SUSE / BCI-tests

This repository contains the tests for the SUSE Base Container Images
Apache License 2.0
8 stars 21 forks source link

Add blackduck security scanner #54

Open evrardjp opened 3 years ago

evrardjp commented 3 years ago

We are already testing with security scanners, but some ISVs mentioned the fact that they are using blackduck. It might be a good idea to test our deliverable with that security scanner too.

See also: https://github.com/blackducksoftware/synopsys-detect

dcermak commented 3 years ago

I have looked around the interwebs, but it does not appear like blackduck is offering a free tier. So if we want to use it, we'd have to grab some $$