GitLab CI¶
The ppee-cli image's entry point is ppee-cli itself, so it doesn't suit a job's image: (GitLab runs script lines in a shell). Use one of these two approaches.
Option A: ppee-cli in a helper image¶
Build a helper image with ppee-cli, jq and bash, next to the files from the Linux release archive. It needs glibc 2.38+, so use Debian 13 (Alpine's musl can't run it):
Dockerfile.ci
FROM debian:trixie-slim
RUN apt-get update && apt-get install -y --no-install-recommends jq && rm -rf /var/lib/apt/lists/*
COPY ppee-cli Suspicious.txt THIRD-PARTY-NOTICES.txt /opt/ppee/
ENV PATH="/opt/ppee:${PATH}"
.gitlab-ci.yml
stages: [build, inspect]
pe-gate:
stage: inspect
image: $CI_REGISTRY_IMAGE/ppee-ci:2.0.0
needs: [build-windows]
script:
- ./ci/ppee-policy.sh --require-signature --require-hardening --forbid-wx
--report ppee-report.jsonl dist/*.exe dist/*.dll
artifacts:
when: always
paths: [ppee-report.jsonl]
expire_in: 30 days
Option B: Docker-in-Docker¶
.gitlab-ci.yml
pe-gate:
stage: inspect
image: docker:27
services: [docker:27-dind]
variables:
PPEE_IMAGE: $CI_REGISTRY_IMAGE/ppee-cli:2.0.0
before_script:
- apk add --no-cache bash jq
- docker login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" "$CI_REGISTRY"
script:
- export PPEE_CLI="docker run --rm -v $PWD:$PWD:ro -w $PWD $PPEE_IMAGE"
- ./ci/ppee-policy.sh --require-hardening --report ppee-report.jsonl dist/*.exe
artifacts:
when: always
paths: [ppee-report.jsonl]
Docker-in-Docker volume paths
With docker:dind, $PWD inside the job must also exist for the dind daemon. That works with the default /builds share. If your runner uses a different layout, prefer Option A.
Merge request report¶
Turn the JSON Lines report into a readable file in the MR widget with artifacts:expose_as:
after_script:
- jq -r '"\(.path)\tsigned=\(.signed)\taslr=\(.aslr)\tcfg=\(.cfg)"' ppee-report.jsonl > ppee-summary.txt
artifacts:
expose_as: "PE inspection"
paths: [ppee-summary.txt, ppee-report.jsonl]
References¶
- CI/CD YAML syntax reference (GitLab): every key used in the pipelines on this page.