The white duck team takes all security vulnerabilities seriously. This Template is being used for all our Cloud Native Software Development Project. This Template has the Goal to enhance the security of all our Cloud Native Software Projects.
- Vulnerability Reporting and Disclosure Policy
- Issues and Pull Request Templates
- Security CI/CD Pipeline Templates
- Dependency Review
- GitLeaks Secret Scanning
- Snyk Container Scanning
- GitHub CodeQL Static Code Scanning
- Security CI/CD Pipeline examples
Usage Instructions can be found within docs/INSTALL_INSTRUCTIONS.md