SecuriTEA & Crumpets is a series where security professionals come together to talk about their background, research, and interesting topics. The first episode is with Mathew Payne of GitHub where he talks about his background, his experience with Static Analysis and his current job which is working with CodeQL. This series shows how to use CodeQL from a basic introductory level of how you can use it within Visual Code and the web interface!
00:00 Introduction
5:00 Degrees
10:35 Automation
19:40 Projects worked on at Cigital
23:10 Moving to Github
34:49 CodeQL
Host: Lewis Ardern - / lewisardern
Guest: Mathew Payne - / geekmasher
References:
Largest student ran security conference:
https://securi-tay.co.uk
Introduction to static analysis:
https://owasp.org/www-community/Sourc...
CodeQL Resources:
https://github.com/geekmasher/securit...
https://github.com/github/codeql-cli-...
https://github.com/github/codeql
https://securitylab.github.com/bounties
https://github.com/github/vscode-code...
https://codeql.github.com/docs
https://lgtm.com
Vulnerable Open Source Applications:
https://github.com/bkimminich/juice-shop
https://github.com/GeekMasher/Pixi