// the find
DefectDojo/django-DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
DefectDojo is a Django app for vulnerability management: it ingests scan output from dozens of SAST/DAST/SCA tools, deduplicates findings across tools, and tracks remediation through engagements and products. It's aimed at AppSec teams who already run multiple scanners and need one place to correlate and report on the results, not at individual developers.
It's an OWASP flagship project with a decade of history and a real moderator structure (not just a solo maintainer), which shows in the CI setup — separate unit, integration, k8s, and performance test workflows all gating merges. The parser ecosystem is the actual value: support for a long list of scanner formats with cross-tool deduplication logic, which is the hard, tedious part most teams end up half-building themselves. Docker Compose quick start gets a working instance with admin credentials in under 5 minutes, and there's a documented REST API v2 plus client wrappers for automation.
The README spends more space on Pro-edition upsell badges and Hall of Fame credits than on architecture or data model — you'll be reading external docs (docs.defectdojo.com) to understand how products/engagements/tests actually relate before you can use the API sensibly. It's a full Django + Celery + Postgres + nginx stack, so self-hosting is a real operational commitment, not a single binary. The initializer taking up to 3 minutes on first boot and requiring a log-grep for the admin password is a rough first-run experience. Feature split between OSS and Pro (risk-based prioritization, ServiceNow/GitHub/GitLab connectors, better UI) means the free version is explicitly the stripped-down path, which shapes what you can expect to extend yourself.