|
|
|
|
|
by taleodor
10 days ago
|
|
We support this with ReARM - https://rearmhq.com/ It's an open-core product (there is an option to self-host FOSS ReARM CE yourself) that gives you per-release vulnerability posture. It consumes various artifacts (e.g., SBOMs) generated during CI phase and does scan on them, doesn't need access to source code. Apart from SBOMs it consumes files with findings from other tools (reports in SARIF format, VDRs, VEXs). |
|