Loading…
or to bookmark your favorites and sync them to your phone or calendar.
Thursday, November 14
 

1:15pm IST

Building git hooks for your organization
Thursday November 14, 2024 1:15pm - 2:00pm IST
  Have you been in a situation where you had to help developers write secure code and you spent hours in training or code reviews? What if there was a way to make such reviews proactive?

This talk will discuss about using git-hooks for performing security scans. We will discuss using git hooks the usual way and how one team like application security can distribute the hooks across the organisation to enable developers write clean code. We will specifically talk about using pre-commit for code scanning.

We will look at ways we distribute the hooks to every developer in the company, problems we faced, how we collect metrics to understand usage pattern and efficiency. Problems like time consumption and other issues will also be discussed.
During this implementation there were a lot of challenges and lessons learned. Why current tools or frameworks won't work out. What could possibly go wrong when installing the hooks. We will discuss all of those.
                                   
    
Speakers
avatar for Naveen S

Naveen S

Lead Security Engineer, Freshworks
Thursday November 14, 2024 1:15pm - 2:00pm IST
 
Friday, November 15
 

12:30pm IST

The Inmates Are Running the Asylum: Why Developers Drive Security Professionals Crazy and How to Restore Sanity
Friday November 15, 2024 12:30pm - 1:15pm IST
                                                In the evolving landscape of software development, the integration of DevSecOps has emerged as a critical paradigm, promising a harmonious blend of development, security, and operations to streamline feature delivery while ensuring security. However, the path to achieving this seamless integration is fraught with hurdles—ranging from the lack of security training among developers to the complexity of security tools, the scarcity of dedicated security personnel, and the generation of non- actionable security alerts. Historically, there has been a palpable tension between development teams, who prioritize rapid feature deployment, and security professionals, who focus on risk mitigation. This discrepancy often results in a "The Inmates Are Running the Asylum" scenario, where developers, driven by delivery deadlines, may inadvertently sideline security, leading to frustration among security teams. However, the essence of DevSecOps lies in reconciling these differences by embedding security into the development lifecycle, thereby enabling faster, more secure releases without compromising productivity. This paper explores strategies for embedding security into the development process in a harmonious manner, thereby enhancing productivity without compromising on security.
                                   
    
Speakers
avatar for Debrup Ghosh

Debrup Ghosh

Principal Product Manager, F5
Friday November 15, 2024 12:30pm - 1:15pm IST

2:45pm IST

Leveraging DevSecOps and AI to Triage and Resolve OWASP Top 10 Vulnerabilities in a project(s)
Friday November 15, 2024 2:45pm - 3:15pm IST
 In this session, we'll explore how to effectively triage and resolve vulnerabilities within the OWASP Top 10 categories using a DevSecOps platform like GitLab.
Attendees will learn:
1. How to configure security scanners within project pipelines to generate comprehensive vulnerability reports.
2. We'll then dive into using the data from these reports to triage vulnerabilities according to the OWASP Top 10 categories.
3. Finally, we’ll demonstrate how AI-assisted tools can suggest resolutions and automate the remediation of these identified critical vulnerabilities.
                                   
    
Speakers
avatar for Bala Kumar Subramani

Bala Kumar Subramani

Senior Backend Engineer, Gitlab
Friday November 15, 2024 2:45pm - 3:15pm IST