Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SCA to monitor dependencies #9

Open
htrgouvea opened this issue Nov 9, 2023 · 1 comment
Open

Add SCA to monitor dependencies #9

htrgouvea opened this issue Nov 9, 2023 · 1 comment

Comments

@htrgouvea
Copy link
Owner

Using an SCA (Software Composition Analysis) is super important for code integrity and application security. There is no SCA present in this repository yet, so I am opening this issue to plan this activity.

Reference: https://owasp.org/www-community/Component_Analysis

@andersonbosa
Copy link
Contributor

I have separated some tools that I believe we could use here, but we still need to evaluate Perl support. I also noticed that @htrgouvea started a new tool warn-cpan.

Some SCA tools free to our use here:

And if necessary in the future install a security gate we could use something like SecurityGoat

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants