Draugr runs Trivy, Semgrep, Gitleaks, and other security scanners from one configuration file. It consolidates SAST, software composition, secrets, IaC, and container findings into a ranked SARIF report and can fail CI on new findings.
Draugr is an Application security & vulnerability scanning project. It focuses on combining and prioritizing findings from multiple security scanners into a single CI decision and SARIF report. It is built as an open-source project for devSecOps engineers and software development teams. The project is open source (Open Source). Draugr is available on the command line, and it can be self-hosted.
draugr-dev builds and maintains Draugr. Among its 10 catalogued features are multi-scanner execution, SARIF reports, and risk ranking. It exposes integrations via a public API.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match