Closed RolaH1t closed 9 months ago
Source in Catena-X Confluence and Expert Contacts here(Source only accessible for Catena-X Consortia members in current transition phase).
[ ] Threat Modelling Analysis results Analysis completed (operations excluded):
Artifact Repository:
Prime Contacts:
[ ] Static Application Security Testing (SAST)
Best Practise:
[ ] Dynamic Application Security Testing (DAST) incl API testing (if applicable)
[ ] Secret scanning Scan executed centrally by SEC team and ZERO valid findings
Prime Contact:
[ ] Software Composition Analysis (SCA) Dependencies must be scanned with Veracode tool with regards to vulnerability
[ ] Container Scan conducted All containers in GitHub Packages must be scanned
[ ] Infrastructure as Code IaC code must be scanned.
This is the test comment.
https://owasp.org/Top10/
I am not able to change the status and check the checkbox.
Release Security 23.12
Source in Catena-X Confluence and Expert Contacts here(Source only accessible for Catena-X Consortia members in current transition phase).
[ ] Threat Modelling Analysis results Analysis completed (operations excluded):
Artifact Repository:
Prime Contacts:
[ ] Static Application Security Testing (SAST)
Best Practise:
Artifact Repository:
Prime Contacts:
[ ] Dynamic Application Security Testing (DAST) incl API testing (if applicable)
Best Practise:
Artifact Repository:
Prime Contacts:
[ ] Secret scanning Scan executed centrally by SEC team and ZERO valid findings
Artifact Repository:
Best Practise:
Prime Contact:
[ ] Software Composition Analysis (SCA) Dependencies must be scanned with Veracode tool with regards to vulnerability
Best Practise:
Artifact Repository:
Prime Contacts:
[ ] Container Scan conducted All containers in GitHub Packages must be scanned
Best Practise:
Artifact Repository:
Prime Contacts:
[ ] Infrastructure as Code IaC code must be scanned.
Best Practise:
Artifact Repository:
Prime Contacts: