r2c meetup: Writing Semgrep rules for security, correctness, performance, and more
Автор: semgrep
Загружено: 2020-08-26
Просмотров: 1516
r2c meetup recorded on August 26, 2020
Semgrep is a simple, customizable, and fast static analysis tool for finding bugs. It combines the speed and customization of grep with the precision of traditional static analysis tools. There’s no painful domain-specific language; Semgrep rules look like the source code you’re targeting. It’s free and open source.
Agenda
Isaac Evans, CEO and co-founder of r2c
During this talk, we’ll look at how to write Semgrep rules for common use cases in security, correctness, performance, and more.
We'll also discuss how to use existing institutional knowledge, post mortems, and internal security controls to write Semgrep rules relevant to your organization.
This will be an interactive session so you can follow along in the Semgrep live editor.
Slides: https://web-assets.r2c.dev/presentati...
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: