Eric Johnson -- Continuous Integration in .NET episode artwork

EPISODE · Jun 14, 2017 · 27 MIN

Eric Johnson -- Continuous Integration in .NET

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Security testing loses value when its results arrive outside the developer’s normal workflow. Eric Johnson joins the podcast to explain how continuous integration can make security checks part of building and delivering software, with a particular focus on .NET. He discusses connecting automated tools to development pipelines and using feedback where engineers already work. Eric then introduces Puma Scan, an open-source security analyzer built on the Roslyn compiler platform, and describes how compiler-aware rules can identify insecure code while developers are editing it. The conversation compares that approach with older .NET analysis options and considers how the wider community can contribute. It is a practical look at reducing the distance between writing code, finding a flaw, and fixing it.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Eric Johnson:→ Eric Johnson on LinkedIn→ Puma ScanMentioned in this episode:→ Roslyn (.NET Compiler Platform)→ Jenkins→ OWASP ZAP→ Find Security Bugs→ BrakemanFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Continuous integration and .NET security with Eric Johnson02:53 Eric’s development and security background04:57 Teaching application security08:17 Bringing security checks into continuous integration10:05 Using the tools developers already rely on12:59 Why focus on .NET and Roslyn?15:13 Building security rules and Puma Scan18:26 Using Puma Scan inside Visual Studio21:25 Filling the open-source .NET scanning gap

Episode metadata supplied by the publisher feed · Published Jun 14, 2017

Embed this episode

Security testing loses value when its results arrive outside the developer’s normal workflow. Eric Johnson joins the podcast to explain how continuous integration can make security checks part of building and delivering software, with a particular focus on .NET. He discusses connecting automated tools to development pipelines and using feedback where engineers already work. Eric then introduces Puma Scan, an open-source security analyzer built on the Roslyn compiler platform, and describes ho...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Eric Johnson -- Continuous Integration in .NET

0:00 27:32

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 27 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 14, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!