Kirø~$

🇳🇴 NO|🇬🇧 EN
IT/DevOps consultant
Cloud/Solution Architect
Board gamer and sci-fi fan
Ponderer of life mysteries
House owner and Handyman

Security tools

Definitely needed stuff.

Snyk

Has automated pull requests to update dependencies.

White source

The issue feed is used by github I think.

Github advanced security

Including the lgtm.com stuff is quite powerful. Mostly free for open source stuff.

Dependency scanning! Automated pull requests and security audit emails. That’s cool. Even needed.

Zap OWASP

Does OWASP scanning of your repo.

Gitlab

Seems like a nice competitor to github.

Azure DevOps??

I know they have some scanning stuff in their pipelines, but it’s not dedicated such as Snyk.