checkmarx-ltd / cx-flow
Checkmarx Scan and Result Orchestration
☆88Updated this week
Related projects ⓘ
Alternatives and complementary repositories for cx-flow
- Checkmarx Python SDK☆27Updated this week
- Useful tools and Examples made by Checkmarx Professional Services☆38Updated last month
- Checkmarx application security testing (AST) GitHub action☆16Updated this week
- Checkmarx CxFlow GitHub Action with SARIF output☆52Updated last month
- A CLI project wrapping application security testing (AST) APIs☆41Updated this week
- Software Component Verification Standard (SCVS)☆134Updated 6 months ago
- Exports vulnerability scan data from the Checkmarx SAST platform for use in analytical tools.☆20Updated this week
- Container Security Verification Standard☆57Updated 5 years ago
- SonarQube plugin for identifying hardcoded secrets, such as passwords, API keys, AWS credentials, etc..☆100Updated 11 months ago
- Node application to help managing Maturity Models like the ones created by BSIMM and OpenSAMM☆187Updated 6 years ago
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆81Updated this week
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆147Updated 4 years ago
- Zap baseline scanner in Docker with authentication☆104Updated 5 months ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning …☆41Updated 4 months ago
- Checkmarx Health Monitor☆18Updated last year
- threatspec - continuous threat modeling, through code☆332Updated 3 years ago
- Github action to run dependency check☆71Updated 3 months ago
- Evaluation Framework for Dependency Analysis (EFDA)☆42Updated 2 years ago
- Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependenci…☆805Updated last year
- Java libraries for working with available vulnerability data sources (GitHub Security Advisories, NVD, EPSS, CISA Known Exploited Vulnera…☆121Updated last week
- A utility to (re-)import findings and language data into DefectDojo☆42Updated last month
- Awesome resources about Security in Kubernetes☆40Updated last year
- OWASP Foundation Web Respository☆54Updated last year
- Frontend UI for Dependency-Track☆105Updated last week
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆363Updated this week
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆509Updated this week
- Python API library for DefectDojo☆40Updated last year
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use …☆61Updated 5 months ago