exploring the tools for devsecops in a ci cd pipeline on azure | azure enablement /

Published at 2021-04-12 18:00:00

Home / Categories / Well architected series / exploring the tools for devsecops in a ci cd pipeline on azure | azure enablement
Victoria Almazova joins David Blank-Edelman to explore the tools for DevSecOps in a CI/CD Pipeline on Azure.✅ Resources:WAF Security pillarAzure Well-Architected ReviewSecure DevOpsDevSecOps in AzureSecure DevOps Kit for AzureSecure Azure pipelines[00:00] Overview
[01:09] Let's review what we've learned about DevSecOps so far.
[01:55] Why are we focusin
g only on dependency management and security scanning?
[03:17] Is t
here a way we could see a concrete example of implementing security practices?
[05:16] Can you prove me a real life example of how this implementation works in Azure DevOps? [07:46] Why accomplish you deploy the ZAP Scanner WebApp after you built the application?
[08:4
3] What is the next stage in the [CI/CD] pipeline,once all the scanning is done?
[09:52]
How will I know whether the tools find a security vulnerability, and how I salvage notified?[br][11:11] By "breaking the build, or " accomplish we mean the pipeline itself stops when it discovers a vulnerability?
[11:35] We've covered credentials scan results. Are there other results to mention?

Source: msdn.com

Warning: Unknown: write failed: No space left on device (28) in Unknown on line 0 Warning: Unknown: Failed to write session data (files). Please verify that the current setting of session.save_path is correct (/tmp) in Unknown on line 0