|
|
|
|
|
by kai-tub
524 days ago
|
|
Author here: I also find this an important thing to ask yourself when you are running applications/scripts that do anything with sudo and which is why I have written a fairly in-depth "Security" section on the isd documentation page: https://isd-project.github.io/isd/security/ Let me know if anything is missing! |
|
Where I work we also use defectdojo to catalogue and manage CVRs in our projects, but it's more involved to setup the testing pipeline and deploy the required services.