awslabs / awslabs/simple-code-scanning-pipeline
Review AWS-DevSecOps-Factory to see what tools could be used
- Dominant language
- TypeScript
- Stars
- 19
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/jonrau1/AWS-DevSecOps-Factory
Of particular note are the Security Tools
Secret detection: Detect-Secrets
Linting: TFLint, cfn-python-lint, Hadolint
Platform SAST: TFSec, Checkov, Cfn-nag, Cfripper, Polaris, sKan
Code-specific SAST: Bandit, Gosec
OSSec / License management: Snyk, Whitesource, OWASP DependencyCheck (via Dagda)
Vulnerability management: Trivy, Dagda
Anti-virus / anti-malware: Dagda, ClamAV
Operating System Assurance: DISA STIG, Amazon Inspector (for CIS Benchmarks)
Things we haven't looked at yet:
- TFLint
- Hadolint
- Cfripper
- Polaris
- sKan (K8s) - https://github.com/alcideio/skan
- Gosec
- Whitesource
- Dagda/OWASP DependencyCheck
- Trivy
- DISA STIG
- Amazon Inspector
Contributor guide
Research direction
Start by reviewing the linked AWS-DevSecOps-Factory project and the security-tools list in this issue, especially TFLint, Hadolint, Cfripper, Polaris, sKan, Gosec, Whitesource, Dagda, Trivy, DISA STIG, and Amazon Inspector. The issue does not name repository files or tests and does not define a concrete completion criterion, so the expected assessment and deliverable need clarification first.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, docker, kubernetes, terraform
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100