返回排行榜

DefectDojo/django-DefectDojo

HTMLdefectdojo.com

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

pythonvulnerability-databasesdjangosecurityowaspanalyticsvulnerability-managementautomationsecurity-automationsecurity-orchestrationdevsecopsvulnerability-correlation
Star 增长趋势
Star
4.8k
Forks
1.9k
周增长
Issues
196
2k4k
2015年3月2018年12月2022年10月2026年7月
README

DefectDojo

Open Source Security Index - Fastest Growing Open Source Security Projects

OWASP Flagship GitHub release YouTube Subscribe Twitter Follow

Unit Tests Integration Tests CII Best Practices

DefectDojo is a DevSecOps, ASPM (application security posture management), and vulnerability management tool. DefectDojo orchestrates end-to-end security testing, vulnerability tracking, deduplication, remediation, and reporting.

Demo

Pro Edition: pro.demo.defectdojo.com

OWASP Community Edition: demo.defectdojo.org

Either demo environment can be logged into with username admin and password 1Defectdojo@demo#appsec. Please note that the demos are publicly accessible and reset every day. Do not put sensitive data in the demo. An easy way to test DefectDojo is to upload some sample scan reports.

Quick Start for Docker Compose

git clone https://github.com/DefectDojo/django-DefectDojo && cd django-DefectDojo && docker compose up

This quick start guide will do the following

  • Clone the repository and change directories
  • Start the application
  • Obtain admin credentials in the initializer logs. The first initialization can take up to 3 minutes to run.

if running DefectDojo in detached mode via docker compose up -d, obtain admin credentials from the initializer logs with the command below. Please note, the initializer can take up to 3 minutes to run.

docker compose logs initializer | grep "Admin password:"

Documentation

Supported Installation Options

Community, Getting Involved, and Updates

Dojo Slack LinkedIn Twitter Youtube

Checkout our new Community Portal and join the DefectDojo community on Slack!

Follow DefectDojo on LinkedIn, YouTube, and X for platform updates!

Contributing

Please see our contributing guidelines for details and standards on contributing before considering or submitting a pull request.

Pro Edition

Upgrade to DefectDojo Pro! Pro transcends the do-it-yourself approach of open-source: A new UI, risk-based vulnerability management, incredibile scalability, API connectors, ServiceNow, GitHub, GitLab, Azure DevOps, automatic data enrichment, prioritization, and more! See all the differentiators at the bottom of our pricing page: defectdojo.com/pricing.

Alternatively, for information please email hello@defectdojo.com

About Us

DefectDojo is maintained by:

Core Moderators can help you with pull requests or feedback on dev ideas:

Moderators can help you with pull requests or feedback on dev ideas:

Hall of Fame

  • Jannik Jürgens (@alles-klar) - Jannik was a long time contributor and moderator for DefectDojo and made significant contributions to many areas of the platform. Jannik was instrumental in pioneering and optimizing deployment methods.
  • Valentijn Scholten (@valentijnscholten | Sponsor | LinkedIn) - Valentijn served as a core moderator for 3 years. Valentijn's contributions were numerous and extensive. He overhauled, improved, and optimized many parts of the codebase. He consistently fielded questions, provided feedback on pull requests, and provided a helping hand wherever it was needed.
  • Fred Blaise (@madchap | LinkedIn) - Fred served as a core moderator during a critical time for DefectDojo. He contributed code, helped the team stay organized, and architected important policies and procedures.
  • Aaron Weaver (@aaronweaver | LinkedIn) - Aaron has been a long time contributor and user of DefectDojo. He did the second major UI overhaul and his contributions include automation enhancements, CI/CD engagements, increased metadata at the product level, and many more.
  • Jay Paz (@jjpaz) – Jay was a DefectDojo maintainer for years. He performed Dojo's first UI overhaul, optomized code structure/features, and added numerous enhancements.
  • Charles Neill (@ccneill) – Charles served as a maintainer of DefectDojo for years and wrote some of Dojo's core functionality.

Security

Please report Security issues via our disclosure policy.

License

DefectDojo is licensed under the BSD 3-Clause License

相关仓库
donnemartin/system-design-primer

Learn how to design large-scale systems. Prep for the system design interview. Includes Anki flashcards.

PythonPyPIOtherprogrammingdevelopment
358.7k57.3k
vinta/awesome-python

An opinionated list of Python frameworks, libraries, tools, and resources

PythonPyPIOtherawesomepython
awesome-python.com
309.6k28.4k
practical-tutorials/project-based-learning

Curated list of project-based tutorials

PythonPyPIMIT Licensetutorialproject
274.6k35.4k
TheAlgorithms/Python

All Algorithms implemented in Python

PythonPyPIMIT Licensepythonalgorithm
thealgorithms.github.io/Python/
223k50.9k
tensorflow/tensorflow

An Open Source Machine Learning Framework for Everyone

C++Apache License 2.0tensorflowmachine-learning
tensorflow.org
196.5k75.7k
Significant-Gravitas/AutoGPT

AutoGPT is the vision of accessible AI for everyone, to use and to build on. Our mission is to provide the tools, so that you can focus on what matters.

PythonPyPIOtheraiopenai
agpt.co
185.6k46.1k
CyC2018/CS-Notes

:books: 技术面试必备基础知识、Leetcode、计算机操作系统、计算机网络、系统设计

algorithmleetcode
cyc2018.xyz
184.8k50.8k
yt-dlp/yt-dlp

A feature-rich command-line audio/video downloader

PythonPyPIThe Unlicenseyoutube-dlpython
discord.gg/H5MNcFW63r
179.4k15.3k
521xueweihan/HelloGitHub

:octocat: 分享 GitHub 上有趣、入门级的开源项目。Share interesting, entry-level open source projects on GitHub.

PythonPyPIgithubhellogithub
hellogithub.com
166.5k12.4k
huggingface/transformers

🤗 Transformers: the model-definition framework for state-of-the-art machine learning models in text, vision, audio, and multimodal models, for both inference and training.

PythonPyPIApache License 2.0nlpnatural-language-processing
huggingface.co/transformers
162.8k34k
langgenius/dify

Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. Deploy on cloud, VPC, or self-hosted, so teams move from prototype to production without rebuilding the stack.

TypeScriptnpmOtheraigpt
dify.ai
149.7k23.6k
langchain-ai/langchain

The agent engineering platform.

PythonPyPIMIT Licenseaianthropic
docs.langchain.com/langchain/
142.3k23.7k