
Eric Johnson -- Continuous Integration in .NET
Om avsnittet
Security testing loses value when its results arrive outside the developer’s normal workflow. Eric Johnson joins the podcast to explain how continuous integration can make security checks part of building and delivering software, with a particular focus on .NET. He discusses connecting automated tools to development pipelines and using feedback where engineers already work. Eric then introduces Puma Scan, an open-source security analyzer built on the Roslyn compiler platform, and describes how compiler-aware rules can identify insecure code while developers are editing it. The conversation compares that approach with older .NET analysis options and considers how the wider community can contribute. It is a practical look at reducing the distance between writing code, finding a flaw, and fixing it.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Eric Johnson:
→ Eric Johnson on LinkedIn
→ Puma Scan
Mentioned in this episode:
→ Roslyn (.NET Compiler Platform)
→ Jenkins
→ OWASP ZAP
→ Find Security Bugs
→ Brakeman
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Continuous integration and .NET security with Eric Johnson
02:53 Eric’s development and security background
04:57 Teaching application security
08:17 Bringing security checks into continuous integration
10:05 Using the tools developers already rely on
12:59 Why focus on .NET and Roslyn?
15:13 Building security rules and Puma Scan
18:26 Using Puma Scan inside Visual Studio
21:25 Filling the open-source .NET scanning gap
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.