-
Updated
Apr 10, 2021 - Python
devsecops
Here are 267 public repositories matching this topic...
-
Updated
Mar 31, 2021 - Python
-
Updated
Jan 12, 2021
-
Updated
Apr 3, 2021 - CSS
Safety parser relly on a DB of vulnerabilities with CVE infos. This databases is upgraded/modified every month.
This pb is that our unit tests relly on this changing file.
We need to do one of these options:
- fix the DB file for unit tests
- remove completely this feature and wait that the CVE info come from the report (I pushed a pull request upstream to have CVE directly in the JSON rep
-
Updated
Apr 16, 2021 - Python
- terrascan version: 1.2
- Operating System: all
Description
When scanning a repo, if the severity field is not all caps (HIGH|MEDIUM|LOW), when violations are output, the color of the severity field does not show up. The compare should be case-insensitive, OR we can normalize the severity field.
What I Did
terrascan scan -d [dir]
-
Updated
Feb 15, 2021 - HTML
-
Updated
Oct 17, 2020 - CSS
Current Behavior:
When viewing vulns in the Audit Vulnerabilities tab. the Analysis column appears to contain code (enum?) names, e.g. NOT_SET, FALSE_POSITIVE. This problem also occurs in Policy Violations tab.
Steps to Reproduce:
Open the Audit Vulnerabilities tab.
Expected Behavior:
The Analysis column contains language specific analysis values, e.g. Not Set, False Positive
-
Updated
Apr 9, 2021 - Python
-
Updated
Apr 4, 2021
-
Updated
Mar 31, 2021 - Go
-
Updated
Apr 15, 2021 - HCL
Document ZAP
-
Updated
Dec 9, 2020 - HCL
-
Updated
Mar 8, 2021 - Dockerfile
-
Updated
Jun 1, 2020 - Python
-
Updated
Apr 2, 2021
-
Updated
Apr 14, 2021 - Java
As developers of the securecCodeBox we want to release new scanner versions more frequently.
To enable us to update more frequently we need some kind of notification for the new scanner version.
One possible solution could be that GitHub provides Atom feeds for releases of repositories.
See: https://www.ronaldsvilcins.com/2020/03/26/rss-feeds-for-your-github-releases-tags-and-activity/
A Pro
-
Updated
Aug 7, 2020
-
Updated
Jul 10, 2020 - Dockerfile
It will be a fun exercise to make scan work for mono repos such as https://github.com/swapnil-linux/spring-boot-examples
In theory, this can be achieved using a bit of bash with the new scan AppImage.
Hi,
It would be interesting to have those new rules integrated in ChopChop, see : https://github.com/nnposter/nndefaccts/blob/master/http-default-accounts-fingerprints-nndefaccts.lua
-
Updated
Apr 16, 2021 - Go
Improve this page
Add a description, image, and links to the devsecops topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the devsecops topic, visit your repo's landing page and select "manage topics."


Describe the bug
CKV_GCP_14 requires a backup configuration, but it does not take into consideration read replicas.
A read replica cannot have backup enabled in GCP.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
Read replicas