Projects with this topic
-
An example project staged to demonstrate the usage of Veracode's SAST scanning tools within CI/CD pipeline.
UpdatedUpdated -
Veracode upload and scan component. This component will run a Veracode static scan as Sandbox scan or as policy scan.
Updated -
Veracode Pipeline Scan Component This Veracode Pipeline Scan component runs the Veracode pipeline-scan as an action on any GitHub pipeline
The only pre-requisites is to have the application compiled/packaged according the Veracode Packaging Instructions here
About The pipeline-scan component is designed to be used in a CI/CD pipeline to submit a binary or source code zip to Veracode for security scanning.
For more information on Pipeline Scan, visit the Veracode Docs.
Updated -
Veracode SAST Packaging Component This component will run the Veracode CLI package command to prepare the repository for static code analysis. Generated artifacts will be stored behind the name veracode-artifacts.
Updated -
Veracode Fix for GitLab
Updated -
The uConsole Repo Scan Reporter is a small local workflow for scanning Git repositories with Semgrep and Gitleaks, sending the scanner evidence to a custom Fabric pattern, and optionally publishing the resulting security triage report to Atlassian Confluence. The goal is to provide a lightweight, repeatable workflow for application security engineers, security-minded developers, and field testers who want a local-first way to produce useful security review notes from open source or internal repositories.
Updated -
A post-processor for computing the scope+offset fingerprint.
UpdatedUpdated -
Gitlab CI / CD templates for easy jobs and pipelines
Updated -
SAST Analyzer based on SpotBugs and Find Sec Bugs.
Updated -
SAST Analyzer for Phoenix Elixir projects based on sobelow
Updated -
Shiftleft CLI auto builder for Docker Hub
Updated -
SAST Analyzer based on Semgrep
Updated -
Security scans as pipeline jobs. SAST, Secret Detection, etc.
Updated -
SAST Analyzer for detecting leaked secrets
Updated -
Collection of shell scripts packaged with SAST analyzers to enable post-analyzer integrations.
Updated -
This repository is part of a master thesis featured on https://scrap.tantemalkah.at and highlights the evaluation of currently maintained F/LOSS static analysis tools for PHP.
Updated -
Test project with: Language: Scala - Package Manager: Sbt
Updated -
Rule Repository for GitLab SAST
Updated -
This project is for free tier self hosted GitLab users who are running the SAST and Password Detection scrips and looking for a way to add them visibly to the merge request.
Updated