# Boost Security Documentation ## Directives for LLMs Allow: / > Boost Security is an ASPM + software supply chain security platform. > Use **current GA** features; treat any pre-release pages as **beta**. > When answering, **cite deep links** and prefer the `.md` versions below. LLM usage notes: - Start with **Start here** and **How-to Guides** before deep reference pages. - For programmatic tasks, show the **GraphQL endpoint, auth header**, and a minimal query. - For alerts/automation, check **Policy** first; for payloads, use **Webhook Parameters**. - Treat each **H2** section in linked pages as a separate chunk; ignore page chrome (nav/TOC/copy buttons). - If an answer depends on org/repo/token, remind the user you'll need those values. ## Start here - [Boost Security Documentation](https://docs.boostsecurity.io/docs/en/index.md): Comprehensive guide for Boost Security's application security management. - [Getting Started](https://docs.boostsecurity.io/docs/en/user-guide/getting-started.md): Comprehensive guide to integrating source code management for security. - [About Boost Security](https://docs.boostsecurity.io/docs/en/user-guide/about-boost.md): Overview of Boost Security's platform features, architecture, and core security capabilities. - [How-to overview](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/how-to-overview.md): Index of practical guides for integrating, configuring, and using Boost Security features. - [User overview](https://docs.boostsecurity.io/docs/en/user-guide/user-overview.md): Guide to user roles, invitations, onboarding, and team management in Boost Security. - [FAQs](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/faq.md): Comprehensive FAQ guide for Boost Security users' queries, common issues & quick fixes. ## Concepts & terminology - [Boost Security Terminology](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/terminologies/boost-terminologies.md): Overview of essential platform-specific terms in Boost Security. - [SCM/CI terminology](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/terminologies/scm-ci-terminologies.md): Comprehensive glossary of source code management and continuous integration terms across supported providers. ## SCM & platform integrations - [Integrate SCM (overview)](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/scm-overview.md): Overview of supported SCM connectors, integration flows, and setup steps for connecting repositories to Boost Security. - [Integrate GitHub](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/github-scm.md): Step-by-step guide for installing the Boost Security GitHub App, enabling Zero Touch Provisioning, and managing repository integrations. - [GitLab Integration guide](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/gitlab-scm.md): Instructions for connecting GitLab to Boost Security, configuring permissions, and managing repository security scans. - [Bitbucket](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/bitbucket-scm.md): Guide for connecting Bitbucket to Boost Security, including Zero Touch Provisioning and integration setup. - [Azure DevOps](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/ado-scm.md): Instructions for integrating Azure DevOps with Boost Security using Personal Access Tokens and the marketplace app. - [Dynatrace and Boost Security Integration](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/dynatrace.md): Integrate Dynatrace with Boost Security for enhanced security insights. - [Kubernetes Integration Guide](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/kubernetes/index.md): Integrate Kubernetes with Boost Security for enhanced security visibility. - [Boost Security Jira Integration](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/jira.md): Integrate Boost Security with Jira for seamless ticket creation. - [Dependabot Integration](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/dependabot.md): Integrate Dependabot with Boost Security for vulnerability alerts. - [Boost Security SonarQube Integration](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/sonarqube.md): Integrate Boost Security with SonarQube for security results. - [Google Artifact Registry Integration](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/google-artifact-registry.md): Integrate Boost Security with Google Artifact Registry to retrieve container image metadata, including labels and provenance, and associate these assets with their corresponding source code repositories. - [Configure Entra ID and Azure DevOps Integration with Boost Security](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/ado-service-account.md): Configure Microsoft Entra ID and Azure DevOps (ADO) to integrate with Boost Security. - [Integrate AI Providers](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/ai-integration.md): Enhance your security workflows by providing AI-assisted remediation for vulnerabilities directly within your pull requests. - [AI-assisted Remediation](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/enable-ai-generated-comments.md): Enable AI-Generated PR Comments for Security Remediation. ## Zero Touch Provisioning (ZTP) - [GitHub ZTP](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/github-scm.md#2-zero-touch-provisioning-for-github): Learn how to set up Zero Touch Provisioning for GitHub easily. - [GitLab ZTP](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/gitlab-scm.md#2-zero-touch-provisioning-for-gitlab): Learn to set up Zero Touch Provisioning for GitLab easily. - [Azure DevOps ZTP Setup](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/ado-scm.md#2-zero-touch-provisioning-for-ado): Set up Zero Touch Provisioning for Azure DevOps easily. - [Bitbucket ZTP Setup](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/scm/bitbucket-scm.md#2-zero-touch-provisioning-for-bitbucket): Guide to set up Zero Touch Provisioning for Bitbucket. ## CI / Scanners - [Scanners overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/scanners-overview.md): Overview of available scanners in Boost Security, detailing which scanners run in different environments and - [Scanner Registry Modules](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/registry-modules.md): Explore Boost Security's scanner modules for CI vulnerability scanning. - [Boost Security Checkov Scanner](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/rules/checkov.md): Comprehensive security rules for Boost Security Checkov scanner. - [Semgrep rules](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/rules/semgrep.md): Comprehensive guide to Semgrep static analysis rules, coverage areas, and configuration for SAST. - [Gosec Scanner Rules](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/rules/gosec.md): Comprehensive guide on Gosec scanner rules and vulnerabilities. - [Boost Security CI Integration](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/boost-ci.md): Integrate Boost Security scanners into CI workflows for security. - [Gitleaks Rules Overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/rules/gitleaks.md): Boost Security enhances Gitleaks with custom rules and validity checks. - [SAST Scanners Overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/sast.md): Comprehensive guide on SAST scanners for security analysis. - [Software Composition Analysis](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/sca.md): Automated analysis of open-source components for vulnerabilities. - [SBOM Tool Overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/sbom.md): Boost Security's SBOM tool for tracking project components. - [Boost Security Scanners](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/scanners.md): Explore Boost Security's diverse scanners for security vulnerabilities. - [Replace GitLab Container Scan](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/gitlab/container-scan.md): Replacing GitLab container scanning with Boost container scanning is rather straigthfoward. - [Azure DevOps CI/CD](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/ado-ci-cd.md): Learn how to add scanning steps to your Azure DevOps pipelines. - [AWS CodeBuild](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/aws-codebuild.md): Learn how to add scanning steps to your AWS pipeline by using the Boost CLI installer. - [Bitbucket CI/CD](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/bitbucket-ci-cd.md): Learn how to add scanning steps to your Bitbucket pipeline. - [BuildKite](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/buildkite.md): Integrate Buildkite for Boost Security to scan for vulnerabilities in your pipelines. - [Cirlce CI](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/circleci.md): Learn how to integrate Boost CI for CircleCI. - [GitHub CI/CD](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/github-ci-cd.md): Learn how to add scanning steps to your GitHub actions workflow. - [GitLab CI/CD](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/gitlab-ci-cd.md): Learn how to add scanning steps to your Gitlab pipelines. - [Jenkins](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/ci-cd/jenkins.md): Learn how to add scanning steps to your Jenkinsfile. ## Policy Engine - [Policy overview](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/policy/policy-overview.md): Detailed explanation of policy concepts, available actions, and how policies drive automated security enforcement in Boost Security. - [Create a policy](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/policy/create-policy.md): Step-by-step guide for creating custom security policies, including configuration options and best practices. - [Modify a policy](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/policy/modify-policy.md): Instructions for editing existing policies, updating