
5/3/2019 · Cindy Blake
What this post added
This post introduces the concept of "shift left" for application security testing in cloud-native environments. It emphasizes integrating security into the development lifecycle through DevSecOps, advocating for automated security scans at code commit. It highlights GitLab's review app feature for pre-merge testing and the use of Dynamic Application Security Testing (DAST) to scan these review apps. The post also touches on the importance of horizontal security coverage (application, container, orchestrator, access management) and the benefits of simplicity and integration in security tools.