baloise / open-source

Open Source @ Baloise
https://baloise.github.io/open-source
Creative Commons Attribution 4.0 International
22 stars 2 forks source link

DefectDojo - codeQL setup reflect? #327

Open MarkusTiede opened 2 years ago

MarkusTiede commented 2 years ago

SARIF compatible - interesting for @FT?

In February a new student joins us to continue with DefectDojo. He will contact us for any further cooperation.

MarkusTiede commented 2 years ago

Related issues

MarkusTiede commented 2 years ago

last information

Comparison of codeQL & SonarQube findings: no significant advantages of findings e.g. within code smells, security & co

SARIF is not (yet) supported as interchange format in sonarqube; we wrote a lightweight mapping

current idea / potential

Next exchange: Show & Tell of defectDojo instance tool?

MarkusTiede commented 2 years ago

Basic demonstration of neutral project "Juice Shop" : https://owasp.org/www-project-juice-shop/

MarkusTiede commented 2 years ago

Test instance is ready - contact @MrCode97 for additional information.