Sveriges mest populära poddar

DevOps Topeaks

#8 - Application Security

24 min • 31 december 2022

Send us a text

In this episode we discussed all-things application security; from scanning, to designing with security in mind, through OWASP and sources of information we feel engineers in the world of dev / ops should be aware of and familiar with!

We talked about:

  • OWASP Top 10 - https://owasp.org/www-project-top-ten
  • Git leaks - https://github.com/zricethezav/gitleaks
  • 12 Factor - https://12factor.net
  • Scanners: [Python Bandit: https://bandit.readthedocs.io/en/latest, Go: https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck]
  • Clair static analysis for containers: https://github.com/quay/clair
  • Bug Bounty platforms: HackerOne, Bugcrowd, Intigrity
  • BGP repo cleaner - remove secrets from git history: https://rtyley.github.io/bfg-repo-cleaner
  • Harden EKS - https://github.com/aws-samples/hardeneks


Meir's blog: https://meirg.co.il
Omer's blog: https://omerxx.com
Telegram channel: https://t.me/espressops

Förekommer på
00:00 -00:00