Securing Open Source pipeline using Plug-n-Play Scanning

0 分で読めます

| Talk |

Amol Deshpande, Product Security Engineer, Sales Force

Salesforce believes in giving back to the community, and one of the ways engineers can give back is by open sourcing the work they have done so that other individuals can benefit from it.

Until July 2020, the requests to open source any internal Salesforce work were reviewed by Product Security manually and it soon became a bottleneck. We developed an automation service that seamlessly connects with the internal task-tracking system and internal security tools to provide a consolidated scan report of the repository to be open-sourced saving at least 150 hours of manual work per year.

This framework can now be extended to be a plug and play security scanning/testing framework capable of incorporating any tool.

Curious for more? Learn why Snyk is loved by both developers and security teams and how you can secure your open source projects and entire Cloud Native Application Stack.

Up Next

Why can’t we simply add a button that does X?

Making the impossible work with minimal resources is a great accomplishment by our engineers. But what if… Let me show you how all of us make the same mistake over and over again.

続きを読む
Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment

Snyk (スニーク) は、デベロッパーセキュリティプラットフォームです。Snyk は、コードやオープンソースとその依存関係、コンテナや IaC (Infrastructure as a Code) における脆弱性を見つけるだけでなく、優先順位をつけて修正するためのツールです。世界最高峰の脆弱性データベースを基盤に、Snyk の脆弱性に関する専門家としての知見が提供されます。

無料で始める資料請求

© 2024 Snyk Limited
Registered in England and Wales

logo-devseccon