v1.0.0
This first release of the devsecops demo includes:
- Static application security testing (SAST) using SonarQube, and JUnit Testing
- Software composition analysis (SCA) with Maven Dependency Report and Nexus
- Interactive application security testing (IAST) and dynamic application security testing (DAST) using StackRox/RHACS
- Configuration Management and Image Risk using StackRox/RHACS
- Pentesting using OWASP Zap Proxy
- Performance Tests using Gatling
- Optional: Slack Notifications using Stackrox Notifications and Slack chanel
- Ansible Automation for install, configure and prepare all the prerequisites and software needed during the demo