GitHub Security Tool Integration
Budget: $250 – $750 USD
Enhance an existing SecDevOps workflow with SonarQube, Snyk and similar tools into GitHub repository so every pull request automatically triggers code-quality and security scans. Surface actionable findings early in the lifecycle and block merges that don’t meet quality gates.
Deliverables
• Pipeline configuration (YAML) that runs SonarQube, Snyk, and WhiteSource on each push and pull request
• Quality-gate rules defined in SonarQube and enforced in the workflow
• Secure handling of API keys/secrets through GitHub Secrets
• A brief README explaining setup, how to interpret the reports, and how to update tool versions
Acceptance criteria
• All scans execute in under 10 minutes on a medium-sized codebase
• Failed quality gates or high-severity findings block the merge with clear messaging
• No plaintext credentials committed; secrets load only from secure storage
Please only bid if you have SecDevOps experience
Deliverables
• Pipeline configuration (YAML) that runs SonarQube, Snyk, and WhiteSource on each push and pull request
• Quality-gate rules defined in SonarQube and enforced in the workflow
• Secure handling of API keys/secrets through GitHub Secrets
• A brief README explaining setup, how to interpret the reports, and how to update tool versions
Acceptance criteria
• All scans execute in under 10 minutes on a medium-sized codebase
• Failed quality gates or high-severity findings block the merge with clear messaging
• No plaintext credentials committed; secrets load only from secure storage
Please only bid if you have SecDevOps experience
Related categories:
Software Development
Git
API
Continuous Integration
Security
DevOps
GitHub
Automation