简体   繁体   English

Checkmarx和OWASP依赖项检查

[英]Checkmarx and OWASP dependency check

We are creating a delivery pipeline for our project. 我们正在为我们的项目创建一个交付管道。 And we have checkmark scan as part of our pipeline. 我们将检查标记扫描作为我们流程的一部分。

We would like to know if dependency check is already done as part of checkmark scan or do we need to add OWASP dependency check seperately as part of our pipeline? 我们想知道依赖检查是否已经作为检查标记扫描的一部分进行了,还是我们需要单独添加OWASP依赖检查作为管道的一部分?

No, Checkmarx has an alternative to DependencyTrack, and they also support scanning open source dependencies. 不,Checkmarx可以替代DependencyTrack,并且它们还支持扫描开源依赖项。 This cost some more money, ask them directly. 这花了一些钱,直接问他们。 To use dependency check, you'll have to do that in a separate part of the pipeline. 要使用依赖性检查,您必须在管道的单独部分中执行此操作。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM