Sign In

Use your Cognito demo user. The vulnerable lab app is not exposed here; successful sign-in opens the DevSecOps dashboard.

Only this login screen is visible before authentication.

Codex-style Security DevSecOps Dashboard

Region
Repo
Pipeline
Lab Service
Signed in. Load the latest pipeline evidence.

Pipeline Runs

Selected Run Evidence

Gate-
High Findings-
Model Route-
Commit-
GitHub SourcePush to wanatun/owaspdemo triggers the AWS pipeline.
CodeBuild in VPCSecurity agent reads repo contents in the build workspace.
Mantle GPT-5.5Codex-style review call through Bedrock Mantle OpenAI-compatible path.
Patch and ValidateAllowlisted local patch, diff, tests, and high-severity gate.
Private ECS/FargateDeployment target remains private; dashboard exposes evidence, not the vulnerable app.

Codex-style Security Findings

Patch Diff

(select a run)

Validation Logs

(select a run)

Packet Evidence

Queries VPC Flow Logs for the CodeBuild private IPs captured during the security-agent run and the effective Mantle region.

Select a run first.
Time Source ENI Source Destination Port Protocol Action Bytes Packets
No packet rows loaded yet.

Mantle Review Output

(select a run)