Nancy Gariché and Tanya Janca — DevSlop, the movement episode artwork

EPISODE · May 21, 2019 · 38 MIN

Nancy Gariché and Tanya Janca — DevSlop, the movement

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How does an intentionally vulnerable application become a community learning movement? Nancy Gariché and Tanya Janca explain the evolution of OWASP DevSlop from a project into a live, collaborative way to teach application security. They describe the DevSlop Show, its deliberately imperfect demonstrations, and the value of learning in public without pretending every experiment will work. The conversation explores Pixi, Paddy the Pipeline, and integrations with free security tools including ZAP, dependency scanning, and web application firewalls. Nancy and Tanya also explain how contributors can start small, join broadcasts, document what they learn, and help expand the project. Their approach treats mistakes as useful teaching material and makes hands-on AppSec education more welcoming to developers and security newcomers.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Nancy Gariché and Tanya Janca:→ Nancy Gariché and OWASP DevSlop→ Tanya Janca on LinkedInMentioned in this episode:→ OWASP DevSlop→ Pixi→ OWASP ZAP→ Burp Suite→ Mend→ OWASP ModSecurity Core Rule Set→ Qualys SSL LabsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 DevSlop as a movement02:11 Meet Nancy Gariché and Tanya Janca05:11 What OWASP DevSlop is09:03 API security and the project’s scope11:14 Learning through the DevSlop Show16:15 Security tools in Paddy the Pipeline18:47 Dependency scanning with Mend21:36 Web application firewalls and ModSecurity23:45 Making mistakes in public27:47 How new contributors can begin30:46 Community participation as the real output32:51 DevSlop’s channels and identity36:55 Closing thoughts

Episode metadata supplied by the publisher feed · Published May 21, 2019

Embed this episode

How does an intentionally vulnerable application become a community learning movement? Nancy Gariché and Tanya Janca explain the evolution of OWASP DevSlop from a project into a live, collaborative way to teach application security. They describe the DevSlop Show, its deliberately imperfect demonstrations, and the value of learning in public without pretending every experiment will work. The conversation explores Pixi, Paddy the Pipeline, and integrations with free security tools including ZA...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Nancy Gariché and Tanya Janca — DevSlop, the movement

0:00 38:11

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 38 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on May 21, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!