Closed QaysarA closed 4 years ago
Tools that might be of interest that are offered by DOTS (DevOps Tool Suite) team:
Should ADR be part of this or implementation story?
Tooling used by VSP (thanks to Andrew Gunsch):
These are ruby specific and won't be applicable for our usecase.
Another tool to review: https://github.com/marketplace/actions/sast-scan
https://lgtm.com/ It was bought by GitHub and seems well integrated with GitHub. Free for opensource.
Matrix and recommendations documented in this spreadsheet
next: include resources from sw dev email thread and check out last week's town hall on security, also checkout infosec hub (do we want to share with infosec team?)
Summary of recommendations:
Bandit / Hawkeye
lgtm
Twistlock
Snyk
Codacy
After following up with team at dev sync this morning, took some follow-up actions and have these recommendations:
Recommend: Bandit / Hawkeye
Recommend: lgtm
Recommend: dependabot
Recommend: Twistlock
Noting a conversation has been scheduled with Sara Diaz from InfoSec for next week.
The purpose of this spike would be to research and document any security concerns that must be addressed for VANotify prior to going into production
- [ ] Do we need to add a Security policy, as recommended by github?Timebox - 3 Days
Security Toolbox Needs:
Other guiding principles
Notes:
Assumption: