Home

Security Scanning

Snyk

CLI Installation

1. npm install -g snyk
2. snyk auth # authenticate
3. snyk test ionic # scanning a public package as test

Scanning for Dependency issues

In project directory (level of package.json), node_modules are required

snyk test

Scan all projects (including nested package.json)

snyk test --all-projects

Scanning for code quality

Prerequisite: needs to be enabled in the dashboard - Settings/Snyk Code > Enable Snyk Code

snyk code test

SonarQube

Installation

Einfache Installation mit Docker und docker-compose.yml, dann im Browser anmelden, z.B. localhost:9000

version: "3.8"

services:
  sonarqube:
    image: sonarqube:community
    container_name: sonarqube
    depends_on:
      - db
    ports:
      - "9000:9000"
    environment:
      SONAR_JDBC_URL: jdbc:postgresql://db:5432/sonar
      SONAR_JDBC_USERNAME: sonar
      SONAR_JDBC_PASSWORD: sonar
    volumes:
      - sonarqube_data:/opt/sonarqube/data
      - sonarqube_extensions:/opt/sonarqube/extensions
      - sonarqube_logs:/opt/sonarqube/logs
    restart: unless-stopped

  db:
    image: postgres:15
    container_name: sonarqube_db
    environment:
      POSTGRES_USER: sonar
      POSTGRES_PASSWORD: sonar
      POSTGRES_DB: sonar
    volumes:
      - postgresql_data:/var/lib/postgresql/data
    restart: unless-stopped

volumes:
  sonarqube_data:
  sonarqube_extensions:
  sonarqube_logs:
  postgresql_data:

Im Browser:

# Login with username and password

# Click **"Create a local project"** → assign a project name/key (e.g., the name of your React repo)
# Analysis method: **"Locally"** → you will be shown a token + the corresponding scanner command
# The token is important – it is only displayed once, so it is best to save it somewhere
# SonarQube will then generate a ready-to-use command for you to copy-paste, which you execute in **Git Bash** within the project folder
# If the displayed command does not work with `sonar`, try `sonar-scanner-npm`:

sonar-scanner-npm \
  -Dsonar.host.url=http://localhost:9000 \
  -Dsonar.token=sqp_dein_token_hier \
  -Dsonar.projectKey=projektname
  
 # Note: the newly created directory ".scannerwork" should be included into .gitignore