Loading…
Friday, August 9 • 1:00pm - 2:00pm
OWASP DevSlop: A DevSecOps Pipeline

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
The OWASP DevSlop team are back with “Patty”, a new module of the project consisting of a DevSecOps pipeline made with Azure DevOps Pipelines, passing negative unit tests, ensuring all the 3rd party components are known-secure (White Source Bolt), dynamic code analysis (OWASP Zap), retrieving secrets from a secret store (Key Vault), releasing into Azure. This entire system/project is open-sourced as part of the project as live streaming and recorded videos, so that developers can watch each of the lessons, add it to their own pipelines, and have a head start on DevSecOps. The talk will consist mostly of a start-to-finish demo of the system, finishing with the DevSlop team releasing their own website live, on stage, using the pipeline. Tools showcased include SSL Labs, White Source Bolt and OWASP Zap.

For many people ‘the cloud’ and DevSecOps can be a bit mysterious. Let’s clear this up with a nice, long, slow demo of how to load up an app in your editor, make a change, run it through your pipeline (and pass the security checks!), then publish it into the cloud. One step at a time.

Speakers

Friday August 9, 2019 1:00pm - 2:00pm PDT
Acacia D