{"id":13717374,"url":"https://github.com/mercedes-benz/sechub","last_synced_at":"2025-05-16T00:09:06.707Z","repository":{"id":36963569,"uuid":"198238470","full_name":"mercedes-benz/sechub","owner":"mercedes-benz","description":"SecHub provides a central API to test software with different security tools.","archived":false,"fork":false,"pushed_at":"2025-05-13T05:52:39.000Z","size":67268,"stargazers_count":304,"open_issues_count":433,"forks_count":74,"subscribers_count":11,"default_branch":"develop","last_synced_at":"2025-05-13T06:33:28.770Z","etag":null,"topics":["api","appsec","build","client","continuous-integration","dast","k8s","orchestration","rest","sast","sdlc","secdevops","sechub","security","security-automation","security-scanner","security-testing","security-tools","server","vulnerability-scanners"],"latest_commit_sha":null,"homepage":"https://mercedes-benz.github.io/sechub/","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mercedes-benz.png","metadata":{"files":{"readme":"README.adoc","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2019-07-22T14:20:50.000Z","updated_at":"2025-05-13T05:52:36.000Z","dependencies_parsed_at":"2024-12-16T08:29:31.153Z","dependency_job_id":"b783948f-293d-4d80-bbfe-5efa852b5b0e","html_url":"https://github.com/mercedes-benz/sechub","commit_stats":null,"previous_names":[],"tags_count":197,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mercedes-benz%2Fsechub","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mercedes-benz%2Fsechub/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mercedes-benz%2Fsechub/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mercedes-benz%2Fsechub/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mercedes-benz","download_url":"https://codeload.github.com/mercedes-benz/sechub/tar.gz/refs/heads/develop","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254442855,"owners_count":22071878,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["api","appsec","build","client","continuous-integration","dast","k8s","orchestration","rest","sast","sdlc","secdevops","sechub","security","security-automation","security-scanner","security-testing","security-tools","server","vulnerability-scanners"],"created_at":"2024-08-03T00:01:21.383Z","updated_at":"2025-05-16T00:09:01.690Z","avatar_url":"https://github.com/mercedes-benz.png","language":"Java","funding_links":[],"categories":["Dependency intelligence","安全","Java"],"sub_categories":["SCA and SBOM"],"readme":"// SPDX-License-Identifier: MIT\n\n:toc:\n:toclevels: 4\n:toc-placement!:\n\n[link=https://github.com/mercedes-benz/sechub/actions?workflow=Java+%26+Go+CI]\nimage::https://github.com/mercedes-benz/sechub/workflows/Java%20\u0026%20Go%20CI/badge.svg[Build status]\n\ntoc::[]\n\n== SecHub\n\nimage::sechub-doc/src/docs/asciidoc/images/sechub-logo.png[\"Eugen\" - the SecHub mascot]\n\nThe free and open-source security platform SecHub, provides a central API to test software with different security tools.\nSecHub supports many free and open-source as well as proprietary security tools.\n\nSecHub features:\n\n* \u003c\u003cuser-perspective, Easy to use\u003e\u003e\n* \u003c\u003cuser-perspective, Scan using one API/client\u003e\u003e\n* \u003c\u003creport, Single human readable report\u003e\u003e\n* \u003c\u003cmark-false-positives, Mark findings as false-positive\u003e\u003e\n* \u003c\u003cmodules, Supports many security tools\u003e\u003e\n* \u003c\u003csechub-plugins, Provides IDE and text editor plugins\u003e\u003e\n\nSupported security tools:\n\n* \u003c\u003ccodescan, Code scanners\u003e\u003e\n* \u003c\u003ciacscan, IaC scanners\u003e\u003e\n* \u003c\u003csecretscan, Secrets scanners\u003e\u003e\n* \u003c\u003cwebscan, Web scanners\u003e\u003e\n* \u003c\u003cinfrascan, Infrastructure scanners\u003e\u003e\n* \u003c\u003clicensescan, License scanners\u003e\u003e\n\n=== Getting Started\n\n* https://mercedes-benz.github.io/sechub/latest/sechub-getting-started.html[SecHub Getting Started Guide]\n\n=== Installation\n\nPlease visit https://github.com/mercedes-benz/sechub/wiki/ for detailed information.