vitech-team-sdlc/SDLC

QG: Snyk alternative

Closed this issue · 1 comments

We need to find a more affordable or open-source solution for security check.

https://github.com/goodwithtech/dockle
https://github.com/aquasecurity/trivy

check also nice implementation fro Azure pipelines: https://github.com/Azure/container-scan

From @serhiy-krupka-vitech : need to consider free service - https://github.com/aquasecurity/trivy