secureCodeBox / secureCodeBox/secureCodeBox

👨‍🔬 Cross check the OASIS SARIF format with the SCB generic DAST Finding Format

Open
#322 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement help wanted scanner
Dominant language
Go
Stars
988
Forks
184
Avg merge
1d 23h
Merged PRs (30d)
42

Description

The OASIS introduced a standard format for Static Analysis Results (SAST) which means a lot of SAST scanners recently adopted this as a common result format. Sadly as for now there is no comparable standard for DAST scanners. But maybe it's a good inspiration and starting point to cross check this standard with the generic secureCodeBox Findings Result Format used for all integrated DAST scanners by now.

Additional Context

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the secureCodeBox Findings Result Format documentation and the linked OASIS SARIF 2.1.0 specification, then use the SARIF Validator and referenced examples to compare the formats. Done should include a documented cross-check identifying how the formats align and where they differ.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.