Exploring the tools for DevSecOps in a CI/CD Pipeline on Azure

Поділитися
Вставка
  • Опубліковано 1 лют 2025

КОМЕНТАРІ • 9

  • @roborr8495
    @roborr8495 3 роки тому +2

    Fantastic ! I really like the approach and of course the changing to host mode !!!

  • @ermukesh09
    @ermukesh09 3 роки тому +1

    Is there any template that we can deploy or any labs ?

  • @vijayanandmuniyasamy5157
    @vijayanandmuniyasamy5157 3 роки тому

    Hi ,
    Thanks for session Victoria Almazova , the session was informative and useful. One question about the SAST and DAST scan. When we implement this on the pipeline, for the small scale application the time taken to complete the scan may be lesser but in case of larger applications do you prefer running for every push to the remote. What would be your suggestion on this?
    I have created a devsecops pipeline with Veracode and Zap as standalone job from usual build pipeline ,because I am running it overnight or only when needed so I am not slowing the generic pipeline pace.

    • @VjanandSanna
      @VjanandSanna 3 роки тому

      hi sir , do you have any step by step document to practice SAST and DAST. please share with me to upskill

    • @fabiofreitas7760
      @fabiofreitas7760 3 роки тому

      If performance is a hinder factor, my personal experience is to have it trigger on pushes to the main development branch but have it as a downstream job instead of on the main CI/CD pipeline

  • @sebastiencuber7088
    @sebastiencuber7088 3 роки тому

    Great! Thanks

  • @yusufmilz9216
    @yusufmilz9216 2 роки тому

    Hey, what license is required to access all these features?

  • @sconnell194
    @sconnell194 3 роки тому

    👍

  • @Codecloudai
    @Codecloudai 3 роки тому

    Actually Victoria looks like a true Security Analyst.