This repository shows you how to build up an enterprise-ready DevSecOps Pipeline with GitHub. It utilises the SCA, SAST, DAST scans with different open source tools such as snyk, dependency check, trivy and Github advanced security configurations such as Dependabot with specific and general rules, CodeQL analysis , Secrets scan, secret protection, push protection and othersfor creating a secure CI and CD workflow during build into main branch on every change.
forked from romanoroth/GitHubDevSecOps
-
Notifications
You must be signed in to change notification settings - Fork 0
This repository shows you how to build up an enterprise-ready DevSecOps Pipeline with GitHub
License
Poatan222/DevSecOps-Pipeline
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
This repository shows you how to build up an enterprise-ready DevSecOps Pipeline with GitHub
Resources
License
Stars
Watchers
Forks
Releases
No releases published
Languages
- Java 96.1%
- Dockerfile 3.9%