filmov
tv
GitLab Advanced SAST: Accelerating Vulnerability Resolution

Показать описание
GitLab Advanced SAST is a Static Application Security Testing (SAST) analyzer designed to discover vulnerabilities by performing cross-function and cross-file taint analysis.
By following the paths user inputs take, the analyzer identifies potential points where untrusted data can influence the execution of your application in unsafe ways, ensuring that injection vulnerabilities, such as SQL injection and cross-site scripting (XSS), are detected even when they span multiple functions and files.
OUTLINE
00:00 - Introduction
00:32 - Advanced SAST Overview
01:06 - Supported Languages
01:18 - Enabling Advanced SAST
01:42 - Vulnerabilities Detected in a Merge Request
02:15 - Vulnerability Report Population
03:10 - Examining the Code Flow
04:30 - Using AI to Explain Code
04:46 - Conclusion
USEFUL LINKS
Thanks for watching! Be sure to subscribe and follow @awkwardferny and @gitlab on twitter for similar content.
By following the paths user inputs take, the analyzer identifies potential points where untrusted data can influence the execution of your application in unsafe ways, ensuring that injection vulnerabilities, such as SQL injection and cross-site scripting (XSS), are detected even when they span multiple functions and files.
OUTLINE
00:00 - Introduction
00:32 - Advanced SAST Overview
01:06 - Supported Languages
01:18 - Enabling Advanced SAST
01:42 - Vulnerabilities Detected in a Merge Request
02:15 - Vulnerability Report Population
03:10 - Examining the Code Flow
04:30 - Using AI to Explain Code
04:46 - Conclusion
USEFUL LINKS
Thanks for watching! Be sure to subscribe and follow @awkwardferny and @gitlab on twitter for similar content.
GitLab Advanced SAST: Accelerating Vulnerability Resolution
GitLab Advanced SAST + Duo Vulnerability Explanation Walkthrough
DAST On Demand - Advanced Security Testing (HD)
GitLab 14.4 Release: New Security Features
Webinar - Secure - Implementing Security Scans and Dashboards
Accelerate AppSec Efficiency with the GitLab Security Dashboard (DevSecOps)
Walk through of GitLab's APEX Static Application Security Testing (SAST) for Salesforce Develop...
Security Dashboard - Advanced Security Testing (v2) (HD)
Commit Virtual 2021: Prevent Vulnerabilities Using Secure Guardrails With Semgrep
GitLab Ultimate Demo - 5/4/21
A tour of GitLab Security capabilities
GitLab - DevSecOps and Compliance EMEA Webinar
Dependency Scanning Live Demo
Security Dashboard - Sales Enablement 2018-11-15
Managing Security & Compliance with GitLab - DevSecOps SKILup Day, 17th Sept 2020
🔴 LIVE DEMO | How to Automate Vulnerability Scans? | #DevSecOps LIVE
A DevSecOps Controversy? Failing the Build with Jenkins in SAST
Managing security and compliance with GitLab
Secure Stage Strategy Review - November 2023
Security 101 Sales Enablement
GitHub Secret-Scanning Could Create False Sense of Security
Commit Virtual 2020: GitLab Product Keynote
Next Generation DAST
How to Build a DevSecOps Pipeline in Jenkins - Part 2 of 2
Комментарии