Open source · Security

DSI VAPT Scanner MIT

A SAST and dependency-audit scanner that emits SARIF, so findings land in the same pipeline as lint.

Browse the catalogue

Public repository

https://github.com/dev-sec-it/vapt-scanner

View repository

Releases, issues and the commit history are on the repository, so the license and the maintenance status can be checked against the last tagged release rather than taken on trust.

Catalogue record

The facts a buyer screens on first

Every value below is copied from the catalogue entry and is verifiable against the public repository.

License
MIT

OSI identifier, as published in the repository.

Stack
Python

Primary language and runtime.

Status
Production

As recorded in the DEV SEC IT catalogue.

Stars
2.1k

Counted from the public repository at the time of writing.

What we maintain

Our contribution to DSI VAPT Scanner

This project is on the catalogue because we own part of it. The parts we wrote, review and release are named here; everything else is upstream work we depend on.

Maintenance

Maintained by DEV SEC IT

What we wrote

Rule packs mapped to OWASP ASVS

First tagged release

First tagged release in 2022.

Where it runs

An internal dependency, not a side project.

DSI VAPT Scanner is consumed inside DEV SEC IT's own platforms, which is why its release cadence and license are kept current rather than left to a final commit.

  • Consumed in production

    dAuth (Self-host or managed), dCloud (Self-host or managed).

Talk to us

Need this running inside your own perimeter?

We maintain this project and the platforms built on it. If you want a deployment, a review or a fix against your environment, the same engineers who ship it can scope it.

All open source