Appearance
Security scanning
Status: Planned. A standalone SPARK Security product is specified but not yet connected to Studio. Publishing today does not run these scans. This page describes what will exist and what protects you now.
Planned pipeline
Plugin code -> Build -> SAST -> Dependency scan -> Secret scan -> Container scan -> Quality and security gate -> PublishPlanned scan types
Code quality and SAST, dependency and license scanning, secret scanning, container scanning, OWASP checks; severity levels, quality and security gates that can block Publish, scan reports with developer remediation guidance, CI/CD integration. Scanner adapters (for example SonarQube, Semgrep, Trivy) sit behind one interface.
What protects you today
- Validation before publish (structure, references, permissions).
- Builds in isolated, disposable containers with limits and no network.
- Tests run before publish; failures stop Publish.
- Marketplace packages require dependencies to resolve; upgrade guard checks extensions.
- Secrets are never stored in plugin metadata; connectors keep them encrypted.
