Matt Konda -- OWASP Glue episode artwork

EPISODE · Jan 18, 2019 · 35 MIN

Matt Konda -- OWASP Glue

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Developers need useful findings in their workflow, not another collection of security tools to operate by hand. Matt Konda explains how OWASP Glue grew from that problem: run multiple tools, normalize their output, and make the results usable in a build or development process. He shares his path from software development into AppSec, the thinking behind Jemurai, and why OWASP’s community appealed to him. The technical discussion compares Glue with Gauntlt and DefectDojo, examines integrations and extensibility, and considers how open-source projects can work together. Matt closes with a straightforward way for an individual developer to try Glue. Throughout, the focus is on connecting security work to engineering habits and making automation produce information people can act on.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Matt Konda:→ Matt Konda on LinkedIn→ OWASP Glue source codeMentioned in this episode:→ Gauntlt→ OWASP DefectDojo→ Brakeman→ ZAPFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Connecting security tools with Matt Konda01:09 From software development into security04:34 Bridging the gap with development teams08:55 The story behind Jemurai10:34 Tools, processes, and useful security signals13:33 Finding a community in OWASP17:08 Why OWASP Glue was created19:52 Comparing Glue with Gauntlt and adding tools26:01 How Glue relates to DefectDojo29:48 Improving commercial tool integrations31:59 The easiest way to start using Glue34:47 Final thoughts

Episode metadata supplied by the publisher feed · Published Jan 18, 2019

Embed this episode

Developers need useful findings in their workflow, not another collection of security tools to operate by hand. Matt Konda explains how OWASP Glue grew from that problem: run multiple tools, normalize their output, and make the results usable in a build or development process. He shares his path from software development into AppSec, the thinking behind Jemurai, and why OWASP’s community appealed to him. The technical discussion compares Glue with Gauntlt and DefectDojo, examines integrations...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Matt Konda -- OWASP Glue

0:00 35:47

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 35 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 18, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!