https://github.com/broadinstitute/dsp-appsec-infrastructure-apps
This repository hosts DSP AppSec internal infrastructure apps deployed in GKE.
https://github.com/broadinstitute/dsp-appsec-infrastructure-apps
application-security appsec appsec-tools appsecurity cis-scanner devsecops secure-development security security-automation security-scan security-scanner security-tools zap-scanner
Last synced: 5 months ago
JSON representation
This repository hosts DSP AppSec internal infrastructure apps deployed in GKE.
- Host: GitHub
- URL: https://github.com/broadinstitute/dsp-appsec-infrastructure-apps
- Owner: broadinstitute
- License: bsd-3-clause
- Created: 2020-03-02T22:59:35.000Z (about 5 years ago)
- Default Branch: master
- Last Pushed: 2024-09-04T19:29:17.000Z (9 months ago)
- Last Synced: 2024-09-07T01:36:32.722Z (9 months ago)
- Topics: application-security, appsec, appsec-tools, appsecurity, cis-scanner, devsecops, secure-development, security, security-automation, security-scan, security-scanner, security-tools, zap-scanner
- Language: Python
- Homepage: https://broadinstitute.github.io/dsp-appsec-infrastructure-apps/
- Size: 13 MB
- Stars: 6
- Watchers: 5
- Forks: 1
- Open Issues: 3
-
Metadata Files:
- Readme: README.md
- Contributing: CONTRIBUTING.md
- License: LICENSE
- Code of conduct: CODE_OF_CONDUCT.md
- Security: security-controls/Dockerfile
Awesome Lists containing this project
README
# DSP AppSec Infrastructure Apps
[](https://sonarcloud.io/summary/new_code?id=broadinstitute_dsp-appsec-infrastructure-apps)
This repository hosts DSP AppSec internal infrastructure deployed in GCP Kubernetes.
Check the documentation in this [link](https://broadinstitute.github.io/dsp-appsec-infrastructure-apps/).### Apps
- [SDARQ](sdarq) - `SDARQ` is a coordination platform to guide both developers and appsec professionals through an SDLC and provide interfaces into various tools and bind them. Learn more in this [link](https://broadinstitute.github.io/dsp-appsec-infrastructure-apps/docs/sdarq).
Tools integrated with SDARQ:
- [CIS Scanner](cis) - Security scanner that assess security posture of GCP projects.
- [Automated ZAP Scanner](zap) - Scripts running in GKE as Cronjobs to scan a specific list of endpoints.
- [DefectDojo](defectdojo)
- [CodeDx](codedx)### Questions
`[email protected]`