-
Updated
Dec 30, 2021 - Python
devsecops
Here are 374 public repositories matching this topic...
config validation
Is your feature request related to a problem? Please describe.
It would be nice if gitleaks had a validate
command that would validate examples found in the config rules. Introducing such a feature would speed up rule development and help with debugging.
Describe the solution you'd like
example
entry in the rules
tables
ex:
[[rules]]
id = "discord-client-secret"
des
-
Updated
Dec 29, 2021 - Shell
-
Updated
Jan 1, 2022 - Go
CKV_AWS_116 flags any Lambda without a dead-letter queue (DLQ) enabled. There's no explanation given for this recommendation:
AWS has retired it from their Foundational Security Best Practices controls on August 31, 2021:
https://docs.aws.amazon.com/securityhub/latest/userguide/securi
-
Updated
Dec 28, 2021 - Python
-
Updated
Dec 14, 2021
- terrascan version: 1.9.0
- terraform version: 1.0.1
Enhancement Request
Other security scanning tools (e.g. checkov
and tfsec
) have a --soft-fail
flag or equivalent option that allows you to always exit with 0 status.
Extremely useful when running the tool without halting a pipeline for example.
I currently use a workaround, but something more concrete would be very desira
-
Updated
Nov 12, 2021 - Python
Slack us first!
Hello. I write about problem here:
https://owasp.slack.com/archives/C2P5BA8MN/p1624892081234100
Be informative
As additional into slack I find the same behaviour with Risk Accepted findings. Into Metrics I see 0 Risk Accepted findings, but I have 1 Risk Accepted finding
Bug description
No error. Metrics into product, or metrics dushboard has incorrect info
-
Updated
Dec 29, 2021 - CSS
-
Updated
Dec 28, 2021 - Go
-
Updated
Dec 15, 2021 - Python
-
Updated
Aug 6, 2021 - HTML
-
Updated
Dec 24, 2021 - Go
-
Updated
Dec 21, 2021
-
Updated
Dec 30, 2021 - Go
The current swagger definition is autogenerated. The automatically generated definitions rely on reflection and annotations to create the documentation. The reflection capabilities are poor at best and lead to missing API parameters. Annotations can help in some cases, but the only fix for Swagger is to create individual POJOs for every possible request. This will lead to unnecessary large number
-
Updated
May 18, 2021 - CSS
-
Updated
Dec 23, 2021 - Python
-
Updated
Dec 31, 2021 - TypeScript
-
Updated
Sep 22, 2021
-
Updated
Dec 6, 2021 - Go
-
Updated
Dec 29, 2021 - HCL
I want to view the log, but I cannot find the location of the log file. How to customize the log path?
-
Updated
Nov 24, 2021 - Dockerfile
Hi,
It would be interesting to have those new rules integrated in ChopChop, see : https://github.com/nnposter/nndefaccts/blob/master/http-default-accounts-fingerprints-nndefaccts.lua
Document ZAP

Community Powered Security
January 07, 2022 • Virtual
Improve this page
Add a description, image, and links to the devsecops topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the devsecops topic, visit your repo's landing page and select "manage topics."
Description
we have NPM7 generated package-lock.json with lockFileVersion = 2. Now when we scan Node.js project using Trivy filesystem scan, Trivy does not find out packages from package-lock.json.
It is working with lockFileVersion = 1
What did you expect to happen?
It should find out packages in package-lock.json
What happened instead?
It did not find out packages from pack