Automated ASP.NET Security Review
Budget: $10 – $100 USD
I want to put a fully-automated static security code-review workflow around our ASP.NET Framework and ASP.NET Core repositories. I have already settled on SonarQube as the analysis engine, and I need an Application Security / DevSecOps engineer who can design, build and document the entire pipeline.
Here is what I am after:
• End-to-end CI/CD integration
– every commit and pull request should trigger a SonarQube scan and fail the build when high-severity issues appear.
• Custom rule set
– we do not yet have our own rules. I will rely on you to translate our security policies into SonarQube custom rules that focus on Authentication & Authorization, Data Validation & Sanitization, and Error Handling & Logging, plus any additional attack surface you consider relevant.
• Secure baseline and tuning
– thresholds, quality gates, and branch policies so developers get rapid feedback but aren’t flooded with noise.
• Knowledge transfer
– concise documentation and a walkthrough so my team understands how to maintain the rules and keep SonarQube healthy.
Acceptance criteria
1. A pipeline build from a sample branch shows a green build with no critical findings, then deliberately injected flaws cause the build to fail.
2. At least five custom rules demonstrate detection of our most common mistakes.
3. Documentation covers installation, rule authoring, upgrades, and day-to-day use.
If you have experience with Fortify or Checkmarx as well, let me know; cross-tool insights are always welcome, but SonarQube will be the implementation target.
Please outline your approach, similar past work, and the estimated timeline to reach a production-ready setup.
Here is what I am after:
• End-to-end CI/CD integration
– every commit and pull request should trigger a SonarQube scan and fail the build when high-severity issues appear.
• Custom rule set
– we do not yet have our own rules. I will rely on you to translate our security policies into SonarQube custom rules that focus on Authentication & Authorization, Data Validation & Sanitization, and Error Handling & Logging, plus any additional attack surface you consider relevant.
• Secure baseline and tuning
– thresholds, quality gates, and branch policies so developers get rapid feedback but aren’t flooded with noise.
• Knowledge transfer
– concise documentation and a walkthrough so my team understands how to maintain the rules and keep SonarQube healthy.
Acceptance criteria
1. A pipeline build from a sample branch shows a green build with no critical findings, then deliberately injected flaws cause the build to fail.
2. At least five custom rules demonstrate detection of our most common mistakes.
3. Documentation covers installation, rule authoring, upgrades, and day-to-day use.
If you have experience with Fortify or Checkmarx as well, let me know; cross-tool insights are always welcome, but SonarQube will be the implementation target.
Please outline your approach, similar past work, and the estimated timeline to reach a production-ready setup.
Related categories:
.NET
C# Programming
ASP.NET
Microsoft SQL Server
Documentation
Continuous Integration
.NET Core
CI/CD