OWASP / www-project-devsecops-guideline

The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use in this matter. Also, the project is trying to help us promote the shift-left security culture in our development process.
https://owasp.org/www-project-devsecops-guideline/
61 stars 30 forks source link

ZAP is now Checkmarx #32

Open sydseter opened 1 month ago

sydseter commented 1 month ago

ZAP should probably be removed from the guidelines: https://owasp.org/www-project-devsecops-guideline/latest/02b-Dynamic-Application-Security-Testing

https://github.com/OWASP/www-project-developer-guide/issues/282

sydseter commented 1 month ago

This seems to be a more complete list of tools: https://owasp.org/www-community/Vulnerability_Scanning_Tools

kingthorin commented 1 month ago

The text on the linked page is still correct