The purpose of secureCodeBox is not to replace the penetration testers or make them obsolete. We strongly recommend to run extensive tests by experienced penetration testers on all your applications. For more information about this project, please have look at our GitHub Repo secureCodeBox or online documentation. Our main goal is to implement a major security testing platform and framework which enables developers and teams to integrate a bunch of security testing tools in their CI/CD environment or kubernetes environment as easy as possible. The flexibility and scalability of the platform architecture leads to features like multi tenancy support, large scale (multi-) project testing, support of distributed and private networks, customizable security test flows, which enables projects to test complex environments without implementing the complete security testing infrastructure on their own. Secondly we try to foster a broad range of security tools to be easily integrated. Also we will try to integrate existing OWASP Projects as building blocks in our platform.
The secureCodeBox architecture is based on Kubernetes Custom Resource Definitions (CRDs). Scans are executed as containers in Kubernetes that are started on demand, keeping resource consumption close to zero when nothing is executed. The system is modular and can be freely extended to support custom scan type that aren't maintained by the core team.
For a quickstart see our installation documentation and the starting your first scan documentation on our comprehensive documentation site.
This Project is free software: you can redistribute it and/or modify it under the terms of the Apache License 2.0. OWASP secureCodeBox Project and any contributions are Copyright by the secureCodeBox authors.