Developer-First Security: How to Automate Security Tests with GitHub, GitLab, and more

Logo
Presented by

Steven Zimmerman, DevOps Security Solutions Manager, Black Duck

About this talk

Forcing AppSec tests into developer pipelines, without aligning them to their preferred tools, can lead to inefficiencies and security oversights. Security teams need full risk visibility and developers need to meet shipping deadlines. While developers should not take full responsibility for security testing, they must be able to initiate, support, and benefit from it without changing their existing workflows. The most effective and efficient way to accomplish this is with out-of-the-box integrations and security testing templates that work natively with leading DevOps platforms like GitHub, GitLab, and Azure DevOps (ADO) to automate critical AppSec tests and quickly close feedback loops with developers. Join Black Duck as we discuss: Using DevOps platforms’ automation templates to embed AppSec into CI pipelines - Making security scans and fix pull requests an automatic part of dev workflows - Reducing risk and issue backlogs with developer security training and clear fix guidance - Accelerating AppSec using AI-enabled DevOps and security tools Start making life easier for developers and AppSec teams with integrated security testing for GitHub, GitLab, ADO, and more.
Related topics:

More from this channel

Upcoming talks (10)
On-demand talks (132)
Subscribers (67754)
Black Duck® offers the most comprehensive, powerful, and trusted portfolio of application security solutions in the industry. We have an unmatched track record of helping organizations around the world secure their software quickly, integrate security efficiently in their development environments, and safely innovate with new technologies. As the recognized leaders, experts, and innovators in software security, Black Duck has everything you need to build trust in your software. As of October 1, 2024 the Synopsys Software Integrity Group is now Black Duck®