GitLab Advanced SAST: Accelerating Vulnerability Resolution

Описание к видео GitLab Advanced SAST: Accelerating Vulnerability Resolution

GitLab Advanced SAST is a Static Application Security Testing (SAST) analyzer designed to discover vulnerabilities by performing cross-function and cross-file taint analysis.

By following the paths user inputs take, the analyzer identifies potential points where untrusted data can influence the execution of your application in unsafe ways, ensuring that injection vulnerabilities, such as SQL injection and cross-site scripting (XSS), are detected even when they span multiple functions and files.

OUTLINE
00:00 - Introduction
00:32 - Advanced SAST Overview
01:06 - Supported Languages
01:18 - Enabling Advanced SAST
01:42 - Vulnerabilities Detected in a Merge Request
02:15 - Vulnerability Report Population
03:10 - Examining the Code Flow
04:30 - Using AI to Explain Code
04:46 - Conclusion

USEFUL LINKS
GitLab Advanced SAST Documentation: https://docs.gitlab.com/ee/user/appli...
Vulnerability Code Flow: https://docs.gitlab.com/ee/user/appli...

Thanks for watching! Be sure to subscribe and follow @awkwardferny and @gitlab on twitter for similar content.

Комментарии

Информация по комментариям в разработке