Reset

Showing 203 rule(s)

Rule ID Name Platform Category Severity
DOS6051 CI/CD variable value should not be empty GitLab project Severitymedium
DOS6052 Project must have a default branch (CI anchor) GitLab project Severitymedium
DOS6053 Project must have a recorded last-activity timestamp (CI freshness) GitLab project Severitylow
DOS6054 Project must have a non-empty path-with-namespace (CI scoping) GitLab project Severitylow
DOS6055 Project fork count should not exceed bounded threshold GitLab project Severitylow
DOS6056 Runner active flag should be enabled GitLab organization Severitymedium
DOS6057 Project-scoped runner should be locked to the project GitLab organization Severityhigh
DOS6058 Runner should not pick up untagged jobs GitLab organization Severitymedium
DOS6059 Runner status should be online GitLab organization Severitymedium
DOS6060 Project should require at least one approval before merge GitLab organization Severityhigh
DOS6061 Project should reset MR approvals when new commits are pushed GitLab organization Severityhigh
DOS6062 Project integration should be active GitLab organization Severitylow
DOS6063 Project integration should subscribe to pipeline events GitLab organization Severitymedium
DOS6064 Pipeline schedule should be active GitLab organization Severitymedium
DOS6065 Pipeline schedule should specify a cron timezone GitLab organization Severitylow
DOS6710 GH DevSecOps Control - Ensure Secret Scanning (SS) GitHub appsec Severitycritical
DOS6720 GH DevSecOps Control - Ensure Software Composition Analysis (SCA) / Dependency Scanning GitHub appsec Severitycritical
DOS6730 GH DevSecOps Control - Ensure Static Application Security Testing (SAST) / Code Scanning GitHub appsec Severitycritical
DOS6740 GH DevSecOps Control - Ensure Container Image Scanning (CIS) / Container Scanning GitHub appsec Severitycritical
DOS6750 GH DevSecOps Control - Ensure Infrastructure as Code Scanning (IACS) GitHub appsec Severitycritical