\n\n=== Documentation\n\n* https://mercedes-benz.github.io/sechub/[Documentation]\n\n=== Introduction\n\nSecHub orchestrates various security and vulnerability scanners which can find potential vulnerabilities in sourcecode, binaries or web applications.\nThis enables security, development and operation teams to review and fix security issues. As a result, SecHub improves application security.\n\n.SecHub basic architecture overview\n[[figure-architecture-overview]]\n[ditaa]\n....\n                                                   +--------------+\n                                              +--\u003e | PDS + Tool A |\n                                              |    +--------------+\n+--------+                     +---------+    |\n| SecHub | ---- scan data ---\u003e | SecHub  | \u003c--+\n| Client | \u003c---- report ------ |   API   | \u003c--+\n+--------+                     +---------+    |\n                                              |    +--------------+\n                                              +--\u003e | PDS + Tool B |\n                                                   +--------------+\n....\n\nThe objective of SecHub is to help secure the software development lifecyle (SDLC) phases: development, deployment and maintenance. From the first written line of code to the application being in production. SecHub can be used to scan the software continuously.\n\nThe security tools are categorized into modules which are named after the security testing method they perform: `codeScan`, `licenseScan`, `secretScan`, `webScan` etc.\n\n[NOTE]\n--\nThe terms SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) are intentionally not used for the module names, because the designers feel those terms are vague and difficult to understand for non-security experts. On the other hand, security experts can easily map: `codeScan` to SAST and `webScan` to DAST.\n--\n\nBecause of the modules, the user only needs to understand what security testing a module performs, rather than to know what specific security tools are used for the actual scan. The user describes in a configuration file what module(s) to use. Or in other words, what security testing methods should be used to test the software with.\n\nTo start a scan, the user sends the configuration file to the SecHub server via API.\nFor ease of use SecHub offers a https://github.com/mercedes-benz/sechub/releases?q=%22client+version%22\u0026expanded=true[client] which calls the REST API for the user.\nThe SecHub client can be used manually or can be integrated into a continuous-integration build pipeline (see below figure).\n\n.CI/CD systems or users can scan with SecHub\n[[figure-cicd-user-sechub]]\n[ditaa]\n....\n/------\\\n| User | ----+\n\\------/     |            +--------+\n             +-- Scan --\u003e |        |\n                          | SecHub |\n             +-- Scan --\u003e |        |\n/-------\\    |            +--------+\n| CI/CD | ---+\n\\-------/\n....\n\nOn receiving the user request, SecHub creates a job, delegates it to one or more security tools, collects the results and converts all into a report.\nNext, the user can download the \u003c\u003creport,report\u003e\u003e in a JSON or HTML format.\n\n[[user-perspective]]\n=== User Perspective\n\nSecHub is designed to provide an efficient user workflow. The basic idea of SecHub is, that the user has to do as little as possible to execute a security scan.\nThe user has two options: +\na) to use the https://mercedes-benz.github.io/sechub/latest/sechub-restapi.html[REST API] directly +\nb) to use the https://mercedes-benz.github.io/sechub/latest/sechub-client.html[SecHub client]. +\nBoth can be integrated into a CI/CD pipeline.\n\nUsing the REST API requires several steps, which is fine if SecHub needs to be integrated into another software or platform.\n\nHowever, it is recommended to use the SecHub client. +\nThe SecHub client reduces the workflow to three steps:\n\n.SecHub three steps to scan\n[[figure-three-steps-to-scan]]\n[ditaa]\n....