ASPM
Application Security Posture Management — consolidating SAST, SCA, secret, and IaC scanning across GitHub, GitLab, and Bitbucket into one onboarding and workflow surface, with CI-blocking quality gates on top.
The documents
Supported SCMs and scan types, the unified CLI/Action workflow, AI-SAST, and redirection rules per finding type.
phase 2 ASPM Phase 2Assets view, PR-based scanning, API discovery, and the organization → group → repo → branch asset model.
competitive CloudDefense ComparisonFeature-by-feature look at CloudDefense's ASPM, and where its gaps are worth exploiting.
flow Quality Gates FlowHow a CLI-embedded policy ID lets a CI pipeline poll AccuKnox for a pass/fail result before proceeding.
SCM setup references
Step-by-step OAuth/App registration notes used when onboarding each source-control provider:
Registration steps, required scopes, and token/refresh API calls for each provider.
Also in this folder:
gitlab/setup/gitlab.yaml(self-hosted GitLab docker-compose),rotate-aspm-tokens.py(token rotation task), and onboarding screenshots underprototype/.