Want to protect your software supply chain from attacks?
Learn how!Checkmarx One
Improve your security posture with full visibility into the security, dependency management, and maintenance health of the code repositories used in your applications.
Quickly assess the riskiness of open source repositories using Open Source Security Foundation (OSSF) Scorecards while also ensuring that you are implementing best practices for your own repositories.
Continuous Repo Health Scoring
Continuously tracks health scores for all repositories included in your applications based on key factors, including code quality, dependency management, and project maintenance.
Automatic SCM-Triggered Scans
SCM integration enables scans to be run automatically upon repository updates, ensuring up-to-date repo health metrics with no manual effort.
Flexible On-Demand Scanning Options
In addition to automatic SCM-triggered scans, developers and security teams can manually run repo health scans at any time via API, CLI, or the Checkmarx One UI.
Unified Risk Reporting
Repository health scores are included in Checkmarx One reports, providing visibility into – and efficient prioritization of – security vulnerabilities, code quality issues, and repository health risks all in one place.
Learn how leading enterprises use repository health scoring to improve their application security posture.
What’s in it for you
Comprehensive security assessments of open source and first-party code repositories improve AppSec while enhancing transparency and communication among stakeholders.
Organizations track repository health metrics for two main reasons: to ensure that the open source libraries used in their applications are being held to high standards of security and quality, and to ensure that their own code repositories are likewise subject to security and quality best practices.
Repository health scores are based on many factors, including the presence of branch protection, pinned dependencies, code review before merging, fuzzing tools, CII best practices, token permissions, and signed releases.
OSSF Scorecard is an open source project created by the Open Source Security Foundation (OpenSSF) that assesses open source projects for security risks through a series of automated checks. Checkmarx One incorporates the results of OSSF Scorecard metrics in its reports so that developers and security teams can improve their visibility into security vulnerabilities, code quality issues, and repository health risks.
Frequent scans on a regular basis (weekly or monthly) are recommended to continuously monitor for emerging risks. In addition, it is considered a best practice to re-scan a repository any time it is updated, preferably through SCM integration and automation.
Enterprises use repo health scores to evaluate the risks associated with open source components, guiding decisions on whether to adopt, update, or replace dependencies based on their security and operational risk scores.
A poor repo health score indicates that the repository may have security or operational risks, prompting further investigation and remediation steps, such as updating dependencies, improving security practices, or considering alternative libraries.
Checkmarx One
Everything enterprises need to secure application development from code to cloud on a unified platform.
Application Security Posture
Management (ASPM) Consolidated, correlated, prioritized insights to help your team manage risk
Code
AI PoweredConduct fast and accurate scans to identify risk in your custom code.
Identify vulnerabilities only seen in production and assess their behavior.
Eliminate shadow and zombie APls and mitigate API-specific risks.
Supply Chain
AI PoweredEasily identify, prioritize, remediate, and manage open source security and license risks.
Detect and remediate malicious or suspicious third-party packages that may be endangering your organization.
Built to accelerate AppSec teams and help developers secure applications from the first line of code.
Minimize risk by quickly identifying and eliminating exposed secrets.
Reduce security risks by health-scoring the code repositories used in your applications.
Cloud
AI PoweredScan container images, configurations, and identify open source packages and vulnerabilities preproduction and runtime.
Automatically scan your laC files for security vulnerabilities, compliance issues, and infrastructure misconfigurations.
Dev Enablement
Secure code training to upskill your developers and reduce risk from the first line of code.
Services
Maximize ROI with prioritized technical support, metrics monitoring, and operational assistance.
Augment your security team with Checkmarx services to ensure the success of your AppSec program.
Assess the current state of your AppSec program, benchmark against peers, and get actionable next steps for improvement.
Unified Dashboard, Reporting & Risk Management
Application Security Posture
Management (ASPM)
Consolidated, correlated, prioritized insights to help your team manage risk
AI Powered
Code
Static Application Security Testing (SAST)
Conduct fast and accurate scans to identify risk in your custom code.
Dynamic Application Security Testing (DAST)
Identify vulnerabilities only seen in production and assess their behavior.
API Security
Eliminate shadow and zombie APls and mitigate API-specific risks.
Supply Chain
Software Composition Analysis (SCA)
Easily identify, prioritize, remediate, and manage open source security and license risks.
Malicious Package Protection
Detect and remediate malicious or suspicious third-party packages that may be endangering your organization.
AI Security
Built to accelerate AppSec teams and help developers secure applications from the first line of code.
Secrets Detection
Minimize risk by quickly identifying and eliminating exposed secrets.
Repository Health
Reduce security risks by health-scoring the code repositories used in your applications.
Cloud
Container Security
Scan container images, configurations, and identify open source packages and vulnerabilities preproduction and runtime.
IaC Security
Automatically scan your laC files for security vulnerabilities, compliance issues, and infrastructure misconfigurations.
Get a Demo
Learn how automatic repository health tracking strengthens your software supply chain security.
Trusted By: