Skip to content

QuackatronHQ/sca-kitchen-sink

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SCA Kitchen Sink

This repository serves as a benchmark environment for comparing various Software Composition Analysis (SCA) providers, with a specific focus on evaluating DeepSource's SCA capabilities against other solutions.

Purpose

The main objectives of this repository are:

  1. To provide a controlled testing environment with known vulnerable dependencies
  2. To demonstrate DeepSource's ability to detect and remediate third-party vulnerabilities
  3. To compare the effectiveness of different SCA solutions in identifying and fixing security issues
  4. To showcase realistic scenarios with reachable vulnerable code

Repository Structure

This repository contains intentionally vulnerable code samples and dependencies across various programming languages and package managers. Each vulnerability is carefully crafted to be reachable and exploitable, making it an ideal testing ground for SCA tools.

Usage

This repository is designed for testing and benchmarking purposes only. Do not use any code from this repository in production environments.

License

This project is licensed under the MIT License - see the LICENSE file for details.

Disclaimer

The vulnerabilities in this repository are intentionally created for testing purposes. Do not deploy or use this code in any production environment.

About

SCA benchmarking test bed.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published