OWASP DevGuard
Description
Plateforme open-source unifiée pour la sécurité de la supply chain logicielle. Remplace la patchwork de scanners déconnectés.
Capacités
- Full DevSecOps pipeline : Secret scanning, SAST, SCA, IaC scanning, container scanning, license compliance — un seul CLI
- Risk-based prioritization : Score
(CVSS-BE × (EPSS + 1)) / 2 / Component Depth - SBOM & VEX management : CycloneDX SBOMs, live endpoints
- Dependency Firewall : Proxy npm, Go, Python — bloque packages malveillants avant download
- Supply-chain integrity : in-toto attestations, SLSA provenance, cosign signatures
- Policy enforcement : OPA/Rego, enforcement automatique
- Issue tracker integration : GitHub Issues, GitLab Issues, Jira — sync bidirectionnel
Standards supportés
SBOM, VEX, SARIF, SLSA, in-toto — aucun vendor lock-in
Références
- OWASP DevGuard
- docs.devguard.org
- [[KNOW-REF-048]] — DevSecOps Guideline