brafdlog / caspion

Automated budget tracking from Israeli financial institutions
https://www.caspion.org
MIT License
195 stars 43 forks source link

Add snyk and maybe another security tool #267

Open baruchiro opened 3 years ago

baruchiro commented 3 years ago

Users asked to add Snyk to monitor vulnerabilities in 3rd packages.

Also, since I'm working on Checkmarx, maybe I can get a license.

If not, I still think about writing a Semmle Query to make sure the credentials not passing outside (to the log or monitoring system, for example) without sanitizing.

baruchiro commented 2 years ago

Sonarqube, Codacy