Implement Jit’s out-of-the-box security toolchains or integrate your own favorite tools into Jit’s security orchestration framework.Get started with Jit
Gosec provides static application security testing (SAST) for code written in Go.
Use Gitleaks to surface hard-coded secrets that can be exploited by attackers to gain unauthorized access to the password-protected asset.
Use Trufflehog to surface hard-coded secrets that can be exploited by attackers to gain unauthorized access to the password-protected asset. Trufflehog can determine whether an hard-coded secret will be exposed in production.
Use OSV-Scanner (by Google) to find existing vulnerabilities affecting your project’s dependencies. The tool uses the data provided by https://osv.dev. Support Python and PHP.
Nancy surfaces known vulnerabilities in open source components written in Go.
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by a dedicated international team of volunteers. Use ZAP to run dynamic tests against web apps and APIs to surface a huge list of vulnerabilities.
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Kubescape (by Armo) provides vulnerability and misconfiguration scanning for IaC files being deployed to Kubernetes.
Prowler is an spen source tool to perform AWS security best practices assessments, audits, continuous monitoring, hardening and forensics readiness. It contains more than 200 controls covering CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS and custom security frameworks.
Legitify makes it east to detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets.
Chain-bench by Aqua anaalyzes your software supply chain against new CIS Benchmarks.
Jit BP-checker verifies the GitHub Branch Protection is properly configured.
Add any DevSecOps tool to Jit’s extensible orchestration framework
Plug your preferred security tools into Jit to unify the execution and UX of your developer security stack, enabling a more consistent DevSecOps experience.
Every security tool orchestrated by Jit can be integrated into the developer environment with a few clicks.
Jit supports open source tools, cloud-native tools, commercial tools, or even your own in-house tool.