- OWASP Dependency-Check: Scans for known vulnerabilities in project dependencies.
- SonarQube: Performs static code analysis to identify bugs, code smells, and security vulnerabilities.
- Aqua Security Microscanner or Trivy: Tools to scan Docker images for vulnerabilities.
To install plugins, go to Manage Jenkins > Manage Plugins and search for these tools under the Available tab.