Static Application Security Testing With CICD Pipelines Using Whitesource

Опубликовано: 25 Октябрь 2024
на канале: Mohamed Radwan - DevOps
7,279
71

In this video, you will learn how to run Static Application Security Testing with CICD Pipelines Using Whitesource in order to scan and check for Vulnerabilities in OSS (Open Source Libraries).

Also, to check for OSS (Open Source Libraries) allowance and outdated.

You will get more info about Common Vulnerabilities and Exposure Database and National Vulnerabilities Database.

You will learn how to configure and run security scan for Azure Pipeline using Whitesource Bolt and how to read the security scan report

Using WhiteSource, you can detect and find vulnerable open source libraries and components, generate complete open source inventory reports of all open source libraries per project or build.
Also, enforce open source license compliance and show its allowance, including dependencies’ licenses and identify outdated open source libraries with recommendations to update and how many versions released since the out that being used in the project.

About the Author
----------------------------
Video:
   • Mohamed Radwan is a Principal DevOps ...  
Blog:
https://mohamedradwan.com
Linked-in
  / mohamedahmedradwan  
GitHub
https://github.com/DevOpsFounder
Twitter:
  / mradwan06  

#DevSecOps #DevOps #Security #Compliance #Validation