Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add open source solution #52

Open
whitespots opened this issue Jun 30, 2022 · 0 comments
Open

Add open source solution #52

whitespots opened this issue Jun 30, 2022 · 0 comments
Labels
documentation Improvements or additions to documentation

Comments

@whitespots
Copy link

Gitlab security pipelines
Can be found: https://gitlab.com/whitespots-public/pipelines

With Security stage integrated into your team's pipelines, on, let's say, every release, Security stage is run and trigger Security pipelines to do the job. Security stage itself doesn't affect your time-to-market.
Security pipelines combine different types of security scanners in one "Security" stage.
Scans reports are sent to DefectDojo, where triage begins.

Pipelines integration instructions: https://www.youtube.com/watch?v=DLN1kNh_Ha0
SSDLC based approach is described here: https://www.youtube.com/watch?v=6FGV4OcrIB8
How to work with DefectDojo tutorial: https://www.youtube.com/watch?v=_uFOIf1BUwU

We are contributing to this project for about 2 years and are ready to share. Hope it worth being added here.

@Ali-Yazdani Ali-Yazdani added the documentation Improvements or additions to documentation label Jul 1, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

2 participants