Trying Draugr on a real repository? I'll help you set it up #1370
wils0ns
started this conversation in
Show and tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
I'm looking for a few teams to run Draugr on a real repository and tell me where it gets things wrong.
Who it's for: a team that already runs two or more security scanners in CI, such as Trivy, Semgrep, Gitleaks or govulncheck, or that turned one on and got more findings than it can triage.
What I'll do: write the descriptor with you, in this thread or on a call if that's quicker. That includes each component's
exposureandcriticality, which is the part that takes judgment. Then I stay on the thread for whatever the first scan raises.What I'd like back: whatever got in your way, from the install to the first scan to the results.
To start, reply with what the repository is (language, whether it ships container images, which CI) and which scanners you run today. Your code stays private: the scan runs on your machine or runner, and nothing is uploaded.
Wilson
All reactions