desktop/addons/scan-policies/).

0 commit comments

Comments
 (0)