Want to protect your software supply chain from attacks?
Learn how!Checkmarx One
Improve your security posture with full visibility into the security, dependency management, and maintenance health of the code repositories used in your applications.
Without repo health monitoring, repositories are at risk of unauthorized code changes, dangerous or low-quality code, regulatory non-compliance, and other security threats.
Continuous Repo Health Scoring
Track health scores for all repositories included in your applications based on factors including security practices, testing practices, dependency management, CI/CD best practices, and project maintenance.
Automatic SCM-Triggered Scans
Integration with SCM platforms enables scans to run automatically upon repository updates, ensuring up-to-date repo health metrics with no manual effort.
Flexible On-Demand Scanning Options
In addition to automatic SCM-triggered scans, developers and security teams can manually run repo health scans at any time via API, CLI, or the Checkmarx One UI.
Unified Risk Reporting
Repository health scores are included in Checkmarx One reports, providing visibility into – and efficient prioritization of – security vulnerabilities, code quality issues, and repository health risks, all in one place.
Track health scores for all repositories included in your applications based on factors including security practices, testing practices, dependency management, CI/CD best practices, and project maintenance.
Integration with SCM platforms enables scans to run automatically upon repository updates, ensuring up-to-date repo health metrics with no manual effort.
In addition to automatic SCM-triggered scans, developers and security teams can manually run repo health scans at any time via API, CLI, or the Checkmarx One UI.
Repository health scores are included in Checkmarx One reports, providing visibility into – and efficient prioritization of – security vulnerabilities, code quality issues, and repository health risks, all in one place.
Learn how you can use repository health scoring to improve your application security posture.
What’s in it for you
Continuous repository health monitoring helps minimize the threat exposure of vulnerable code repos, leading to improved security and enhanced transparency with stakeholders.
Modern code repositories store application source code, CI/CD configurations, IaC files and other sensitive data. Software supply chain attacks are rising steeply; poorly managed internal code repos are a weak point in an organization’s software supply chain security posture. Because large enterprises typically maintain thousands of repos, it is impossible to manually track how well each of them is configured, maintained, and secured. An automated solution is needed to continuously determine the security and code-quality health of internal code repos.
Checkmarx’ Repository Health helps you maximize the security posture of your applications by automatically and continuously tracking the security and quality practices applied to your code repositories. Each repo is scored on its security policies and best practices, including:
OSSF Scorecard is an open source project created by the Open Source Security Foundation (OpenSSF) that assesses code repositories for security risks through a series of automated checks. Checkmarx One incorporates the results of OSSF Scorecard metrics in its reports so that developers and security teams can improve their visibility into security vulnerabilities, code quality issues, repository maintenance standards, and other repository health risks.
Frequent scans on a regular basis (weekly or monthly) are recommended to continuously monitor repositories for emerging risks. In addition, it is considered a best practice to re-scan a repository any time it is updated, preferably through SCM integration and automation.
Enterprises use repo health scores to evaluate the risks associated with open source components, guiding decisions on whether to adopt, update, or replace dependencies based on their security and operational risk scores.
A poor repo health score indicates that the repository may have security or operational risks, prompting further investigation and remediation steps. To maximize application security posture, repositories must be protected from the risks of unauthorized code changes, dangerous or low-quality code, regulatory non-compliance, and other security threats.
Checkmarx One
Everything enterprises need to secure application development from code to cloud on a unified platform.
Application Security Posture
Management (ASPM) Consolidated, correlated, prioritized insights to help your team manage risk
Code
AI PoweredConduct fast and accurate scans to identify risk in your custom code.
Identify vulnerabilities only seen in production and assess their behavior.
Eliminate shadow and zombie APls and mitigate API-specific risks.
Supply Chain
AI PoweredEasily identify, prioritize, remediate, and manage open source security and license risks.
Detect and remediate malicious or suspicious third-party packages that may be endangering your organization.
Built to accelerate AppSec teams and help developers secure applications from the first line of code.
Minimize risk by quickly identifying and eliminating exposed secrets.
Reduce security risks by health-scoring the code repositories used in your applications.
Cloud
AI PoweredScan container images, configurations, and identify open source packages and vulnerabilities preproduction and runtime.
Automatically scan your laC files for security vulnerabilities, compliance issues, and infrastructure misconfigurations.
Dev Enablement
Secure code training to upskill your developers and reduce risk from the first line of code.
Services
Maximize ROI with prioritized technical support, metrics monitoring, and operational assistance.
Augment your security team with Checkmarx services to ensure the success of your AppSec program.
Assess the current state of your AppSec program, benchmark against peers, and get actionable next steps for improvement.
Unified Dashboard, Reporting & Risk Management
Application Security Posture
Management (ASPM)
Consolidated, correlated, prioritized insights to help your team manage risk
AI Powered
Code
Static Application Security Testing (SAST)
Conduct fast and accurate scans to identify risk in your custom code.
Dynamic Application Security Testing (DAST)
Identify vulnerabilities only seen in production and assess their behavior.
API Security
Eliminate shadow and zombie APls and mitigate API-specific risks.
Supply Chain
Software Composition Analysis (SCA)
Easily identify, prioritize, remediate, and manage open source security and license risks.
Malicious Package Protection
Detect and remediate malicious or suspicious third-party packages that may be endangering your organization.
AI Security
Built to accelerate AppSec teams and help developers secure applications from the first line of code.
Secrets Detection
Minimize risk by quickly identifying and eliminating exposed secrets.
Repository Health
Reduce security risks by health-scoring the code repositories used in your applications.
Cloud
Container Security
Scan container images, configurations, and identify open source packages and vulnerabilities preproduction and runtime.
IaC Security
Automatically scan your laC files for security vulnerabilities, compliance issues, and infrastructure misconfigurations.
See it in action
Learn how automatic repository health tracking strengthens your software supply chain security.
Trusted By: