Falling in love with static analysis

Falling in love with static analysis

説明:

As a developer, chances are you are aware how much static code analysis tools could help you to secure the application, yet beside simple linters you do not use them to their full extent. Maybe you even circumvent them when possible. The reasons for this are that most of these tools are slow, generate massive amounts of false alarms and the real alarms are complex and not actionable. Commonly, these tools produce reports that might serve post-development audits, but fail to integrate in your daily workflow and are painful to use. You are not alone.

In this session, we want to show you the life of a pull request and follow your workflow. First, we want to remedy as many security issues as possible before the code is pushed. Then we will show you how Snyk Code helps to secure the rest of the SDLC. We will show you how Snyk Code provides security insight when and where you need it during development, code review and in the CI/CD pipeline. We will leave you with some practical advice on how to review and modernize the development process.

講演者:

Noa Moshe

Solutions Engineer, Snyk

Elad Yaakov

Product Manager, Snyk

Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment

Snyk (スニーク) は、デベロッパーセキュリティプラットフォームです。Snyk は、コードやオープンソースとその依存関係、コンテナや IaC (Infrastructure as a Code) における脆弱性を見つけるだけでなく、優先順位をつけて修正するためのツールです。世界最高峰の脆弱性データベースを基盤に、Snyk の脆弱性に関する専門家としての知見が提供されます。

無料で始める資料請求

© 2024 Snyk Limited
Registered in England and Wales

logo-devseccon