OWASP NZ 22 - Building Your First DevSecOps Pipeline

  Рет қаралды 7,858

Wise Fox Security

Wise Fox Security

Жыл бұрын

Abstract
I am sure all of you have heard about "Shift Left Security" in many presentations, but how do you actually achieve this? Well, this is the talk for you - where I'll cover all the DevSecOps buzzwords and showcase a functional DevSecOps pipeline that can perform security testing such as SCA, SAST, and DAST.
Description
In this talk I'll cover how to build your first DevSecOps pipeline with Open Source tooling. I'll address various concepts and buzzwords related to DevSecOps to clear your doubts. I'll demonstrate a GitLab pipeline that has various open-source security tooling embedded to perform the following security tests against a vulnerable application:
Secrets Detection (tools such as TruffleHog, etc.)
Software Composition Analysis (SCA)
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
With this pipeline, our aim is to identify security issues as early as possible so that we can build "Secure by Default" products. This pipeline and demos will cover tools such as RetireJS, Safety, Bandit, TruffleHog, NMAP, SSLyze and ZAP.

Пікірлер: 8
@Malpekar-mo4wb
@Malpekar-mo4wb Ай бұрын
Good video
@umairahmed2459
@umairahmed2459 Жыл бұрын
where can i find the YML files used here?
@giftonpaulimmanuel146
@giftonpaulimmanuel146 Жыл бұрын
great
@lookback6314
@lookback6314 10 ай бұрын
🙏
@aryadiadi6888
@aryadiadi6888 Жыл бұрын
Thank you for your sharing. Can you share the slide ?
@forgottenvy
@forgottenvy 2 ай бұрын
720p video, poor screencast video'd into video, and no materials shared. 10/10
@noname-vl6vy
@noname-vl6vy 10 ай бұрын
hello, can you share the repo?
@nobisstudio8497
@nobisstudio8497 Жыл бұрын
Pls make. Video on how to bypass any login in Android apk. Thnk u☺️
DevSecOps : What, Why and How
52:46
Black Hat
Рет қаралды 57 М.
Clown takes blame for missing candy 🍬🤣 #shorts
00:49
Yoeslan
Рет қаралды 39 МЛН
Llegó al techo 😱
00:37
Juan De Dios Pantoja
Рет қаралды 45 МЛН
Life of a DevSecOps Engineer (w/ Aras "Russ" Memisyazici)
1:06:45
Cyberspatial
Рет қаралды 48 М.
Android Application Pentesting - Mystikcon 2020
56:51
Wise Fox Security
Рет қаралды 67 М.
SAST- Static Analysis with lab by Practical DevSecOps - 9 Jun
1:28:39
Open Security Summit
Рет қаралды 7 М.
DevSecOps on Azure
1:10:08
DevOps on Azure
Рет қаралды 8 М.
DevSecOps - the What, Why & How
1:00:53
GitLab
Рет қаралды 11 М.
Clown takes blame for missing candy 🍬🤣 #shorts
00:49
Yoeslan
Рет қаралды 39 МЛН