Browser-based DAST Analyzer
How Developer-Centric AppSec Testing Transforms DevOps Teams

How Developer-Centric AppSec Testing Transforms DevOps Teams

8/21/2020 · Joni Klippert

What this post added

This post discusses the integration of developer-centric application security testing tools into the CI pipeline, specifically mentioning Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), and Secrets Detection. It highlights GitLab's DAST checks for Ultimate tier customers and StackHawk as a more robust alternative. The post outlines a playbook for implementing these tests, starting with local configuration, then non-blocking CI instrumentation, followed by bug triage, and finally switching to blocking tests. It also emphasizes the cultural shift required for security to become an enabler of rapid development.

Read the original post ↗