GitHub Security Tool Integration

Job ID: 40326947

Budget: $250 – $750 USD

Enhance an existing SecDevOps workflow with SonarQube, Snyk and similar tools into GitHub repository so every pull request automatically triggers code-quality and security scans. Surface actionable findings early in the lifecycle and block merges that don’t meet quality gates.

Deliverables
• Pipeline configuration (YAML) that runs SonarQube, Snyk, and WhiteSource on each push and pull request
• Quality-gate rules defined in SonarQube and enforced in the workflow
• Secure handling of API keys/secrets through GitHub Secrets
• A brief README explaining setup, how to interpret the reports, and how to update tool versions

Acceptance criteria
• All scans execute in under 10 minutes on a medium-sized codebase
• Failed quality gates or high-severity findings block the merge with clear messaging
• No plaintext credentials committed; secrets load only from secure storage

Please only bid if you have SecDevOps experience