Tool

Sonar Cloud

  • Sonar Cloud is a tool that easily integrates into the cloud DevOps platform and uses code review tools that extend CI/CD workflows when teams want to deliver clean code consistently and efficiently.

GitHub Actions

  • Automate, customize, and run software development workflows directly from the repository using GitHub Actions. You can discover, create, and share tasks to accomplish the desired tasks, including CI/CD, and combine them in fully customized workflows.

FOSSA

  • FOSSA protects code by mitigating open source risk.
  • Software protection against open source risk management and license violations, vulnerabilities, and supply chain threats.

✅ License Identification
✅ Manage 5 Projects
✅ Vulnerability Management
✅ Basic Teams / Roles

Dependabot

  • Dependabot creates Dependabot alerts when a known vulnerability is detected in the dependencies used by the project.