GitProxy
A proxy that sits between developers and a Git remote and checks every push against policies.
Open source (Apache-2.0)By FINOS
Read the GitProxy documentation
Alternatives
About GitProxy
GitProxy stands between developers and a Git host such as GitHub. It applies configurable plugin rules to every outgoing git push over HTTPS or SSH and blocks pushes that fail. Example checks include allowed licences, secret detection, blocking data files and matching author e-mail domains.
It is aimed at firms in regulated industries such as financial services that want to contribute to open source while meeting security and legal rules. It can also run locally to enforce one developer's own practices. It runs on Node.js.
Strengths
- Supports both HTTPS and SSH pushes
- Policies are extensible through plugins
- Can catch secrets and data files before they leave the organisation
- Backed by maintainers from several large banks
Limitations
- Blocks all pushes by default until repositories are configured
- Requires Node.js and adds a hop to the push workflow
Details
- Pricing
- FreeFree and open source under the Apache 2.0 licence.
- License
- Apache-2.0
- Developer
- FINOS
- Platforms
- Self-hosted, Command line
- How it runs
- Downloadable app, Self-hosted
- Best suited for
- Organisations in regulated industries controlling what code is pushed to public repositories
- Categories
- Security tools, Developer tools
- Last verified
- Added