Implement AppSec-as-a-Service
- Dominant language
- JavaScript
- Stars
- 12
- Forks
- 8
- Avg merge
- 23h 38m
- Merged PRs (30d)
- 15
Description
Fortify is an offering from the IT security team to detect vulnerabilities in our code repo and report them to a centralized location for the IS team, per M-21-31 logging mandates. For GEAR, the implementation should be fairly straightforward by using Fortify's GitHub Action to automatically scan our pull requests and report the results. Here is [more information on the effort](https://ociso.gsa.gov/OCISO-Security/AppSec-aaS/).
Here are the steps to implementation:
- [ ] Fill out the [onboarding form](https://docs.google.com/forms/d/e/1FAIpQLScy5OEwzN7kx0cP75xuaE7tn3hoCwfcHE7fzvPw6mztVuTa6Q/viewform)
- [ ] Our team will need to gain access to the Fortify portal, which will include an API key to connect from our GitHub Actions (to authenticate)
- [ ] Review GitHub [installation instructions](https://github.com/GSA/ise-engagements/wiki/AppSec-Documentation) for Fortify from GSA's IT security team (IS)
- [ ] This will likely need to be documented in our System Security & Privacy Plan (SSPP). Also, our ISSO, Isaac, suggested that their may need to be a SN request ticket to document this change. He will get back to me based on his discussion with his team.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.