
Episode #32: Hooks, Kits, and Git - putting security into your git pipeline
Relating to DevSecOps
00:00
Jenkins Security Is Great but It's Not the Only One
Jenkins is great but it's harder to share that I think between these three organizations yeah. We need to limit like what you are introducing from a security perspective into engineering lives even if you are accepting all that information on the tail end. In security we're used to like dropping a sass tool in seeing thousands of false positives weeding through them for three months and then saying okay here's the noiseless stuff for your day job. The difference is that is our day job so it's not something that we can just say hey go use this hook it detects like thousands of vulnerabilities every time you run it. If you see this username somewhere it's probably indicative of a potential problem where
Transcript
Play full episode