$ ./devsecops-pipeline --report
Site DevSecOps report
This site goes through the same kind of controls I apply at work. A GitHub Actions pipeline runs on every change and weekly, and publishes its results here.
Fail Secrets in code and history
Tool:
gitleaks- 1 findings
OK Static analysis (SAST)
Tool:
Semgrep CE- ERROR 0
- WARNING 0
- INFO 0
- 105 files
OK Vulnerable dependencies
Tool:
npm audit- critical 0
- high 0
- moderate 0
- low 0
OK SBOM (component inventory)
Tool:
CycloneDX- 284 components
- CycloneDX 1.6
OK HTTP security headers
Tool:
curl- ✓ strict-transport-security
- ✓ content-security-policy
- ✓ x-frame-options
- ✓ x-content-type-options
- ✓ referrer-policy
- ✓ permissions-policy
OK Web quality (Lighthouse)
Tool:
Lighthouse- Performance 97
- Accessibility 100
- Best practices 96
- SEO 100