CLI workflow
The Cortex CLI does not provide a Supply Chain Attacks surface. The attack catalog, sidecar, and Block in CI action are tenant capabilities. The CLI is, however, the enforcement point for the policy that Block in CI generates: when the CLI performs the CI scan, the CLI evaluates findings against enabled policies, including the Block in CI policy that blocks the compromised package by name and version. A pipeline that attempts to introduce the blocked package is stopped at CI.
References
For how the CLI evaluates and enforces policies, see the CLI workflow in Unified Application Security Policies.
For the complete CLI reference, see Cortex CLI user guide.
Last updated
Was this helpful?
