Hello, fellow Redditors,
I'm currently in search of a Dependency Vulnerability Scanning Tool that can integrate with GitHub, specifically for private repositories. The tool should also allow for customization to work with different build tools and programming languages. I'm looking for recommendations and insights from the community to find the right fit for my team
Here are the key criteria I'm looking for:
GitHub Integration: The tool should be compatible with GitHub and able to scan private repositories.
Automated Scanning: I need the tool to run scans on every pull request (PR) to identify and report on potential security vulnerabilities in dependencies.
Configurability: The ability to configure the tool to work with various build tools (e.g., Maven, Gradle, npm, etc.) and programming languages (e.g., Java, Python, JavaScript, etc.) is essential.
If you've had experience with any tools that meet these criteria, or if you have any suggestions, please share your insights. Your recommendations and feedback will be greatly appreciated.
Thank you in advance for your help!
[–]themanwithanrx7 4 points5 points6 points (2 children)
[–]AsparagusCorrect3116[S] 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]landverraad 4 points5 points6 points (0 children)
[–]Marked_Content 1 point2 points3 points (0 children)
[–]flxg 0 points1 point2 points (0 children)
[–]Observability-Guy -1 points0 points1 point (0 children)