开发者指南:如何与安全达成协议.pdf

编号:612375 PDF 29页 2.97MB 下载积分:VIP专享
下载报告请您先登录!

开发者指南:如何与安全达成协议.pdf

1、A Developers Guide to Making a Deal with SecurityFour questions that outline how both development and security can get what they want?Larry MaccheroneDevSecOps Transformation,Contrast SecurityLinkedI beatings will continue until morale improves”Captain William Bligh(mutiny on the Bounty)LinkedI Macc

2、heroneLinkedI Security(aka,DevSecOps)is empowered engineering teams taking ownership of the security of their softwarewhile usingFlow,Feedback,and Learning(aka,the 3 ways of DevOps)to continuouslyimprove software value deliveryLinkedI go DevOps?SpeedANDQualityIs Your Dev Team Ready?Question#1LinkedI

3、 of an automated functional test suite that will grow until you trust it to prevent an“unworthy”artifact from getting to the next higher-level branchA single E2E test gets you as much as 30%test coverage and thats all you need for this prerequisiteOnly use solitary unit testing for logic and librari

4、es that are easily isolated w/little to no mocking.Even Martin Fowler now advocates for“sociable unit tests”This functional test suite must be completed prior to the pull-request merge decision1.Because you need it for Software Composition Analysis(SCA).You cant be sure that upgrading to the latest

5、version will not break your app without testing it.2.Because it maximizes the benefits of using IAST tools rather than slower and less accurate SAST tools.Quality reasons should be enough to motivate test writing but with these security reasons,such work is now twice as valuableWhy are functional te

6、sts important for security?LinkedI working agreement document(aka definition of done,Kanban entrance criteria).Connect with me on LinkedIn for the document I start all teams with.2.Devs write happy path test(s),at least,when adding functionality pre-pull-request even if QA writes more later3.Of cour

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(开发者指南:如何与安全达成协议.pdf)为本站 (小小) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