matt-lebl / uvic-marketplace

5 stars 0 forks source link

ST: Setup static code analysis #173

Open Broondoon opened 3 months ago

Broondoon commented 3 months ago

Our pipeline has room for security testing tools such as Sonarqube and Bandit.

Decide whether both are needed, and set up to run tests and generate reports on our system.

Broondoon commented 3 months ago

Useful resource for future work: https://docs.sonarsource.com/sonarqube/latest/setup-and-upgrade/deploy-on-kubernetes/sonarqube/

Broondoon commented 3 months ago

@ivandenys Assigned to you, based on what you said from our meeting.

matt-lebl commented 2 months ago

@ivandenys you mentioned that sonarqube is paid—i think jetbrains qodana has a community version that's free. maybe something to look into? https://www.jetbrains.com/qodana/