Skip to content

ppottorff/jitrepo

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

36 Commits
 
 
 
 
 
 

Repository files navigation

Jit CI is a remarkable security testing tool. Their perspective is radically modern!

  • Deliver Friendly - Specific actionable feedback provided in pull requests, often with a remediation recommendation in the PR. Focus is on the quality of new commits, while supporting the remediation of historical vulnerabilities.
  • Holistic Assessment Jit assessment encompass the potential for code & misconfiguration in a modern cloud application. Secrets, IaC, Container, SCA, SAST... in code assessment. GitHub and cloud account (Azure, AWS, GCP) integration for misconfigurations.
  • Focus on What Matters - Jit doesn't unleash a firehose of alerts and vulnerabilities, false positives. It is focused on quality findings, quality commits, and actionable feedback. It helps compute the cost savings from improved developer productivity and code quality.
  • Modern Integration - Jit is installed as a GitHub App, Configurable at the Org level. Its assessment plans are defined in code (SaC). It can be enabled for all (or select) repos in an Organization, in a matter of minutes.
  • Embraces Open Source - Some of the best security tools are OSS and found in Jit plans.

In this Repo

  1. A Jit security plan, defined in code.
  2. PRs with examples of code issues.

image

About

Repo for Jit workflows

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published