SOURCES SOUGHT
99 -- SonarQube Alternate Sources
- Notice Date
- 8/1/2024 1:06:03 PM
- Notice Type
- Sources Sought
- NAICS
- 513210
—
- Contracting Office
- FA8307 AFLCMC HNCK C3IN SAN ANTONIO TX 78243-7007 USA
- ZIP Code
- 78243-7007
- Solicitation Number
- RFI_HNC_SonarQube
- Response Due
- 8/9/2024 6:00:00 AM
- Archive Date
- 08/24/2024
- Point of Contact
- Karin Werner, Marisa Flores
- E-Mail Address
-
karin.werner.1@us.af.mil, marisa.flores.2@us.af.mil
(karin.werner.1@us.af.mil, marisa.flores.2@us.af.mil)
- Description
- Our organization is currently leveraging SonarQube for continuous cybersecurity and testing activities. In an effort to identify potential alternatives, we are conducting market research to evaluate products and solutions that can meet the following requirements. The organizational objectives of this research are as follows: Identify and catalog available products and solutions in the market. Evaluate the features, functionality, and pricing of each alternative to determine its suitability for our needs. Assess the level of integration and compatibility of each alternative with our DevSecOps platform, while ensuring compliance with DoD security requirements. Estimate the level of government resources required to migrate to a new solution, while maintaining our current operational capabilities. The following are some of the key characteristics that we are using to meet our organizational objectives, as outlined in paragraph 3. While this list is not exhaustive, it does provide a snapshot of some of the most important requirements for our environment. To meet DoD CIO DevSecOps Reference Design compliance and perform continuous cybersecurity and testing activities, the tool must provide the following features: Static application security test and scan (SAST) Static code analysis Source code linting Source code test coverage CI/CD integration Customizable security scanning and reporting The tool must support the following programming languages: C# TypeScript CSS HTML Go PHP Helm Java JavaScript Python XML Terraform Ruby Scala Swift Objective-C C C++ PL/SQL TSQL VB.NET The tool must integrate with the following package managers: Maven Gradle PyPi NPM .NET The tool must support multiple application development projects and provide a means to integrate with user authentication and authorization methods such as SAML or OIDC.
- Web Link
-
SAM.gov Permalink
(https://sam.gov/opp/96413272b28e412da0607660784689d0/view)
- Place of Performance
- Address: San Antonio, TX, USA
- Country: USA
- Country: USA
- Record
- SN07153949-F 20240803/240801230158 (samdaily.us)
- Source
-
SAM.gov Link to This Notice
(may not be valid after Archive Date)
| FSG Index | This Issue's Index | Today's SAM Daily Index Page |