Skip to content
servasecPublic

Latest commit

 

History

215 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

servasec open source ASPM

servasec - Open Source ASPM

GitHub Stars Release badge badge

Application Security Posture Management (ASPM) platform that aggregates SAST/DAST/SCA scanner findings into a unified dashboard for triaging, tracking, and remediating security vulnerabilities across your application portfolio.

Features

Feature Free Pro
Findings management & lifecycle ✓ ✓
Dashboard with enriched stats ✓ ✓
Team-based collaboration ✓ ✓
Webhook notifications ✓ ✓
RBAC ✓ ✓
Issue Tracker (GitHub, GitLab) ✓ ✓
Resource-level permissions ✓ ✓
Scanner ingest (Semgrep, Trivy, etc.) ✓ ✓
Version comparison ✓ ✓
SSO / OIDC ✓
Audit log ✓
MCP Server ✓
SLA management (planned) ✓
Advanced reporting (planned) ✓

Quick start

Interactive mode (prompts for admin password, domain, registration):

curl -fsSL https://servasec.com/install.sh | sh -s -- -i

Build from source (local build instead of pulling published images):

curl -fsSL https://servasec.com/install.sh | sh -s -- --local-build

Install with pro features:

# Pull mode: uses the private backend-pro image from the servasec-pro project (authenticate first)
docker login registry.gitlab.com -u $CUSTOMER_UUID -p $CUSTOMER_TOKEN
curl -fsSL https://servasec.com/install.sh | sh -s -- --pro

Pro features are available with a valid subscription of servasec.
Please refer to servasec.com/pricing to obtain one.

Manual setup (without the install script):

git clone https://github.com/servasec/servasec.git
cd servasec
cp .env.example .env
# Edit secrets (JWT_SECRET, REFRESH_SECRET, CSRF_SECRET, SSC_ADMIN_PASSWORD)

# Pull the published images from registry.gitlab.com
make community

# Or build from source instead
make community-build

Scanner support

Look at https://docs.servasec.com/scanners/overview/ for the complete list of scanners supported.

Frequently Asked Questions

Is servasec free and open source?

Yes, servasec is licensed under AGPLv3. Self-host it for free, forever. A separate commercial license is required only for Pro features (audit log, MCP Server, SSO, etc).

Which scanners does servasec support?

servasec ingests Semgrep, Trivy, Gitleaks, OSV-Scanner, tfsec, SARIF exports and a lot more ! See supported scanners for details.

Environment Variables

See https://docs.servasec.com/getting-started/configuration/

License

servasec is dual-licensed:

  • AGPLv3 - Free, open-source. All standard features included.
  • Commercial License - Required for pro features (audit log, MCP, SLA management, advanced reporting).

See LICENSE and COMMERCIAL_LICENSE.md.

Development

# Start dev stack with hot-reload
make dev

# View logs
make logs

# Stop
make down

Requires: Docker, Docker Compose, make.

Releases

Packages

Used by

Contributors

Languages