To evaluate the tools/findings, we need should compare it with our current environment:
- Create scripts to pull repositories from Wikimedia for Gerrit, GitLab and GitHub, limited to just extensions for now
- Automate scanning repositories for semgrep and osv-scanner. To be extended to Phan and LibUp
- Ingest the data into DefectDojo via REST API
- Create SQL queries and datasets for Apache Superset and create dashboards