The Wayback Machine - https://web.archive.org/web/20220723115536/https://github.com/topics/devsecops
Skip to content
#

devsecops

Here are 491 public repositories matching this topic...

computeralex92
computeralex92 commented Jul 21, 2022

Description

If using the new license check feature the exit code is after every run 0, regardless of the option --exit-code 1 etc

What did you expect to happen?

The check is working in the same way like the vuln type of check, so I can define that e.g. a CRITICAL or HIGH risk license exits with exitcode 1.
That would allow to prevent the usage of risky licenses in a company e

kind/bug help wanted good first issue
Mobile-Security-Framework-MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
  • Updated Jul 17, 2022
  • JavaScript
zricethezav
zricethezav commented Dec 3, 2021

Is your feature request related to a problem? Please describe.
It would be nice if gitleaks had a validate command that would validate examples found in the config rules. Introducing such a feature would speed up rule development and help with debugging.

Describe the solution you'd like
example entry in the rules tables
ex:

[[rules]]
id = "discord-client-secret"
des
enhancement help wanted good first issue
Scanners-Box
prowler

Prowler is an Open Source security tool to perform AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains more than 240 controls covering CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS and custom security frameworks.
  • Updated Jul 22, 2022
  • Shell
terrascan
adegoodyer
adegoodyer commented Aug 11, 2021
  • terrascan version: 1.9.0
  • terraform version: 1.0.1

Enhancement Request

Other security scanning tools (e.g. checkov and tfsec) have a --soft-fail flag or equivalent option that allows you to always exit with 0 status.

Extremely useful when running the tool without halting a pipeline for example.

I currently use a workaround, but something more concrete would be very desira

ThreatMapper
dependency-track
agateau-gg
agateau-gg commented Jul 20, 2022

GitGuardian Shield Version

  • 1.12.0

Command executed

ggshield secret scan pre-receive

Describe the bug

When ggshield is used in pre-receive mode, ggshield cache should be skipped as it's not actionable after. This can also avoid trying to save on a read-only file-system.

Expected behavior

ggshield secret scan pre-receive should not save its cache.

Technic

bug good first issue status:: confirmed

Improve this page

Add a description, image, and links to the devsecops topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the devsecops topic, visit your repo's landing page and select "manage topics."

Learn more