Skip to content
Abierto

Sources sought

SonarQube Alternate Sources

RFI_HNC_SonarQube

Department of the Air Force, FA8307 AFLCMC HNCK HNC Cyber & NTR. Software Publishers.

Response deadline

August 9, 2024 at 9:00 AM EDT

Closed 769 days ago. Posted August 1, 2024. Scheduled to archive August 24, 2024.

Description

As published on SAM.gov.

Our organization is currently leveraging SonarQube for continuous cybersecurity and testing activities. In an effort to identify potential alternatives, we are conducting market research to evaluate products and solutions that can meet the following requirements. The organizational objectives of this research are as follows:

Identify and catalog available products and solutions in the market. Evaluate the features, functionality, and pricing of each alternative to determine its suitability for our needs. Assess the level of integration and compatibility of each alternative with our DevSecOps platform, while ensuring compliance with DoD security requirements. Estimate the level of government resources required to migrate to a new solution, while maintaining our current operational capabilities.

The following are some of the key characteristics that we are using to meet our organizational objectives, as outlined in paragraph 3. While this list is not exhaustive, it does provide a snapshot of some of the most important requirements for our environment.

To meet DoD CIO DevSecOps Reference Design compliance and perform continuous cybersecurity and testing activities, the tool must provide the following features: Static application security test and scan (SAST) Static code analysis Source code linting Source code test coverage CI/CD integration Customizable security scanning and reporting The tool must support the following programming languages: C# TypeScript CSS HTML Go PHP Helm Java JavaScript Python XML Terraform Ruby Scala Swift Objective-C C C++ PL/SQL TSQL VB.NET The tool must integrate with the following package managers: Maven Gradle PyPi NPM .NET The tool must support multiple application development projects and provide a means to integrate with user authentication and authorization methods such as SAML or OIDC.

Publications

Every notice SAM.gov issued under this solicitation number, oldest first. Each is a separate record on SAM.

  1. August 1, 2024

    Sources sought

    Due August 9, 2024 at 9:00 AM EDT. SAM.gov, notice 96413272b28e412da0607660784689d0

Points of contact