Episode 475: Rey Bango on Secure Coding Veracode

Topics covered
Popular Clips
Episode Highlights
Shift-Left Security
Shift-left security emphasizes embedding security features early in the software development lifecycle. highlights the importance of considering security from the initial stages of application development, even before writing a single line of code 1. He mentions the concept of security champions within organizations to mentor and guide developers in secure coding practices 2.
You should be thinking about how security plays a role within your whole entire lifecycle.
---
This proactive approach helps in identifying potential vulnerabilities early, reducing the risk of security breaches later in the development process.
Secure CI/CD Pipelines
Integrating security measures into CI/CD pipelines is crucial for maintaining robust software security. acknowledges the challenges developers face with added latency in pipelines but emphasizes the necessity of these security checks 3. He advises that while initial implementation may be cumbersome, it eventually becomes a seamless part of the development workflow 4.
It's a journey. When you're implementing tooling, you're going to have some pain points.
---
This integration ensures that security is not compromised for performance, ultimately leading to more secure and efficient software.
Related Episodes


Episode 441 Shipping Software - With Bugs
Answers 383 questions

Episode 514: Vandana Verma on the Owasp Top 10
Answers 383 questions

SE-Radio-Episode-309-Zane-Lackey-on-Application-Security
Answers 383 questions

Episode 482: Luke Hoban on Infrastructure as Code
Answers 383 questions

SE-Radio Episode 357: Adam Barr on Code Quality
Answers 383 questions

SE Radio 634: Jim Bugwadia on Kubernetes Policy as Code
Answers 383 questions

Episode 544: Ganesh Datta on DevOps vs Site Reliability Engineering
Answers 383 questions

SE-Radio Episode 288: DevSecOps
Answers 383 questions

SE-Radio Episode 350: Vivek Ravisankar on HackerRank
Answers 383 questions

Episode 535: Dan Lorenc on Supply Chain Attacks
Answers 383 questions
Episode 152: MISRA with Johan Bezem
Answers 383 questions

SE Radio 597: Coral Calero Muñoz and Félix García on Green Software
Answers 383 questions

SE-Radio Episode 276: Björn Rabenstein on Site Reliability Engineering
Answers 383 questions

Episode 59: Static Code Analysis
Answers 383 questions

SE-Radio Episode 314: Scott Piper on Cloud Security
Answers 383 questions













