ASPM

Application Security Posture Management — consolidating SAST, SCA, secret, and IaC scanning across GitHub, GitLab, and Bitbucket into one onboarding and workflow surface, with CI-blocking quality gates on top.

The documents

SCM setup references

Step-by-step OAuth/App registration notes used when onboarding each source-control provider:

SCM App Setup 3 docs

Registration steps, required scopes, and token/refresh API calls for each provider.

Also in this folder: gitlab/setup/gitlab.yaml (self-hosted GitLab docker-compose), rotate-aspm-tokens.py (token rotation task), and onboarding screenshots under prototype/.


Back to top

© 2026 Ayush Aggarwal. Notes are living documents — they change as I learn, update, and reorganize them.