Skip to content

Implement SAST tool #1655

Open
Open
@JeanChristopheMorinPerso

Description

As part of the OpenSSF Best Practices badges, we need to add at least one SAST (Static Application Security Testing) tool.

We could take a look at https://semgrep.dev/ which provide both a free and "pro" version. The pro version is free for public open source repos. Alternatively, we could also look at https://codeql.github.com/ which is also free for open source repos.

Requirements:

Metadata

Metadata

Assignees

No one assigned

    Labels

    openssf-best-practiceshttps://www.bestpractices.dev/en/projects/8389

    Type

    No type

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions