Gitting Down to the Issue - Closing the Feedback Loop with Automation

Gitting Down to the Issue - Closing the Feedback Loop with Automation

Beschreibung:

During this session, a focus on how security professionals are beginning to provide "pipelines-as-a-service" has necessitated a product / service-oriented mindset, even for internal teams. A structured approach on how to leverage continuous integration tools to incorporate not only Snyk Open Source, but security tools in general, into the application development lifecycle will be reviewed. A demonstration of how APIs, functions, and scripts can be used to provide (Snyk) scan output as a GitHub Issue, allowing for feedback to given and discussion to take place prior to a Pull Request event. This presentation will also discuss some of the practical challenges faced related to "privatizing" the code for pipelines, pipeline performance, and secret management as they were faced while adopting the approach at an enterprise scale.

Speaker:

David Wiggs

Manager, Bain

Snyk ist eine Developer Security Plattform. Integrieren Sie Snyk in Ihre Tools, Workflows und Pipelines im Dev-Prozess – und Ihre Teams identifizieren, priorisieren und beheben Schwachstellen in Code, Abhängigkeiten, Containern, Cloud-Ressourcen und IaC nahtlos. Snyk bringt branchenführende Application & Security Intelligence in jede IDE.

Kostenlos startenLive-Demo buchen

© 2024 Snyk Limited
Alle Rechte vorbehalten

logo-devseccon