awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
DefectDojo avatar

DefectDojo/django-DefectDojo

0
View on GitHub↗
4,528 stele·1,821 fork-uri·HTML·bsd-3-clause·12 vizualizăridefectdojo.com↗

Django DefectDojo

DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture.

The system distinguishes itself by aggregating findings from various security tools into a single report and normalizing that data to prioritize remediation. It provides specific workflows for vulnerability triage and deduplication to reduce noise and redundant manual work across the software development lifecycle.

The platform covers a broad capability surface including security pipeline automation, asset hierarchy modeling, and the generation of security metrics and reports. It integrates with external security tools, issue trackers, and directory services for identity management.

The application is built as a Django-based monolith and exposes its core functionality through a REST API.

Features

  • Vulnerability Management - Tracks and remediates security flaws by centralizing findings from various tools into a single management workflow.
  • Vulnerability Management Systems - Provides a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners.
  • Relational Inventory Schemas - Uses a strongly typed relational database schema to structure security assets and vulnerability hierarchies for consistent reporting.
  • Scan Data Importers - Ingests findings from multiple security tools to centralize vulnerability data in a single location.

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI
  • External Security Tool Integrations - Provides connectors to automatically ingest data and enrich findings from various third-party security scanning utilities.
  • REST APIs - Exposes core functionality through a structured REST API for CI/CD pipeline integration and automated finding uploads.
  • Security Posture Dashboards - Visualizes security risks and trends through dashboards and reports to monitor the overall organizational defense posture.
  • Security Metrics Dashboards - Provides a Django-based web interface for visualizing security metrics and organizational risk posture.
  • Asset Hierarchy Modeling - Organizes products and assets into a structured hierarchy to map the security posture of an organization.
  • Security Finding Management - Normalizes and aggregates data from various security tools into a single report for prioritized remediation.
  • Security Orchestration - Automates the ingestion and triage of security scan results across the software development lifecycle.
  • Vulnerability Scanner Integrations - Connects multiple third-party security scanners and APIs to automatically ingest and consolidate vulnerability data.
  • Vulnerability Lifecycle Managers - Implements workflows for managing the full lifecycle of security defects from discovery to remediation.
  • Ingestion Parsers - Standardizes diverse security tool outputs into a common internal format using specialized ingestion parsers.
  • Security Finding Deduplicators - Merges duplicate security findings from different scanners to reduce noise and prioritize remediation efforts.
  • Issue Tracking Integrations - Synchronizes identified vulnerabilities with external issue trackers to coordinate remediation efforts across development teams.
  • Security Testing Pipelines - Automates the discovery of vulnerabilities by integrating security testing directly into delivery pipelines.
  • Role-Based Access Control - Manages system permissions by mapping users to specific roles that define access levels to organizational assets.
  • Security Performance Metrics - Generates quantitative measurements of security posture and risk trends via dashboards.
  • Vulnerability Report Generation - Produces detailed reports and dashboards from scan results to track remediation progress.
  • Security Testing Orchestration - Coordinates the end-to-end process of security testing and vulnerability tracking.
  • Security Orchestration - Platform for security orchestration and vulnerability management.
  • Application Security - Orchestrates application vulnerability correlation and management.
  • Vulnerable Applications - Open-source vulnerability correlation and security orchestration tool.
  • Istoric stele

    Graficul istoricului de stele pentru defectdojo/django-defectdojoGraficul istoricului de stele pentru defectdojo/django-defectdojo

    Întrebări frecvente

    Ce face defectdojo/django-defectdojo?

    DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture.

    Care sunt principalele funcționalități ale defectdojo/django-defectdojo?

    Principalele funcționalități ale defectdojo/django-defectdojo sunt: Vulnerability Management, Vulnerability Management Systems, Relational Inventory Schemas, Scan Data Importers, External Security Tool Integrations, REST APIs, Security Posture Dashboards, Security Metrics Dashboards.

    Care sunt câteva alternative open-source pentru defectdojo/django-defectdojo?

    Alternativele open-source pentru defectdojo/django-defectdojo includ: infobyte/faraday — Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… dependencytrack/dependency-track — Dependency-Track is a software composition analysis tool and vulnerability management system designed to track… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… keygraphhq/shannon — Shannon is an integrated security platform designed for autonomous penetration testing, static and dynamic analysis,…

    Alternative open-source pentru Django DefectDojo

    Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Django DefectDojo.
    • infobyte/faradayAvatar infobyte

      infobyte/faraday

      6,523Vezi pe GitHub↗

      Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings from multiple scanners into a single dashboard. It utilizes a relational security database to catalog hosts, services, and security flaws, enabling users to track remediation and analyze organizational risk. The platform distinguishes itself through a plugin-based system that normalizes diverse security tool outputs into a unified data model. It supports deep integration with a wide array of scanners and CLI tools, intercepting shell command output or parsing report files to ag

      Python
      Vezi pe GitHub↗6,523
    • projectdiscovery/subfinderAvatar projectdiscovery

      projectdiscovery/subfinder

      13,105Vezi pe GitHub↗

      Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

      Gobugbountyhackinghacktoberfest
      Vezi pe GitHub↗13,105
    • dependencytrack/dependency-trackAvatar DependencyTrack

      DependencyTrack/dependency-track

      3,612Vezi pe GitHub↗

      Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity

      Javaappsecbill-of-materialsbom
      Vezi pe GitHub↗3,612
    • snyk/snykAvatar snyk

      snyk/snyk

      5,586Vezi pe GitHub↗

      Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

      TypeScript
      Vezi pe GitHub↗5,586
    Vezi toate cele 30 alternative pentru Django DefectDojo→