sentenz / devops

A service for DevOps operations.
Apache License 2.0
1 stars 3 forks source link

Add `semgrep` tp find reachable dependency vulnerabilities in code #48

Open sentenz opened 1 year ago

sentenz commented 1 year ago

Semgrep is a fast, open-source, static analysis engine for finding bugs, detecting vulnerabilities in third-party dependencies, and enforcing code standards.