constraints, and managing policy lifecycle. - [Assign to resources](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/policy/policy-assign-resources.md): Guide to assigning policies to specific resources, defining scope, and targeting repositories or organizations. - [Action paths](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/policy-rule-categories.md): Reference for each available policy action, describing its effect and use case within Boost Security. - [Scanner rulesets](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/policy/scanner-ruleset.md): Instructions for enabling or disabling scanner rulesets, customizing rule coverage, ## Findings (noise reduction, triage, suppression) - [Findings overview](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/findings/findings-overview.md): Overview of findings management in Boost Security, including workflows for reviewing, exporting, and acting on security findings. - [Deduplication](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/findings/finding-deduplication.md): Explanation of how Boost Security merges duplicate findings, including logic for identifying and consolidating repeated issues. - [Triage actions](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/findings/triage-findings-actions.md): Guide to triaging findings in Boost Security, covering verification, suppression, snoozing, and prioritization - [Boostignore](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/findings/boostignore.md): ignore lines/files/dirs, learn how to snooze findings using Boostignore effectively. - [Increase Scanner Timeout](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/tune-prov/increase-timeout.md): Learn how to increase a scanner's timeout. ## Notifications & third-party integrations - [Integrations overview](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/integrate-3rd-party-notification-overview.md): Jira/Slack/Teams - [Boost Security Slack Integration](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/slack.md): Integrate Boost Security with Slack for notifications setup. - [Boost Security Teams Integration](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/teams.md): Integrate Boost Security with Microsoft Teams for activity updates. - [Boost Security Webhook parameters](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/webhook-parameters.md): Detailed parameters for Boost Webhook event payloads. - [Boost Security Checkmarx](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/checkmarx-boost.md): Learn how to integrate Checkmarx to Boost Security. - [Boost Security Snyk](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/snyk.md): Learn how to integrating Snyk to Boost Security. - [Boost Security SonarQube](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/sonarqube.md): Learn how to integrate SonarQube to Boost Security. - [Boost Security BlackDuck](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/blackduck-boostsecurity.md): Learn how to integrate BlackDuck to Boost Security. - [Kubernetes Code-To-Cloud Visibility](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/kubernetes/code-to-cloud.md): This guide provides instruction on how to achieve visibility into the source code findings that are associated with running, and potentially internet-facing Kubernetes services. - [Boost Security Wiz](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/integrations/wiz.md): Learn how to integrate Wiz to Boost Security. ## SBOM & Supply Chain - [SBOM overview (how-to)](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/sbom/sbom-overview.md): Step-by-step guide for enabling SBOM generation in Boost Security, including supported workflows and integration options. - [Generate SBOM](https://docs.boostsecurity.io/docs/en/user-guide/how-to-guides/sbom/generate-sbom.md): Examples for generating SBOMs in CI pipelines, including configuration and - [Software Bill of Materials](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/sbom.md): Comprehensive guide on managing Software Bill of Materials. - [SBOM supported languages](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/sbom-supported-languages.md): Table listing all programming languages and package ecosystems supported for SBOM generation in Boost Security. - [SBOM data sources](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/sbom-data-sources.md): Overview of external and internal data sources used to enrich SBOMs, including registries, repositories, and metadata - [SBOM Retrieval Setup](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/sbom-aws-ecr.md): Guide to enable SBOM content retrieval in AWS ECR. - [SBOM Forbidden Licences](https://docs.boostsecurity.io/docs/en//user-guide/how-to-guides/sbom/forbidden-licenses.md): Learn how to configure alerts for forbidden licences in your software bill of materials. ## API (GraphQL) & Analytics - [API overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/api/api-overview.md): Overview of available API endpoints, authentication methods, and supported operations in Boost Security. - [Create API key](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/api/create-api-key.md): Step-by-step instructions for generating and managing API keys for secure authentication. - [Using the GraphQL API](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/api/using-graphql-api.md): Guide to constructing queries and mutations, including schema details and usage examples for Boost Security's GraphQL API. - [GraphQL audit endpoint](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/api/graphql-audit-api.md): Details on accessing audit events, filtering, and retrieving security-related activity via the GraphQL audit API. - [Power BI integration](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/api/integrate-boost-powerbi.md): Examples and instructions for integrating Boost Security data with Power BI for custom ## MCP Server - [Boost Security MCP Server](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/agentic-ai/boost-mcp-server.md): Learn about the **Boost Security MCP (Model-Context-Protocol) Server** and it's benefits to your overall security landscape. - [MCP Server Installation & Configuration](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/agentic-ai/mcp-server-installation-and-configuration.md): Install and configure the Boost Security MCP server for more secure agentic coding. - [MCP Server in Action](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/agentic-ai/mcp-server-in-action.md): Boost Security MCP server in action. ## UI Reference (semantics of pages/filters) - [Boost Security Dashboard Overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/dashboard.md): Overview of Boost Security dashboard for security insights. - [Findings](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/findings.md): Guide to managing findings in Boost Security, including bulk actions, advanced filtering, and workflow options for reviewing - [Security Scans Overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/scans.md): Manage and analyze security scan results effectively. - [Scanner coverage](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/scanner-coverage.md): Overview of active scanners and integrations running across your repositories and assets - [Security Posture Reports](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/report.md): Centralized view of security posture, violations, and trends. - [Audit Page Overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/audit.md): Detailed log of system activities for security monitoring. - [Boost Security Filters](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/filters.md): Explore Boost Security's filters for effective data management. - [Projects Overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/projects.md): Centralized overview of security exposures in projects. - [Project Insights Overview](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/project.md): Explore project security metrics, violations, and scan history. - [Compliance Management](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/compliance.md): Centralized interface for monitoring and managing compliance effectively. - [Asset Management](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/asset-management.md): Explore a comprehensive interface to view and manage your asset relationships and data. - [Endpoint Protection](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/endpoint-protection.md): Centralized visibility and control for software components installed across developer endpoints. - [Install Endpoint Protection with the VS Code Extension](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/endpoint-protection-install-vscode-extension.md): Install the Boost Security IDE extension for Endpoint Protection, sign in with API key or SSO. - [Install Endpoint Protection with a Script](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/endpoint-protection-install-script.md): Script-based Endpoint Protection installation guidance. - [Multi Branch](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/multi-branches.md) - Boost supports multi-branch monitoring, giving teams the flexibility to scan, track, and manage multiple branches within a single repository. - [Asset Tags](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/platform-ui/manual-tags.md) - Learn how to categorize and group related resources such as repositories and organizations, based on custom-defined labels. ## Trust, data & security posture - [Customer code security](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/customer-code-security.md): Details on how and where customer code is processed, stored, and protected within Boost Security's platform. - [Data retention