DevSkim
DevSkim copied to clipboard
SonarQube integration
What about integrating this tool with SonarQube? I have no idea regarding the complexity of this task, but it may be worth it.
Example of code analysis tool that can be integrated with SonarQube: https://github.com/RIGS-IT/sonar-xanitizer
I'll poke around at that to see what's involved. Probably also makes sense to look at integration with ThreadFix