KBAISE/ for lovable
Library
Docs

Scan your projects for vulnerabilities with Wiz

about 15 minBuildingchecked 13h agoOfficial page
The short version

You can automatically check your Lovable projects for security problems like outdated software parts and risky code. This helps you find and fix issues before your project goes live.

Anyone who wants to make sure their Lovable project is secure before launching or after making changes needs this.

Do this, in order

  1. 1

    Log in to the Wiz portal.

    This is the first step to setting up the connection between Wiz and Lovable.

  2. 2

    Go to the 'Create a new Lovable integration deployment' page in Wiz, give it a name, and click 'Add integration'.

    This creates a special setup in Wiz that allows Lovable to connect and scan your projects.

  3. 3

    Copy the 'Client ID' and 'Client Secret' shown after adding the integration, and save them securely.

    These are like a username and password that Lovable will use to prove it's allowed to talk to Wiz. The secret is only shown once.

  4. 4

    In Lovable, go to 'Connectors' and select 'Wiz', then click 'Add connection'.

    This starts the process of linking your Lovable workspace to your Wiz account.

  5. 5

    Enter a display name for the connection, paste the 'Client ID' and 'Client Secret' you copied from Wiz.

    This provides Lovable with the necessary details to authenticate with your Wiz account.

  6. 6

    Check the 'Token URL' in 'Advanced settings'; it usually defaults to Cognito, but change it to Auth0 if your Wiz administrator confirms that's what your Wiz account uses.

    This ensures Lovable uses the correct method to securely communicate with your specific Wiz setup.

  7. 7

    Optionally, in 'Advanced settings', enter a comma-separated list of Wiz policy names if you want specific security rules to run during scans; otherwise, leave it blank for default policies.

    This allows you to customize which security checks Wiz performs on your project.

  8. 8

    To share the connection with others in your workspace, click 'Share with others' and invite members or the entire workspace.

    This makes sure that all relevant team members can benefit from Wiz security scanning in their projects.

  9. 9

    Click 'Connect' to finalize the setup.

    This completes the connection, and Wiz scanning will automatically be included in future security scans for projects with access to this connection.

  10. 10

    To see the scan results, open your project in Lovable, go to the 'Security' tab, and look for findings with a 'Wiz' badge.

    This is where you can review the security issues Wiz found, their details, and how to fix them.

  11. 11

    Click on a finding to see its details, including what's affected, where it is, a description, and advice on how to fix it.

    Understanding the details helps you address the specific security problem effectively.

  12. 12

    Update your project's code or dependencies based on the advice provided by Wiz.

    This is how you fix the identified security vulnerabilities.

  13. 13

    Run a new security scan to confirm that the issues you fixed are no longer present.

    This verifies that your changes have successfully resolved the security problems.

Paste this into your project

Hey Lovable, I want to set up Wiz security scanning for my project. I've already created a Lovable integration deployment in Wiz and have my Client ID and Client Secret. Can you guide me through connecting Wiz in Lovable, including setting the correct Token URL and sharing it with my team?

Words decoded

Vulnerabilities
Weaknesses or flaws in software that could be exploited by attackers to cause harm.
CVEs
Common Vulnerabilities and Exposures; a list of publicly known information security vulnerabilities.
Software composition analysis (SCA)
A method to check all the pre-built software components (like libraries or packages) your project uses to see if any have known security flaws.
Dependency tree
A list showing all the software components your project relies on, and what those components rely on, and so on.
Static application security testing (SAST)
A method to analyze your project's own code without running it, looking for security problems like secrets accidentally left in the code or unsafe ways of doing things.
Hardcoded secrets
Sensitive information like passwords or keys that are directly written into the code, which is risky because they can be easily found.
Software bill of materials (SBOM)
A complete list of all the software components and libraries used in a project, like a list of ingredients for a recipe.
Remediation guidance
Advice or instructions on how to fix a problem or reduce a risk.
OAuth authentication endpoint
A specific web address that systems use to securely verify who you are and if you're allowed to access something, without sharing your password directly.
Cognito / Auth0
These are services that help manage user logins and security for applications.
CI/CD scan policies
Rules or guidelines that define what security checks should be performed automatically as part of the software development and release process.

Where people get stuck

  • Forgetting to securely store the Client Secret, as it's only shown once and acts like a password.
  • Not inviting the entire workspace to the Wiz connection, which means other projects won't benefit from the scans.
  • Using the wrong 'Token URL' (Cognito vs. Auth0), which will prevent Lovable from connecting to Wiz.
  • Entering incorrect or non-existent policy names in 'CI/CD scan policies', which will cause the Wiz scan to fail.
  • Not running a new scan after fixing issues, which means the Security view won't update to show the fix.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.