Skip to content

GitLab CI

The ppee-cli image's entry point is ppee-cli itself, so it doesn't suit a job's image: (GitLab runs script lines in a shell). Use one of these two approaches.

Option A: ppee-cli in a helper image

Build a helper image with ppee-cli, jq and bash, next to the files from the Linux release archive. It needs glibc 2.38+, so use Debian 13 (Alpine's musl can't run it):

Dockerfile.ci
FROM debian:trixie-slim
RUN apt-get update && apt-get install -y --no-install-recommends jq && rm -rf /var/lib/apt/lists/*
COPY ppee-cli Suspicious.txt THIRD-PARTY-NOTICES.txt /opt/ppee/
ENV PATH="/opt/ppee:${PATH}"
.gitlab-ci.yml
stages: [build, inspect]

pe-gate:
  stage: inspect
  image: $CI_REGISTRY_IMAGE/ppee-ci:2.0.0
  needs: [build-windows]
  script:
    - ./ci/ppee-policy.sh --require-signature --require-hardening --forbid-wx
        --report ppee-report.jsonl dist/*.exe dist/*.dll
  artifacts:
    when: always
    paths: [ppee-report.jsonl]
    expire_in: 30 days

Option B: Docker-in-Docker

.gitlab-ci.yml
pe-gate:
  stage: inspect
  image: docker:27
  services: [docker:27-dind]
  variables:
    PPEE_IMAGE: $CI_REGISTRY_IMAGE/ppee-cli:2.0.0
  before_script:
    - apk add --no-cache bash jq
    - docker login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" "$CI_REGISTRY"
  script:
    - export PPEE_CLI="docker run --rm -v $PWD:$PWD:ro -w $PWD $PPEE_IMAGE"
    - ./ci/ppee-policy.sh --require-hardening --report ppee-report.jsonl dist/*.exe
  artifacts:
    when: always
    paths: [ppee-report.jsonl]

Docker-in-Docker volume paths

With docker:dind, $PWD inside the job must also exist for the dind daemon. That works with the default /builds share. If your runner uses a different layout, prefer Option A.

Merge request report

Turn the JSON Lines report into a readable file in the MR widget with artifacts:expose_as:

  after_script:
    - jq -r '"\(.path)\tsigned=\(.signed)\taslr=\(.aslr)\tcfg=\(.cfg)"' ppee-report.jsonl > ppee-summary.txt
  artifacts:
    expose_as: "PE inspection"
    paths: [ppee-summary.txt, ppee-report.jsonl]

References