\n\n1. Create a configuration file  // (1)\n\n/------+\n| JSON |\n+------/\n\n2. Set Credentials // (2)\n\nexport SECHUB_USERID=myUserName…\n…\n\n3. Scan // (3)\n\n+--------+                 +--------+\n|        | ---- scan ----\u003e |        |\n| Client |                 | SecHub |\n|        | \u003c-- report ---- |        |\n+--------+                 +--------+\n....\n\n(1) Create a https://mercedes-benz.github.io/sechub/latest/sechub-client.html#section-client-configuration-file[SecHub configuration] file. This step only needs to be done the first time.\n\n(2) Provide the SecHub credentials. +\nExample: +\n`export SECHUB_USERID=myUserName` +\n`export SECHUB_APITOKEN=NTg5YSMkGRkM2Uy00NDJjLTkYTY4NjEXAMPLE` +\n`export SECHUB_SERVER=https://sechub.example.com:8443`\n\n(3) Scan using `sechub scan`\n\nOnce the scan is finished, the client returns a \u003c\u003creport,report\u003e\u003e.\n\nIf the client is used to scan asynchronously it will return a `jobUUID` which can be used to get the report:\n\n.Scan asynchronously\n[[figure-scan-asynchronously]]\n[ditaa]\n....\n\n1. Scan asynchronously // (1)\n\n+--------+                     +--------+\n|        | --- scanAsync ----\u003e |        |\n| Client |                     | SecHub |\n|        | \u003c--- jobUUID ------ |        |\n+--------+                     +--------+\n\n2. GetReport // (2)\n\n+--------+                     +--------+\n|        | --- getReport ----\u003e |        |\n| Client |                     | SecHub |\n|        | \u003c--- report ------- |        |\n+--------+                     +--------+\n....\n(1) Scan asynchronously using `sechub scanAsync`. +\n(2) Get report `sechub -jobUUID \u003cjobUUID\u003e getReport`.\n\nIn general, the `jobUUID` can be used to download the report again and again by different users and in different formats.\n\n[[report]]\n=== Report\n\nSecHub collects the scan results from various security tools and converts them into a unified reporting format called: SecHub Report. The advantage is that the user needs to learn only one report format. The json-report below shows how a report can look like:\n\n.JSON report example based on a scan of the https://securego.io/docs/rules/g101.html[G101], https://securego.io/docs/rules/g103.html[G103], https://securego.io/docs/rules/g304.html[G304] examples from GoSec.\n[[json-report]]\n[json]\n----\n{\n   \"result\": {\n      \"count\": 4,\n      \"findings\": [\n         {\n            \"id\": 1,\n            \"description\": \"Potential hardcoded credentials\",\n            \"name\": \"Potential hardcoded credentials\",\n            \"severity\": \"HIGH\",\n            \"code\": {\n               \"location\": \"examples/g101.go\",\n               \"line\": 7,\n               \"column\": 9,\n               \"source\": \"var password = \\\"f62e5bcda4fae4f82370da0c6f20697b8f8447ef\\\"\"\n            },\n            \"type\": \"codeScan\",\n            \"cweId\": 798\n         },\n         {\n            \"id\": 2,\n            \"description\": \"Use of unsafe calls should be audited\",\n            \"name\": \"Use of unsafe calls should be audited\",\n            \"severity\": \"MEDIUM\",\n            \"code\": {\n               \"location\": \"examples/g103.go\",\n               \"line\": 16,\n               \"column\": 21,\n               \"source\": \"intPtr = (*int)(unsafe.Pointer(addressHolder))\"\n            },\n            \"type\": \"codeScan\",\n            \"cweId\": 242\n         },\n         {\n            \"id\": 3,\n            \"description\": \"Use of unsafe calls should be audited\",\n            \"name\": \"Use of unsafe calls should be audited\",\n            \"severity\": \"MEDIUM\",\n            \"code\": {\n               \"location\": \"examples/g103.go\",\n               \"line\": 15,\n               \"column\": 30,\n               \"source\": \"addressHolder := uintptr(unsafe.Pointer(intPtr)) + unsafe.Sizeof(intArray[0])\"\n            },\n            \"type\": \"codeScan\",\n            \"cweId\": 242\n         },\n         {\n            \"id\": 4,\n            \"description\": \"Use of unsafe calls should be audited\",\n            \"name\": \"Use of unsafe calls should be audited\",\n            \"severity\": \"MEDIUM\",\n            \"code\": {\n               \"location\": \"examples/g103.go\",\n               \"line\": 15,\n               \"column\": 56,\n               \"source\": \"addressHolder := uintptr(unsafe.Pointer(intPtr)) + unsafe.Sizeof(intArray[0])\"\n            },\n            \"type\": \"codeScan\",\n            \"cweId\": 242\n         }\n      ]\n   },\n   \"messages\": [],\n   \"reportVersion\": \"1.0\",\n   \"trafficLight\": \"RED\",\n   \"status\": \"SUCCESS\",\n   \"jobUUID\": \"15a96c07-dcf3-4cbc-8d82-0acc9facd3a6\"\n}\n----\n\nThe report can be downloaded in two flavors: JSON and HTML. Both are human readable. The HTML report is self-contained and can be read in any browser.\nThe JSON format is machine readable and can be read by the \u003c\u003csechub-plugins, SecHub plugins\u003e\u003e.\n\n[[mark-false-positives]]\n==== Mark Findings as False-Positives\n\nThere are two major reasons for marking a security finding as false-positive: +\n- It is an actual false-positive. +\n- The finding is a false-positive in the context of the application. For example, the application is never deployed to be reachable from the internet.\n\nRegardless the reason, https://mercedes-benz.github.io/sechub/latest/sechub-client.html#section-client-false-positives-mark[SecHub supports marking findings as false-positives]. The marking of false-positives is a SecHub feature and is independent of the security tools used to scan.\n\n[[sechub-plugins]]\n==== SecHub Plugins\n\nThe SecHub Plugins improve the user experience by enabling the user to work directly with the SecHub report in the IDE or text editor.\n\nSecHub plugins exist for the following text editors and IDEs:\n\n* Plugin for https://marketplace.eclipse.org/content/sechub[Eclipse IDE] (https://github.com/mercedes-benz/sechub-plugin-eclipse[source code])\n* Plugin for https://github.com/mercedes-benz/sechub-plugin-intellij[IntelliJ platttform] (https://github.com/mercedes-benz/sechub-plugin-intellij[source code])\n* Plugin for https://open-vsx.org/extension/mercedes-benz/sechub[VSCode, VSCodium, Eclipse Theia] (https://github.com/mercedes-benz/sechub-plugin-vscode[source code])\n\nAll plugins are free and open-source software (FOSS) and can be installed directly from within the IDE or text editors.\n\n[[modules]]\n=== Modules\n\nSecurity tools are categorized into modules.\n\nEach module performs a different security testing method:\n\n* \u003c\u003ccodescan, `codeScan`\u003e\u003e - scans code or binaries for potential vulnerabilities (weaknesses). +\n  This includes SAST (static application security testing) and IaC (infrastructure as code).\n* \u003c\u003cinfrascan, `infraScan`\u003e\u003e - scans infrastructure for vulnerabilities.\n* \u003c\u003clicensescan, `licenseScan`\u003e\u003e - scans code or artifacts for license information.\n* \u003c\u003csecretscan, `secretScan`\u003e\u003e - scans code or artifacts for secrets (API tokens, certificates, passwords).\n* \u003c\u003cwebscan, `webScan`\u003e\u003e - scans a deployed web application for vulnerabilities. Also knows as DAST.\n\n[[codescan]]\n==== codeScan\n\n__Alias: Static application security testing (SAST), static code analysis__\n\n**Status: Productive**\n\nThe `codeScan` module scans source code or binary artifacts for potential vulnerabilities (weaknesses). To scan the user uploads the code or binary to SecHub. Once the files are uploaded, SecHub delegates the scan to one of many security tools.