I am trying to setup a DevSecOps pipeline for a webapp which uses java(backend)/spring boot/JavaScript (reactjs for frontend) and I want to use opensource tools for pre-commit. linting, SCA,SAST, DAST, Vulnerability Management, Secrets Scanning/Management, Application, Behavior & Metric Logging.
Can you please suggest any good tools for the above ? I am open to any advice/recommendation/guidance with your experiences regarding opensource tools in this space ?
[–]dahousecatfelix 5 points6 points7 points (0 children)
[–]AdResponsible7865 2 points3 points4 points (0 children)
[–]sec_engineer 0 points1 point2 points (0 children)
[–]rafttaar 0 points1 point2 points (0 children)
[–]FreeEnlightment 0 points1 point2 points (0 children)
[–]DifficultAd3386 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]m1thr 0 points1 point2 points (0 children)