Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

OWASP NZ 22 - Building Your First DevSecOps Pipeline

Автор: Wise Fox Security

Загружено: 2022-08-13

Просмотров: 8988

Описание:

Abstract

I am sure all of you have heard about "Shift Left Security" in many presentations, but how do you actually achieve this? Well, this is the talk for you - where I'll cover all the DevSecOps buzzwords and showcase a functional DevSecOps pipeline that can perform security testing such as SCA, SAST, and DAST.

Description

In this talk I'll cover how to build your first DevSecOps pipeline with Open Source tooling. I'll address various concepts and buzzwords related to DevSecOps to clear your doubts. I'll demonstrate a GitLab pipeline that has various open-source security tooling embedded to perform the following security tests against a vulnerable application:

Secrets Detection (tools such as TruffleHog, etc.)
Software Composition Analysis (SCA)
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)

With this pipeline, our aim is to identify security issues as early as possible so that we can build "Secure by Default" products. This pipeline and demos will cover tools such as RetireJS, Safety, Bandit, TruffleHog, NMAP, SSLyze and ZAP.

OWASP NZ 22 - Building Your First DevSecOps Pipeline

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

Mystikcon 2021 - Creating Your First DevSecOps Pipeline with Open Source Tools

Mystikcon 2021 - Creating Your First DevSecOps Pipeline with Open Source Tools

How to Create a DevSecOps CI/CD Pipeline

How to Create a DevSecOps CI/CD Pipeline

From DevOps to DevSecOps - OWASP NZ Day 2023

From DevOps to DevSecOps - OWASP NZ Day 2023

Что такое DevSecOps?

Что такое DevSecOps?

Beyond Services: Using ECS Tasks for Automated AWS Inventory by Petter Uvesten

Beyond Services: Using ECS Tasks for Automated AWS Inventory by Petter Uvesten

Android Application Pentesting - Mystikcon 2020

Android Application Pentesting - Mystikcon 2020

Jumpstarting Your DevSecOps Pipeline with IAST and RASP - Jeff Williams

Jumpstarting Your DevSecOps Pipeline with IAST and RASP - Jeff Williams

Важность DevSecOps и 5 шагов для его правильного внедрения (ОБЪЯСНЕНИЕ DevSecOps)

Важность DevSecOps и 5 шагов для его правильного внедрения (ОБЪЯСНЕНИЕ DevSecOps)

Building AI Platforms Without Losing Your Engineering Principles

Building AI Platforms Without Losing Your Engineering Principles

Best Practices for securing CI/CD Pipelines or how to get Security right | Victoria Almazova

Best Practices for securing CI/CD Pipelines or how to get Security right | Victoria Almazova

Setting Up Your DevSecOps Lab with GitLab

Setting Up Your DevSecOps Lab with GitLab

The Three Faces of DevSecOps

The Three Faces of DevSecOps

DevSecOps & GitLab's Security Solutions

DevSecOps & GitLab's Security Solutions

Kubernetes — Простым Языком на Понятном Примере

Kubernetes — Простым Языком на Понятном Примере

Ростислав Ищенко. Ответ на атаку ВСУ по резиденции Путина, переговоры по Украине и мины в Прибалтике

Ростислав Ищенко. Ответ на атаку ВСУ по резиденции Путина, переговоры по Украине и мины в Прибалтике

Life of a DevSecOps Engineer (w/ Aras

Life of a DevSecOps Engineer (w/ Aras "Russ" Memisyazici)

eLearnSecurity's eWPTX Certificate Story/Review

eLearnSecurity's eWPTX Certificate Story/Review

DevSecOps : What, Why and How

DevSecOps : What, Why and How

I'm in DevOps -  CI/CD at Scale: Best practices with AWS DevOps Services (Level 300)

I'm in DevOps - CI/CD at Scale: Best practices with AWS DevOps Services (Level 300)

DevSecOps Pipeline CI Process  - Real world example!

DevSecOps Pipeline CI Process - Real world example!

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]