docs: rebrand Certifai -> Prüfwerk (user-facing name)
CI / Check (push) Skipped
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
CI / Check (pull_request) Failing after 1m55s
CI / Check (push) Skipped
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
CI / Check (pull_request) Failing after 1m55s
The product is renamed Certifai -> Prüfwerk. This changes only the user-facing brand text in the documentation (docs/**, VitePress title/name). It does NOT touch functional identifiers that happen to contain "certifai" (the Docker network, Keycloak realm/client, Harbor image project, the compliance-* crate names, or the repo name) — those are infra-coupled and need a separate, coordinated migration. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EgxGHn22YEfQz5fLHSHkLv
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
e0c54c4659
commit
5ad9d2d77c
@@ -1,11 +1,11 @@
|
||||
# Glossary
|
||||
|
||||
A reference of key terms used throughout Certifai.
|
||||
A reference of key terms used throughout Prüfwerk.
|
||||
|
||||
## Security Terms
|
||||
|
||||
**SAST (Static Application Security Testing)**
|
||||
Analysis of source code to find vulnerabilities without running the application. Certifai uses Semgrep for SAST scanning.
|
||||
Analysis of source code to find vulnerabilities without running the application. Prüfwerk uses Semgrep for SAST scanning.
|
||||
|
||||
**DAST (Dynamic Application Security Testing)**
|
||||
Testing a running application by sending crafted requests and analyzing responses. Finds vulnerabilities that only appear at runtime.
|
||||
@@ -45,26 +45,26 @@ A license that allows broad freedom to use, modify, and distribute software with
|
||||
## Standards and Formats
|
||||
|
||||
**CycloneDX**
|
||||
An OWASP standard for SBOM formats. Certifai supports export in CycloneDX 1.5 JSON format.
|
||||
An OWASP standard for SBOM formats. Prüfwerk supports export in CycloneDX 1.5 JSON format.
|
||||
|
||||
**SPDX (Software Package Data Exchange)**
|
||||
A Linux Foundation standard for communicating software bill of materials information. Certifai supports export in SPDX 2.3 format.
|
||||
A Linux Foundation standard for communicating software bill of materials information. Prüfwerk supports export in SPDX 2.3 format.
|
||||
|
||||
## Tools
|
||||
|
||||
**Semgrep**
|
||||
An open-source static analysis tool that finds bugs and enforces code standards using pattern-matching rules. Used by Certifai for SAST scanning.
|
||||
An open-source static analysis tool that finds bugs and enforces code standards using pattern-matching rules. Used by Prüfwerk for SAST scanning.
|
||||
|
||||
**Syft**
|
||||
An open-source tool for generating SBOMs from container images and filesystems. Used by Certifai to extract dependency information.
|
||||
An open-source tool for generating SBOMs from container images and filesystems. Used by Prüfwerk to extract dependency information.
|
||||
|
||||
**OSV.dev**
|
||||
Google's open distributed vulnerability database, queried by package URL. Certifai uses it (together with NVD) to match SBOM components against known vulnerabilities.
|
||||
Google's open distributed vulnerability database, queried by package URL. Prüfwerk uses it (together with NVD) to match SBOM components against known vulnerabilities.
|
||||
|
||||
## Protocols
|
||||
|
||||
**MCP (Model Context Protocol)**
|
||||
An open standard that allows LLM-powered tools to connect to external data sources and call tools. Certifai exposes security data through MCP so AI assistants can query findings, SBOMs, and DAST results.
|
||||
An open standard that allows LLM-powered tools to connect to external data sources and call tools. Prüfwerk exposes security data through MCP so AI assistants can query findings, SBOMs, and DAST results.
|
||||
|
||||
**PKCE (Proof Key for Code Exchange)**
|
||||
An extension to the OAuth 2.0 authorization code flow that prevents authorization code interception attacks. Used in Certifai's authentication flow.
|
||||
An extension to the OAuth 2.0 authorization code flow that prevents authorization code interception attacks. Used in Prüfwerk's authentication flow.
|
||||
|
||||
Reference in New Issue
Block a user