filmov
tv
What is static code analysis (SCA)? Lars Andrén OWASP SCA Part 1
Показать описание
Source - unvalidated input
Path - tainted data on the move
Sink - tainted data processed
Did you say SQL injection?
Static Code Analysis - Tools aka Source Code Analysis - Tools
Static Code Analysis aka Source Code Analysis
Flow tracing & Pattern matching
Pattern matching - PMD
Pattern matching - sonarQube
Flow tracing
Coffe or tea? (and some Liam stats?)
Who is Lars Andrén?
I am a software engineer by education and work, currently working at security startup Keypasco in Gothenburg. Three intense years of my life was spent developing the SCA "CodeSecure" at the company Armorize in Taipei, Taiwan ROC. Most of my time was spent with the core analyzer, which doesn't make me a bonafide security expert, but does give me a unique insight in the workings of SCA tools. When I don't scan source code I paint Warhammer models that I less and less frequently have time to play with.
Path - tainted data on the move
Sink - tainted data processed
Did you say SQL injection?
Static Code Analysis - Tools aka Source Code Analysis - Tools
Static Code Analysis aka Source Code Analysis
Flow tracing & Pattern matching
Pattern matching - PMD
Pattern matching - sonarQube
Flow tracing
Coffe or tea? (and some Liam stats?)
Who is Lars Andrén?
I am a software engineer by education and work, currently working at security startup Keypasco in Gothenburg. Three intense years of my life was spent developing the SCA "CodeSecure" at the company Armorize in Taipei, Taiwan ROC. Most of my time was spent with the core analyzer, which doesn't make me a bonafide security expert, but does give me a unique insight in the workings of SCA tools. When I don't scan source code I paint Warhammer models that I less and less frequently have time to play with.
What is Static Code Analysis? || Various Examples
What is Static Code Analysis?
What is Static Code Analysis? | AppSec 101
What is static code analysis? in just 1 minute
Static Code Analysis - Best Practices
Static Code Analysis - A Behind-the-scenes Look • Arno Haase • GOTO 2022
How To Write Clean Code With The Help Of Static Code Analysis
Static Code Analysis: Scan All Your Code For Bugs | Synopsys
ISTQB CTAL-ATT Agile Technical Tester | Exam Practice Tests Sample | English
Static Analysis in C++
What Are Polyspace Static Code Analysis Products?
PC-lint Plus | Static Code Analysis for C and C++
SonarQube: How to run Static Code Scanning?
Static code analysis and why Klocwork is different
What is Static Code Analysis?
What Are Static Analysis Tools?
Where dynamic and static code analysis merge
Code analysis -Static and Dynamic
Embold Static Code Analysis
Unlocking The Secrets Of Static Code Analysis
Bug Hunting with Static Code Analysis - Nick Jones
Top 9 C++ Static Code Analysis Tools
Best Static Code Analysis Tools for Java Code Quality Assurance
Unite 2016 - Static Code Analysis: Preventing Bugs and Lag Before They Happen
Комментарии