Projects with this topic
-
Rule Repository for GitLab SAST
Updated -
SAST Analyzer for detecting leaked secrets
Updated -
SAST Analyzer based on Semgrep
Updated -
GitLab's semgrep container image augmented with hundreds of additional Node.js/JavaScript/Typescript and Go rules from Semgrep's rule repository.
Updated -
Veracode Pipeline Scan Component This Veracode Pipeline Scan component runs the Veracode pipeline-scan as an action on any GitHub pipeline
The only pre-requisites is to have the application compiled/packaged according the Veracode Packaging Instructions here
About The pipeline-scan component is designed to be used in a CI/CD pipeline to submit a binary or source code zip to Veracode for security scanning.
For more information on Pipeline Scan, visit the Veracode Docs.
Updated -
Veracode upload and scan component. This component will run a Veracode static scan as Sandbox scan or as policy scan.
Updated -
Veracode SAST Packaging Component This component will run the Veracode CLI package command to prepare the repository for static code analysis. Generated artifacts will be stored behind the name veracode-artifacts.
Updated -
GitLab PipeIntel - Scan GitLab CI pipelines for security and correctness issues using OPA policies and ShellCheck
Updated -
Test project with: Language: Java - Package Manager: Maven
Updated -
Test project with: Language: Python - Package Manager: Pip
Updated -
Test project with: Language: Php - Package Manager: Composer
Updated -
A post-processor for computing the scope+offset fingerprint.
UpdatedUpdated -
This GitLab CI/CD pipeline implements a complete DevSecOps and GitOps workflow for a containerized application. It performs Dockerfile linting, builds and pushes images with Kaniko, runs Gitleaks and Trivy security scans, generates a CycloneDX SBOM, updates Kubernetes manifests through GitOps, performs DAST using OWASP ZAP and Nuclei, and generates a unified HTML security report with all scan results.
Updated -
Go package for implementing customized rulesets for SAST analyzers
Updated -
Go package for implementing shared vulnerability command interface for secure analyzers
Updated -
SAST Analyzer based on SpotBugs and Find Sec Bugs.
Updated -
SAST Analyzer for Phoenix Elixir projects based on sobelow
Updated -
GitLab Analyzer for Infrastructure as Code (IaC) projects that calls kics. This analyzer is written in Go using the command library shared by all analyzers.
Updated -
Go package for implementing shared vulnerability structs for secure analyzers
Updated -
SAST Analyzer for Salesforce Apex projects based on pmd
Updated