GitLab Advanced SAST: Accelerating Vulnerability Resolution

preview_player
Показать описание
GitLab Advanced SAST is a Static Application Security Testing (SAST) analyzer designed to discover vulnerabilities by performing cross-function and cross-file taint analysis.

By following the paths user inputs take, the analyzer identifies potential points where untrusted data can influence the execution of your application in unsafe ways, ensuring that injection vulnerabilities, such as SQL injection and cross-site scripting (XSS), are detected even when they span multiple functions and files.

OUTLINE
00:00 - Introduction
00:32 - Advanced SAST Overview
01:06 - Supported Languages
01:18 - Enabling Advanced SAST
01:42 - Vulnerabilities Detected in a Merge Request
02:15 - Vulnerability Report Population
03:10 - Examining the Code Flow
04:30 - Using AI to Explain Code
04:46 - Conclusion

USEFUL LINKS

Thanks for watching! Be sure to subscribe and follow @awkwardferny and @gitlab on twitter for similar content.
Рекомендации по теме
Комментарии
Автор

on gitlab docs tutorial for SAST, it guides to use - template: Security/SAST.gitlab-ci.yml and you are guiding to use -template: Job/SAST.gitlab-ci.yml and setting variable GITLAB_ADVANCED_SAST_ENABLED: 'true' . which one is correct way ?

devitimilsina
Автор

Hi I'm facing security vulnerabilities issues in package

Nehavicky
join shbcf.ru