Reset

Showing 123 rule(s)

Rule ID Name Platform Category Severity
DOS3510 DevSecOps Control - Ensure Secret Scanning (SS) AzureDevOps appsec critical
DOS3520 DevSecOps Control - Ensure Software Composition Analysis (SCA) / Dependency Scanning AzureDevOps appsec critical
DOS3530 DevSecOps Control - Ensure Static Application Security Testing (SAST) / Code Scanning AzureDevOps appsec critical
DOS3540 DevSecOps Control - Ensure Container Image Scanning (CIS) / Container Scanning AzureDevOps appsec critical
DOS3550 DevSecOps Control - Ensure Infrastructure as Code Scanning (IACS) AzureDevOps appsec critical
DOS3560 DevSecOps Control - Ensure Infrastructure Scanning (IS) AzureDevOps appsec critical
DOS3570 DevSecOps Control - Ensure Dynamic Application Security Testing (DAST) AzureDevOps appsec critical
DOS3580 DevSecOps Control - Ensure Interactive Application Security Testing (IAST) AzureDevOps appsec high
DOS4010 Ensure Repository Base permissions is set to 'No permission' GitHub organization critical
DOS4015 Disable Repository Forking GitHub organization critical
DOS4025 Disable Public Repository Creation - Disallow members to create public repositories GitHub organization critical
DOS4030 Restrict Repository Creation to Internal - Allow members to create internal repositories GitHub organization critical
DOS4035 Restrict Repository Creation to Private - Allow members to create private repositories GitHub organization critical
DOS4040 Restrict GitHub Pages Creation - Disallow members to publish sites GitHub organization high
DOS4210 Require two-factor authentication in your organization GitHub organization critical
DOS4300 Workflow permissions - Default workflow permissions granted to the GITHUB_TOKEN should be restricted to read-only access GitHub organization critical
DOS4320 Workflow permissions - Prevent GitHub Actions workflows from creating or approving pull requests GitHub organization critical
DOS4375 GitHub Actions Secrets - Minimize the usage and sharing of your organization secrets GitHub organization critical
DOS4380 GitHub Actions Secrets - Restrict the access and visibility of an organization secret to only selected repositories GitHub organization critical
DOS4381 GitHub Actions Secrets - Restrict the sharing of an organization secret to fewer selected repositories GitHub organization critical