Post #2527864
2026-05-08 21:11 UTC
@mcfly@milliways.social We run Trivy Operator in our k8s clusters for vulnerability scanning, also for config audits. For more config best practices checks we use Fairwinds Polaris. In addition we have multiple static analysis tools (BlackDuck, Sonarqube, Snyk). We try to get rid of Azure Defender though.
The main problem with that setup is to collect all the results and get them to the right people. That's why I want to look into vulnerability management tools like Defect Dojo soon.
Replies (2)
-
@mcfly@milliways.social 2026-05-08 21:13
@dentaku@fnordon.de DefectDojo is great. I gave a talk on that thing a while ago.... We use it in the company, i have been involved in 3 setups of that, it was always a big success. For companies consider the enterprise, there's a good connector to jira etc...
-
@musevg@23.social 2026-05-08 21:13
@dentaku@fnordon.de I'd be surprised if DefectDojo would fix that problem. @mcfly@milliways.social