EPISODE · Jun 14, 2017 · 27 MIN
Eric Johnson -- Continuous Integration in .NET
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Security testing loses value when its results arrive outside the developer’s normal workflow. Eric Johnson joins the podcast to explain how continuous integration can make security checks part of building and delivering software, with a particular focus on .NET. He discusses connecting automated tools to development pipelines and using feedback where engineers already work. Eric then introduces Puma Scan, an open-source security analyzer built on the Roslyn compiler platform, and describes how compiler-aware rules can identify insecure code while developers are editing it. The conversation compares that approach with older .NET analysis options and considers how the wider community can contribute. It is a practical look at reducing the distance between writing code, finding a flaw, and fixing it.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Eric Johnson:→ Eric Johnson on LinkedIn→ Puma ScanMentioned in this episode:→ Roslyn (.NET Compiler Platform)→ Jenkins→ OWASP ZAP→ Find Security Bugs→ BrakemanFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Continuous integration and .NET security with Eric Johnson02:53 Eric’s development and security background04:57 Teaching application security08:17 Bringing security checks into continuous integration10:05 Using the tools developers already rely on12:59 Why focus on .NET and Roslyn?15:13 Building security rules and Puma Scan18:26 Using Puma Scan inside Visual Studio21:25 Filling the open-source .NET scanning gap
Embed this episode
What this episode covers
Security testing loses value when its results arrive outside the developer’s normal workflow. Eric Johnson joins the podcast to explain how continuous integration can make security checks part of building and delivering software, with a particular focus on .NET. He discusses connecting automated tools to development pipelines and using feedback where engineers already work. Eric then introduces Puma Scan, an open-source security analyzer built on the Roslyn compiler platform, and describes ho...
Ready to play
Eric Johnson -- Continuous Integration in .NET
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.