Skip to content

Security scanning ​

Status: Planned. A standalone SPARK Security product is specified but not yet connected to Studio. Publishing today does not run these scans. This page describes what will exist and what protects you now.

Planned pipeline ​

Plugin code -> Build -> SAST -> Dependency scan -> Secret scan -> Container scan -> Quality and security gate -> Publish

Planned scan types ​

Code quality and SAST, dependency and license scanning, secret scanning, container scanning, OWASP checks; severity levels, quality and security gates that can block Publish, scan reports with developer remediation guidance, CI/CD integration. Scanner adapters (for example SonarQube, Semgrep, Trivy) sit behind one interface.

What protects you today ​

  • Validation before publish (structure, references, permissions).
  • Builds in isolated, disposable containers with limits and no network.
  • Tests run before publish; failures stop Publish.
  • Marketplace packages require dependencies to resolve; upgrade guard checks extensions.
  • Secrets are never stored in plugin metadata; connectors keep them encrypted.

Testing, Plugin designer, Security.