devtron
devtron copied to clipboard
Software Composition Analysis (SCA) via Devtron
Summary
We are considering using Devtron as an SCA tool, which can scan code/images and notify us of any vulnerabilities in our code. Devtron already provides a mechanism to scan Docker images, and to identify CVEs. We are looking at it to serve the following purposes:
- Inventory of all open source softwares used in a repo.
- License compliance.
- Security Vulnerabilities (CVEs).
Motivation
There are some orgs who have worked in this field. We can take inspiration from their solutions to build it inside Devtron. E.g. AboutCode, Owasp, Fossology
AB#450