Post #2527871
2026-05-09 17:30 UTC
@mcfly@milliways.social
*dependency-check / -track for third party dependency issues,
* gitlab SAST /sonarqube for static code analysis,
* automated zap scan on every pull request (in some projects, preferably feeding openapi spec to the scanner)
*trivy for containers
currently researching trying the security-review from claude code, might give claude security a chance as well soon. (R&D)
Replies (1)
-
@cy@chaos.social 2026-05-09 17:34
@mcfly@milliways.social i did present about this long tine ago also on your favorite camp :) https://media.ccc.de/v/Camp2019-10181-automated_security_testing_for_software_developers_who_dont_know_security