This use case describes how to configure Xray to create a violation for a specific package version.
Step 1: Define a Security Policy for a Specific Package Version
Goal: Create a policy that applies a violation to a targeted package version.
- Navigate to Application > Xray > Watches & Policies.
- Click New Policy, enter a name, and select Security as the type.
- Configure the rule:
- Enter a rule name.
- Select Package Version as the rule type.
- Select Package Type and provide the package name. Take note that this field depends on the package type, the specific instructions are in the watermark of the field.
- Select a specific version or all versions of the package.
- Apply on Scope. Attach the Policy to a Watch.
- Save the policy.
Step 4: Review & Address the Violation
Goal: Investigate and resolve the issue before retrying package usage.
- Navigate to Xray > Scans List and select a specific resource.
- Go to the violations tab and review the violation.
- Take action:
- Upgrade the package to a secure version.
- Create an Ignore Rule on the violation if deemed a false positive.