Vet DevSecOps
Every commit vetted. Runs the security scanners in your pipelines, turns their output into one vulnerability inventory and blocks what should not ship.
- Scanners in your CI: Gitleaks, TruffleHog, Semgrep, Trivy, Grype, OSV-Scanner, Checkov, Syft and OWASP ZAP in GitHub Actions, GitLab CI and Azure Pipelines.
- One ID per vulnerability (VET-123), de-duplicated across tools, closed when the fix merges and reopened with the same ID if it returns.
- Security gate on pull requests, prioritized by CISA KEV and FIRST EPSS, with SLA and MTTR per severity.
- Risk exceptions with expiry and identity confirmation, SBOM and license policy, policy-as-code in Rego, signed evidence reports.