\n\nMore details: https://mercedes-benz.github.io/sechub/latest/sechub-client.html#sechub-config-code-scan\n\nPDS-Solutions: +\n- GoSec +\n- PMD +\n- FindSecurityBugs +\n- Bandit +\n- Checkmarx SAST (wrapper only) +\n- … and more\n\n[[iacscan]]\n==== iacScan\n\n__Alias: infrastructure-as-code (IaC) scan__\n\n**Status: Productive**\n\nThe `iacScan` module scans infrastructure source code for potential vulnerabilities (weaknesses). To scan the user uploads the code or binary to SecHub. Once the files are uploaded, SecHub delegates the scan to one of many security tools.\n\nMore details: https://mercedes-benz.github.io/sechub/latest/sechub-client.html#sechub-config-iac-scan\n\nPDS-Solutions: +\n- Kics +\n\n[[secretscan]]\n==== secretScan\n\n**Status: Productive**\n\nScans code or artifacts for secrets (API tokens, certificates, passwords).\n\nPDS-Solutions: +\n- Gitleaks\n\n[[webscan]]\n==== webScan\n\n__Alias: Dynamic application security testing (DAST)__\n\n**Status: Productive**\n\nThe `webScan` module scans running web applications for vulnerabilities. The only requirement is that the web application can be reached by SecHub via network.\n\nMore details: https://mercedes-benz.github.io/sechub/latest/sechub-client.html#web-scan\n\nPDS-Solutions: +\n- OWASP ZAP\n\n[[infrascan]]\n==== infraScan\n\n**Status: Experimental**\n\nThe `infraScan` scans systems in a network.\n\nMore details: https://mercedes-benz.github.io/sechub/latest/sechub-client.html#infrastructure-scan\n\n[[licensescan]]\n==== licenseScan\n\n**Status: Experimental**\n\nThe `licenseScan` module scans code or artifacts for license information.\n\nPDS-Solutions: +\n- Scancode +\n- Tern\n\n=== Architecture\n\nSecHub is designed to execute hundreds of scans. It can scale horizontally and vertically. It can run on bare-metal, virtual machines, kubernetes or in the cloud.\n\nThe smallest useful setup is: a single SecHub server and a single product delegation server (PDS). Those two components are enough to start scanning.\n\nFor a larger setup, the number of SecHub server instances can be increased. More PDS instances can be added. +\nThe only requirements to scale SecHub are: a PostgreSQL database and an object store or file share.\nSecHub and PDS instances use the PostgreSQL database to share information between instances.\nFor example, the job queue is kept in PostgreSQL. In addition,an object store or file share is necessary, so that all SecHub or PDS instances can store/read files.\n\nRegardless of the backend complexity, whether one SecHub server or many are used the \u003c\u003cuser-perspective, workflow for the user\u003e\u003e stays the same.\n\nFor more details about the architecture have a look at the architecture documentation: https://mercedes-benz.github.io/sechub/latest/sechub-architecture.html.\n\n=== Operations Perspective\n\nOne needs to configure the scan tools as well as manage users and projects. +\nFor details please check the https://mercedes-benz.github.io/sechub/latest/sechub-operations.html[operations guide].\n\n=== REST API\n\nAll user and administrative tasks can be done via https://mercedes-benz.github.io/sechub/latest/sechub-restapi.html[REST API]. SecHub is designed as a RESTful server.\n\n=== Contributing\n\nWe welcome any contributions.\nIf you want to contribute to this project, please read the link:CONTRIBUTING.md[contributing guide].\n\n=== Code of Conduct\n\nPlease read our https://github.com/mercedes-benz/foss/blob/master/CODE_OF_CONDUCT.md[Code of Conduct] as it is our base for interaction.\n\n=== License\n\nThis project is licensed under the link:LICENSE[MIT LICENSE].\n\n=== Provider Information\n\nPlease visit https://www.mercedes-benz-techinnovation.com/en/imprint/ for information on the provider.\n\nNotice: Before you use the program in productive use, please take all necessary precautions,\ne.g. testing and verifying the program with regard to your specific use.\nThe program was tested solely for our own use cases, which might differ from yours.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmercedes-benz%2Fsechub","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmercedes-benz%2Fsechub","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmercedes-benz%2Fsechub/lists"}