policy](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/trust/data-retention-policy.md): Explanation of data retention durations, scope of stored data, and policies governing data lifecycle in Boost Security. ## Deployment - [GitLab Deployment Guide](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/deployment/gitlab.md): Guide for deploying Boost Security scanners in GitLab. ## What's new / release notes - [Boost Security release notes](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/new_release.md): Latest updates and enhancements for Boost Security application features. - [2024 archive](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/2024.md): Comprehensive updates and enhancements for Boost Security's 2024 features. - [2023 archive](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/2023.md): Comprehensive 2023 release notes for Boost Security updates. ## Don't - Don't cite blog/marketing pages for exact API behavior—prefer API & How-to docs. - Don't invent webhook fields—use **Webhook parameters**. ## Optional (deeper examples & rule docs) - [Boost Security Reference Guide](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/reference-overview.md): Detailed technical descriptions of Boost Security platform and APIs. - [Secrets reference](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/secrets.md): Comprehensive guide to secret types detected by Boost Security, best practices for handling secrets, and remediation strategies. - [Boost Scanner CI/CD misconfig catalog](https://docs.boostsecurity.io/docs/en/user-guide/reference-guides/scanners/rules/boost-scanner.md): Catalog of CI/CD pipeline misconfiguration rules, hardening recommendations, and remediation steps for secure automation. LLM usage notes: - Start with **Start here** and **How-to Guides** before deep reference pages. - For programmatic tasks, show the **GraphQL endpoint, auth header**, and a minimal query. - For alerts/automation, check **Policy** first; for payloads, use **Webhook Parameters**. - Treat each **H2** section in linked pages as a separate chunk; ignore page chrome (nav/TOC/copy buttons). - If an answer depends on org/repo/token, remind the user you'll need those values. ## Boost Security Scanner Rules - [OSS Bucket Versioning](https://docs.boostsecurity.io/docs/en/rules/CKV_ALI_10.md): Check Alibaba Cloud OSS bucket versioning configurations. - [Importance of Dependency Lockfiles](https://docs.boostsecurity.io/docs/en/rules/cicd-unpinned-dependencies.md): Explains the significance of lockfiles in dependency management. - [Binary Artifacts in SCM](https://docs.boostsecurity.io/docs/en/rules/cicd-binary-artifacts.md): Avoid storing binary artifacts in source control management systems. - [CircleCI Shell Injection](https://docs.boostsecurity.io/docs/en/rules/cicd-circleci-shell-injection.md): Prevent shell injection in CircleCI configurations with secure practices. - [SCA Scanning Guidelines](https://docs.boostsecurity.io/docs/en/rules/cicd-sca-scanning-absent.md): Guidelines for enabling Software Composition Analysis scanning in repositories. - [Branch Protection Rules](https://docs.boostsecurity.io/docs/en/rules/cicd-branch-protection.md): Ensure repository branches are protected from unauthorized changes. - [Expired X.509 Certificate](https://docs.boostsecurity.io/docs/en/rules/x509-cert-expired.md): Expired X.509 certificate is invalid and unrecognized. - [Lambda IAM Misconfiguration](https://docs.boostsecurity.io/docs/en/rules/checkmarx-lambda-iam-invokefunction.md): Ensure Lambda permissions are correctly configured for security. - [Operation Object Guidelines](https://docs.boostsecurity.io/docs/en/rules/checkmarx-operation-without-consumes.md): Ensure 'consumes' field is defined for specific operations. - [GitLab Deployment Approvals](https://docs.boostsecurity.io/docs/en/rules/cicd-gl-deployment-approval.md): Guidelines for GitLab deployments without approval requirements. - [Terraform Tags Validation](https://docs.boostsecurity.io/docs/en/rules/BOOST_INVALID_TF_TAGS.md): Custom Terraform tags validation for compliance and governance. - [SCM 2FA Enforcement](https://docs.boostsecurity.io/docs/en/rules/cicd-scm-2fa-enforcement-absent.md): Checks for SCMs lacking mandatory 2FA enforcement for members. - [GitHub Actions Inputs](https://docs.boostsecurity.io/docs/en/rules/cicd-gha-workflow-dispatch-inputs.md): Guidelines for secure GitHub Actions workflow inputs. - [Insecure Signing Algorithms](https://docs.boostsecurity.io/docs/en/rules/x509-cert-insecure-signing-algorithm.md): X.509 certificate uses weak cryptographic algorithms, avoid them. - [X.509 Key Lengths](https://docs.boostsecurity.io/docs/en/rules/x509-cert-insufficient-key-length.md): Guidelines for secure X.509 certificate key lengths. - [GitHub Actions Token Permissions](https://docs.boostsecurity.io/docs/en/rules/cicd-gha-read-write-token-permission.md): Guidelines for