Open jaysonmc opened 4 years ago
AVM list of AVM tools may be helpful
Security Code Scan
Web Application Testing
Docker Image Scan
Central Reporting tool
Security Dojo is used as our reporting tool. There are two reports currently leveraged:
docker-compose up
b. Startup OWASP ZAP from OdooSecurity and follow instruction in **README docker instructions.
c. After setting up the proxy, browse the Odoo Application.What remains
Requested by security
Relevant recurity controls
Before allowing production operations, perform a vulnerability scan of the solution environment and apply any required updates and patches. Where possible, integrate vulnerability remediation into the continuous development process. & Before allowing production operations, perform penetration testing and/or run-time vulnerability assessment against publicly accessible interfaces and apply any necessary corrective measures such as patches.