Scanning application code for security vulnerabilities is an important step in which aspect of the Continuous Delivery Pipeline?
According to the SAFe DevOps Practitioner 6.0 study guide1, scanning application code for security vulnerabilities is an important step in the Continuous Integration aspect of the Continuous Delivery Pipeline. Continuous Integration is the process of developing, testing, integrating, and validating new functionality in preparation for deployment and release. Continuous Integration helps teams to improve quality, reduce risk, and establish a fast, reliable, and sustainable development pace. Scanning application code for security vulnerabilities is one of the ways to ensure that the code meets the quality standards and requirements, and that it does not contain any errors, bugs, or vulnerabilities that could compromise the security or functionality of the Solution.Scanning application code for security vulnerabilities can be performed by using tools such as GitHub Advanced Security for Azure DevOps2, which uses CodeQL to identify vulnerabilities in various languages and frameworks. Therefore, scanning application code for security vulnerabilities is an important step in the Continuous Integration aspect of the Continuous Delivery Pipeline.
Limited Time Offer
25%
Off
Currently there are no comments in this discussion, be the first to comment!
Currently there are no comments in this discussion, be the first to comment!