Projects with this topic
-
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Updated -
Codequality jobs in pipelines https://docs.gitlab.com/ee/user/project/merge_requests/code_quality.html
Updated -
This GitLab CI/CD pipeline implements a complete DevSecOps and GitOps workflow for a containerized application. It performs Dockerfile linting, builds and pushes images with Kaniko, runs Gitleaks and Trivy security scans, generates a CycloneDX SBOM, updates Kubernetes manifests through GitOps, performs DAST using OWASP ZAP and Nuclei, and generates a unified HTML security report with all scan results.
Updated -
-
-
-
A project containing "vulnerable" code for testing GitLab SAST functionality.
Updated -
This project sets up Static Application Security Testing (SAST) in a GitLab CI/CD pipeline using two tools:
NJSScan → A security scanner specialized for JavaScript applications. It analyzes source code and flags insecure coding patterns and vulnerabilities.
Semgrep → A lightweight, multi-language static analysis tool that uses rulesets (such as p/javascript) to detect vulnerabilities, insecure practices, and style issues across different programming languages.
Updated -
-
-
Gitlab CI / CD templates for easy jobs and pipelines
Updated