teomach/Lybica Security Scan

Run Lybica's pluggable OSS security scanners (SAST/Secrets/SBOM/SCA/IaC/DAST) as Lybica-labelled stages and ship findings to DefectDojo -> SVM. Scanners are defined in scanners.yaml (the plugin contract) — add one by editing the registry, no code change. Findings POST to the public DefectDojo (DEFECTDOJO_URL, e.g. https://app.lybica.com) over the internet — no Tailscale required.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
productDefectDojo product name (e.g. 'Cenefits Staging').yes
engagementDefectDojo engagement (auto-created).yes
targetPath to scan for code scanners.no.
dast-targetURL to scan for DAST (empty = skip DAST).no""
componentcomponent: label applied to findings.noapp
scannersOptional CSV subset of scanner names (default: all enabled).no""
branchSource branch; tagged on import.no""
commitCommit SHA; tagged on import.no""
python-versionno3.11

no outputs