|
Contributor? Add your recommendation and reasoning here. |
Contributors: I am seeking the right people to get involved in the decision. Add your comments to this page, let's get the conversation started. Please add:
|
|
The application code developed for Lab Booster (DataLab) includes 3rd party libraries that are widely used in the industry but may still include vulnerabilities. Also the business logic within the code along with the application design may itself create vulnerabilities that could expose the Syensqo systems and data to potential bad actors. Including security tools as part of the application code build, and the development practice itself can significantly reduce this risk.
No standardized security tools are used.
What data or research will help make this decision?
| Option 1: Do nothing | Option 2: Aikido | Option 3: Snyk | Option 4: SonarQube | Option 5: HCL AppScan | |
|---|---|---|---|---|---|
Description | https://snyk.io/ | https://www.sonarsource.com/ | https://www.hcl-software.com/appscan | ||
Rollout plan | |||||
| Pros and cons |
|
|
|
|
|
Risks | New product and community knowledge/skills/support may be limited AI classification may not be very accurate | May not address all use cases | High cost and complexity to maintain | ||
Estimated cost and effort | From € 299/mo for 10 users | $25 per dev/product/month (minimum 5 devs / $1,375 annually) | Limited functionality for free Developer license $160/year | On demand, not publicly shared |
Q1.
A1.
|
Learn more: https://www.atlassian.com/team-playbook/plays/daci
Copyright © 2016 Atlassian

This work is licensed under a Creative Commons Attribution-Non Commercial-Share Alike 4.0 International License.