⚠️ [Reminder: Action Needed] - 🚀 DevOps Shield - DevSecOps Automation - Apply AppSec Configurations #1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
PR#1 reminder updated on Fri, 24 Jan 2025 13:37:01 GMT
Apply recommended AppSec Configurations and the following DevSecOps workflows to ensure your repository is protected and remain secure.
This pull request introduces new workflow templates for integrating various security tools into the DevOps pipeline. These templates are designed to enhance application security by automating different types of security scans.
New workflow templates:
.github/workflows/devopsshield-cis-trivy.yml
: CIS - Trivy Container Image Scanning (Aqua Security).github/workflows/devopsshield-dast-zed-attack-proxy-zap.yml
: DAST - Zed Attack Proxy (ZAP) Penetration Testing (Checkmarx).github/workflows/devopsshield-sca-anchore-syft.yml
: SCA - Anchore Syft SBOM Scan (Anchore).github/workflows/devopsshield-ss-trufflehog.yml
: SS - TruffleHog Secret Scanning (Truffle Security Co.)