Git Product home page Git Product logo

sshyran / django-defectdojo Goto Github PK

View Code? Open in Web Editor NEW

This project forked from defectdojo/django-defectdojo

0.0 2.0 0.0 65.84 MB

DefectDojo is an open-source application vulnerability correlation and security orchestration tool.

Home Page: https://www.defectdojo.org/

License: BSD 3-Clause "New" or "Revised" License

Python 24.72% HTML 72.78% JavaScript 0.70% Shell 1.33% CSS 0.21% XSLT 0.05% Smarty 0.18% Batchfile 0.02% Mustache 0.02%

django-defectdojo's Introduction

DefectDojo

OWASP Flagship GitHub release YouTube Subscribe Twitter Follow

Build Status Documentation Status CII Best Practices

Screenshot of DefectDojo

DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, schedule scans, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo.

Quick Start

git clone https://github.com/DefectDojo/django-DefectDojo
cd django-DefectDojo
# building
docker-compose build
# running
docker-compose up
# obtain admin credentials. the initializer can take up to 3 minutes to run
# use docker-compose logs -f initializer to track progress
docker-compose logs initializer | grep "Admin password:"

Navigate to http://localhost:8080.

Alternatively, try out the demo sever at demo.defectdojo.org

Log in with admin / defectdojo@demo#appsec and please note that the demo server is refreshed regularly.

Documentation

For detailed documentation you can visit Read the Docs.

Supported Installation Options

Getting Started

We recommend checking out the about document to learn the terminology of DefectDojo and the getting started guide for setting up a new installation. We've also created some example workflows that should give you an idea of how to use DefectDojo for your own team.

REST APIs

** Deprecation notice ** apiv1 is deprecated and EOS is on 12-31-2020. EOL is planned for 06-30-2021. Please move on to apiv2 and raise issues for any unsupported operations.

Defectdojo can be accessed through a Swagger REST API. Please see the API documentation or the in-app Swagger documentation.

Client APIs and wrappers

This section presents different ways to programmatically interact with DefectDojo APIs.

See Wrappers

Release and branch model

See Release and branch model

Roadmap

A magical, illusionary, non-existent, YMMV, wannabe, no guarantees list of thing we may or may not be working on:

  • New permission model
  • Push groups of findings to a single JIRA ticket
  • Reimport matching improvements

Support, Bug Reports and Getting Involved

Please come to our Slack channel first, where we can try to help you or point you in the right direction:

Slack

Realtime discussion is done in the OWASP Slack Channel, #defectdojo. Get Access.

Social Media

Twitter

DefectDojo Twitter Account tweets project updates and changes.

Available Plugins

Engagement Surveys – A plugin that adds answerable surveys to engagements.

LDAP Integration

SAML Integration

Multi-Factor Auth

About Us

DefectDojo is maintained by:

Project Moderators

Project Moderators can help you with pull requests or feedback on dev ideas.

Hall of Fame

  • Charles Neill (@ccneill) – Charles served as a DefectDojo Maintainer for years and wrote some of Dojo's core functionality.
  • Jay Paz (@jjpaz) – Jay was a DefectDojo maintainer for years. He performed Dojo's first UI overhaul, optimized code structure/features, and added numerous enhancements.

Contributing

We greatly appreciate all of our contributors.

More info: Contributing guideline

We would also like to highlight the contributions from Michael Dong and Fatimah Zohra who contributed to DefectDojo before it was open source.

Swag Rewards

If you fix an issue with the swag reward tag, we'll send you a shirt and some stickers!

Dojo tshirt front

Support

Proceeds are used for testing, infrastructure, etc.

PayPal

Sponsors

Xing 10Security GCSecurity ISAAC Timo-Pagel SDA-SE Signal-Iduna WSO2 CloudBees

Interested in becoming a sponsor and having your logo displayed? Please review our sponsorship information or email [email protected]

License

DefectDojo is licensed under the BSD Simplified license

django-defectdojo's People

Contributors

devgrega avatar aaronweaver avatar valentijnscholten avatar madchap avatar dependabot-preview[bot] avatar maffooch avatar propersam avatar dr3dd589 avatar patriknordlen avatar grendel513 avatar alles-klar avatar deverica avatar dependabot[bot] avatar ptrovatelli avatar piyarathnalakmali avatar mtesauro avatar renovate[bot] avatar nwse-fwn avatar wurstbrot avatar twsagarcia avatar jpbowie avatar hendrikhalkow avatar damiencarol avatar adracea avatar rasinfosec avatar ysaxon avatar xens avatar dougmorato avatar dsever avatar stefanfl avatar

Watchers

James Cloos avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.