SAMMY UI is optimized for resolutions with a width 1024px and higher.
Maturity Level 2
Maturity Level 3
Maturity Level 4
Maturity Level 5
Software Composition Analysis (server side)
T-SA-2-2: Software Composition Analysis (server side)
  • Tests for known vulnerabilities in server side components (e.g. backend/middleware) are performed.
Description

Tests for known vulnerabilities in server side components (e.g. backend/middleware) are performed.

Risk:Server side components might have vulnerabilities.

Test for Time to Patch
T-SA-2-3: Test for Time to Patch
  • Test of the Time to Patch (e.g. based on Mean Time to Close automatic PRs) This activity is not repeated in the Sub-Dimension "Static depth for infrastructure", but it applies to infrastructure as well.
Description

Test of the Time to Patch (e.g. based on Mean Time to Close automatic PRs) This activity is not repeated in the Sub-Dimension "Static depth for infrastructure", but it applies to infrastructure as well.

Risk:Automatic PRs for dependencies are overlooked resulting in known vulnerabilities in production artifacts.

Test libyear
T-SA-2-4: Test libyear
  • Test `libyear`, which provides a good insight how good patch management is.
Description

Test `libyear`, which provides a good insight how good patch management is.

Risk:Vulnerabilities in running artifacts stay for long and might get exploited.