Introducing ScopeGuardian - security scanning orchestrator, simplified for your CI/CD pipelines.
We built ScopeGuardian to make it effortless to run multiple security scanners on your codebase and automatically sync findings to DefectDojo; all in one command.
What it does:
IaC scanning with KICS (Dockerfile, Terraform, Kubernetes, and more)
SCA / dependency vulnerabilities with Grype + Syft SBOM generation
Auto-sync findings to DefectDojo (with deduplication)
Security gate — fail your pipeline if critical/high findings exceed your thresholds
Drop it in your pipeline in minutes with Docker, configure what you need in a simple config.toml, and let ScopeGuardian handle the rest.
🔗 https://scope-guardian.paranoihack.ch