Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DefectDojo - codeQL setup reflect? #327

Open
MarkusTiede opened this issue Mar 10, 2022 · 4 comments
Open

DefectDojo - codeQL setup reflect? #327

MarkusTiede opened this issue Mar 10, 2022 · 4 comments
Assignees
Labels
use https://baloise.github.io/open-source/docs/md/goals/uplift.html#use

Comments

@MarkusTiede
Copy link
Member

SARIF compatible - interesting for @ft?

In February a new student joins us to continue with DefectDojo. He will contact us for any further cooperation.

@MarkusTiede MarkusTiede added the use https://baloise.github.io/open-source/docs/md/goals/uplift.html#use label Mar 10, 2022
@MarkusTiede
Copy link
Member Author

MarkusTiede commented Mar 10, 2022

last information

Comparison of codeQL & SonarQube findings: no significant advantages of findings e.g. within code smells, security & co

SARIF is not (yet) supported as interchange format in sonarqube; we wrote a lightweight mapping

current idea / potential

  • write (our own) codeQL queries (@arburk)
  • aggregated view of findings e.g. within defectDojo (@marcellobellini and FT)
  • sequence / ordering / clustering of items currently unknown
    • configurable "flight-altitude"
      • e.g. C-level
      • Security community
      • developer (e.g. also showing up technical debt)

Next exchange: Show & Tell of defectDojo instance tool?

@MarkusTiede
Copy link
Member Author

Basic demonstration of neutral project "Juice Shop" : https://owasp.org/www-project-juice-shop/

@MarkusTiede
Copy link
Member Author

Test instance is ready - contact @MrCode97 for additional information.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
use https://baloise.github.io/open-source/docs/md/goals/uplift.html#use
Projects
None yet
Development

No branches or pull requests

2 participants