Secure
Secure supported tools assist team members in obtaining data that displays details of the vulnerability in the environment.
These tools provide scores for overall risk, security-related build delays, and security findings during the build process with services like Static Scan that show vulnerabilities aggregated according to the day-month timeline, Open Source License Compliance to show all Licenses detected, and a compliance detail table to find dependencies between applications this provides an overall real-time estimation of the security data of the organization or a specific team.
Follow these steps to access the Tools Configurations page:
From the Kyndryl Bridge main menu , go to Services → Platform Services → Toolchain & Pipeline → DevOps Intelligence → Settings & Utilities → Tools Configuration.
For more information, see Supported toolsSupported Tools.
Tools supported in Secure:
- Qualys Container security tool configuration: Provides centralized, continuous discovery and tracking for containers and images.
- Dependency Track configuration: Scans components for known flaws.
- SonarQube Enterprise Edition configuration: Inspects the code quality and security of codebases and guiding development teams during Code Reviews.
- CodeQL configuration: Enables the discovery of vulnerabilities across your codebase.
- GitLab SAST configuration: Checks your source code for known vulnerabilities
- JFrog configuration: The process of setting up a connection between your platformand JFrog tools such as JFrog Artifactory and JFrog Security Essentials (Xray and JFrogOSS).
- Mend.io configuration: Securely manage open-source risks, license compliance, and AI-generated code.
- GCP Cloud Build configuration: Inspects the code quality and security of codebases and guiding development teams during code reviews.
- CodeQL configuration: Semantic code analysis engine that enables the discovery of vulnerabilities across your codebase.
- GitLab SAST configuration: Reviews your source code for known vulnerabilities.