The purpose of this project is to implement DevSecOps tools into a applicaiton development pipeline. The outcome should result in the implementation of SAST, SCA, and ideally a cloud-native DAST tools.
python-app
|
SAST + SCA - semgrep
|
SAST for Github - CodeQL (standard)