About this project

DefectDojo is an open-source vulnerability management, DevSecOps and application security posture management (ASPM) platform, and an OWASP flagship project. It is designed to orchestrate end-to-end security testing, vulnerability tracking, deduplication, remediation and reporting. Key capabilities described in the README: - Aggregates and manages findings from security testing workflows, with deduplication and remediation tracking. - Reporting features for vulnerability data. - A large set of supported tool parsers for importing scan reports, plus sample scan reports in the repository for testing. - REST APIs, with documented client APIs and wrappers. - Authentication options including OAuth2/SAML2 and LDAP. - Deployment via Docker Compose; a quick start clones the repository and runs `docker compose up`, with admin credentials available in the initializer logs. A Pro edition is offered as SaaS or self-hosted via Kubernetes or Docker Compose. Public demo environments are available for both the Pro and OWASP Community editions, reset daily, and should not be used for sensitive data. Documentation, contributing guidelines, a security disclosure policy and BSD 3-Clause licensing are referenced. The project is maintained by named maintainers and moderators, with community channels on Slack, LinkedIn, YouTube and X.