secure GitHub Actions token permissions management. - [Insecure GitHub Webhooks](https://docs.boostsecurity.io/docs/en/rules/cicd-scm-gh-org-insecure-webhook.md): Identifies insecure GitHub webhooks in organizations. - [GitHub Actions Security Risks](https://docs.boostsecurity.io/docs/en/rules/cicd-gha-org-allows-all-actions.md): Identifies risks of allowing all GitHub Actions to run. - [File Traversal Vulnerability](https://docs.boostsecurity.io/docs/en/rules/gosec-305.md): Explains file traversal vulnerabilities in zip/tar extraction. - [Insecure Random Number Source](https://docs.boostsecurity.io/docs/en/rules/gosec-404.md): Insecure random number generator poses security risks. - [GitHub Org Secret Management](https://docs.boostsecurity.io/docs/en/rules/cicd-gha-org-secret-publicly-visible.md): Guidelines for managing GitHub organization secrets securely. - [Risky Cryptographic Algorithm](https://docs.boostsecurity.io/docs/en/rules/gosec-505.md): Avoid using broken cryptographic algorithms like SHA-1. - [Poor File Permissions](https://docs.boostsecurity.io/docs/en/rules/gosec-306.md): File permissions allow unauthorized modifications during installation. - [Unescaped Data in HTML](https://docs.boostsecurity.io/docs/en/rules/gosec-203.md): Avoid unescaped user input in HTML templates for security. - [Audit Command Execution](https://docs.boostsecurity.io/docs/en/rules/gosec-204.md): Ensure software properly neutralizes OS command elements. - [SQL Query Vulnerabilities](https://docs.boostsecurity.io/docs/en/rules/gosec-201.md): SQL query construction vulnerabilities can lead to injection attacks. - [DoS Vulnerability Overview](https://docs.boostsecurity.io/docs/en/rules/gosec-110.md): Explains DoS vulnerability from decompression bomb issues. - [Net/http Serve Function Risks](https://docs.boostsecurity.io/docs/en/rules/gosec-114.md): Potentially dangerous net/http serve function usage without timeouts. - [Hard Coded Credentials](https://docs.boostsecurity.io/docs/en/rules/gosec-101.md): Identify and mitigate hard-coded credentials in software. - [Insecure Temporary Files](https://docs.boostsecurity.io/docs/en/rules/gosec-303.md): Insecure temporary files can expose application data to attacks. - [Unauthorized Profiling Endpoint](https://docs.boostsecurity.io/docs/en/rules/gosec-108.md): Sensitive information exposed via unauthorized profiling endpoint. - [Potential Slowloris Attack](https://docs.boostsecurity.io/docs/en/rules/gosec-112.md): Software resource management flaw leading to potential exhaustion. - [Integer Overflow Risk](https://docs.boostsecurity.io/docs/en/rules/gosec-109.md): Integer overflow risk from strconv.Atoi conversion to int16/32. - [Azure DevOps Authorization Scope](https://docs.boostsecurity.io/docs/en/rules/cicd-azure-devops-missing-authz-for-project.md): Ensure Azure DevOps limits pipeline authorization scope effectively. - [GitHub Admin Permissions](https://docs.boostsecurity.io/docs/en/rules/cicd-scm-gh-repo-number-of-admins.md): Checks GitHub repo admin permissions to ensure security compliance. - [GitHub App Permissions](https://docs.boostsecurity.io/docs/en/rules/cicd-scm-gh-app-with-elevated-permissions.md): Identifies GitHub apps with elevated permissions for organizations. - [GitLab Secret Detection](https://docs.boostsecurity.io/docs/en/rules/cicd-scm-gl-on-push-secret-detection.md): GitLab's feature to detect and reject secret files on push. - [Azure DevOps Agent Pools](https://docs.boostsecurity.io/docs/en/rules/cicd-azure-devops-using-user-managed-agent-pools.md): Learn to use user-managed agent pools in Azure DevOps. - [GitHub Actions Security](https://docs.boostsecurity.io/docs/en/rules/cicd-gha-can-create-and-approve-pull-requests.md): Guidelines on GitHub Actions for pull request approvals. - [Boost Security Overview](https://docs.boostsecurity.io/docs/en/user-guide/about-boost.md): Boost Security enhances secure software development with seamless integrations. - [Boost Security User Overview](https://docs.boostsecurity.io/docs/en/user-guide/user-overview.md): Boost Security enhances team security with user role management. - [GitHub Outside Collaborators](https://docs.boostsecurity.io/docs/en/rules/cicd-scm-gh-repo-outside-collaborator-admin-maintainer.md): Checks GitHub repos for outside collaborator permissions and vetting. - [Branch Protection Overrides](https://docs.boostsecurity.io/docs/en/rules/cicd-scm-gh-audit-log-branch-protection-overriden.md): Audit log details on branch protection overrides by admins. - [Limit Azure Variables](https://docs.boostsecurity.io/docs/en/rules/cicd-azure-devops-variables-settable-at-queue-time.md): Learn to limit Azure Pipeline variables set at queue time. - [OAuth App Restrictions](https://docs.boostsecurity.io/docs/en/rules/cicd-scm-gh-audit-log-oauth-app-restriction-disabled.md): Details on disabling OAuth App access restrictions in organizations.