General
Repositories
- dynamic-analysis: A curated list of dynamic analysis tools and linters
- static-analysis: A curated list of static analysis (SAST) tools and linters
Technique Articles
- Deepfactor - Security Scanning Tools Defined: SAST, IaC, SCA, DAST, IAST/RASP, Container Runtime Security and Runtime SCA
- Outpost24 - What is best for application security testing: SAST, DAST, or SCA
- Microsoft - Zero Trust DevSecOps
Technology Articles
- OWASP - DevSecOps Guideline
- Medium - Building end-to-end DevSecOps for AWS Migration: Security at Entry Level with open source SCA, SAST and DAST tools
- Medium - Establishing an Enterprise-Ready DevSecOps CI/CD Pipeline on GitHub Actions on Google Cloud
Tools
SAST
-
Sonarqube: An on-premise analysis tool designed to detect coding issues
- Sonar Rule: The collections of rule integrate into Sonarqube Server