Todd A. Jacobs · @todd_a_jacobs
19 followers · 179 posts · Server ruby.social

@theia has just published some guidance on integrating within a secure program. I always look forward to hearing comments and feedback from others in the community, but this time around I hope to hear from the and communities too!

theia.institute/publications/i

#generativeAI #sdlc #infosec #softwareengineering #softwaretesting

Last updated 2 years ago

Gottfried Szing · @kjoo
600 followers · 138 posts · Server hachyderm.io

A kind of follow-up my post yesterday, but this goes more into the software development lifecycle () of software combining classical and quantum computing. Figure 2 and 3 illustrates how both worlds could be combined into on SDLC.

arxiv.org/abs/2307.16345

#sdlc #quantumcomputing #quantum #softwaredevelopment #software

Last updated 2 years ago

aegilops :github::microsoft: · @aegilops
150 followers · 582 posts · Server fosstodon.org

I've wrapped up SpotBugs/FindSecBugs in a bow 🎁 in a GitHub Action, so you can use it in GitHub Code Scanning - free for open source projects, and also available for paid users of GitHub Advanced Security.

SpotBugs and FindSecBugs work with JVM languages - Scala, Java, and Clojure, mainly.

github.com/marketplace/actions

Point it at the results of the build, and go.

#github #sast #scala #jvm #clojure #java #codesecurity #spotbugs #findsecbugs #devsecops #sdlc

Last updated 2 years ago

aegilops :github::microsoft: · @aegilops
147 followers · 576 posts · Server fosstodon.org

I’ve released more GitHub :github: Secret 🔑 Scanning 🔎 custom patterns, which you can use with Advanced Security.

Some are 🔥 (IMHO), some are for auditing only - e.g. my “common passwords” pattern, written to spot some of the most commonly leaked weak passwords - “P@55word123!” etc.

We have DataDog, Sentry, .Net configs, MS SQLServer user creation, and Bearer tokens.

aegilops.github.io/posts/new-g

#github #secretscanning #appsec #sdlc #regex

Last updated 2 years ago

aegilops :github::microsoft: · @aegilops
147 followers · 576 posts · Server fosstodon.org

I’ve released more GitHub :github: Secret 🔑 Scanning 🔎 custom patterns, which you can use if you have Advanced Security.

Some are 🔥 (if I say so myself), some are for auditing only - e.g. my “common passwords” pattern, written to spot some of the most commonly leaked weak passwords - “P@55word123!” and the like.

We’ve got DataDog, Sentry, .Net configs, MS SQLServer user creation, and Bearer tokens.

lnkd.in/eqRG_FRa

#github #secretscanning #appsec #sdlc #SecretsManagement #regex

Last updated 2 years ago

Jan Bartosik · @janbartosik
91 followers · 698 posts · Server witter.cz
aegilops :github::microsoft: · @aegilops
146 followers · 560 posts · Server fosstodon.org

Microsoft :microsoft: have an open job for a Security Program Manager for Open Source.

“Help us solve open source security challenges at scale, both for the company and the world. If you live at the intersection of open source, software engineering, security, and making things happen, please take a look… [It] is US-based, but…up to 100% remote”

jobs.careers.microsoft.com/glo

#jobs #sdlc #appsec #opensource #OpenSSF #security #CodeQL

Last updated 2 years ago

Max Jonas Werner · @makkes
124 followers · 285 posts · Server hachyderm.io

Peeps, can we maybe all agree to use Semver correctly, i.e. when a dep's patch version is updated, I don't even want to have to read the release notes, for minor updates I might check for nice new features and only for major bumps I MUST read the release notes. 🙏

#sdlc #SBOM #keepingmysanity

Last updated 2 years ago

DevConf · @DevConf
113 followers · 218 posts · Server mastodon.cloud

Such a fascinating talk by Johan Venter, “An overview of software development at the SKA Observatory”.
Dev & testing covered in this great talk!

#devconf #ska #sdlc

Last updated 2 years ago

Six Feet Up · @sixfeetup
12 followers · 105 posts · Server sixfeetup.social

In Part 3 of the Podcast 🎙️ with @etdebruin of @7ctos, @calvinhp talks about optimizing with .

👉 LISTEN: t.co/QYjmX0khzf

🚀 Accelerate with the BEST Framework: t.co/Svtplwj5ms

t.co/oIqaCoRyIj

#cto #development #automation #sdlc #softwaredevelopment #bestpractices

Last updated 2 years ago

Adam Dymitruk :uv: :em: :tux: · @adymitruk
2141 followers · 1869 posts · Server techhub.social

Why does matter?

Agilists try to confuse people into thinking R&D (where you trial & error a lot and iterate) is engineering. It's only a part of engineering in the initial phase. is working from the resulting blueprints and schematics to build in a reliable and predictable manner. software development is NOT engineering.

If you're new to this concept, go to EventModeling.org to read more.

#eventmodeling #engineering #agile #research #development #sdlc

Last updated 2 years ago

Six Feet Up · @sixfeetup
12 followers · 103 posts · Server sixfeetup.social

Explore the ultimate framework for accelerating your Software Development Life Cycle (SDLC).

📆 Schedule a free demo of BEST: t.co/Svtplwj5ms 

#sdlc #softwaredevelopment #bestpractices

Last updated 2 years ago

Six Feet Up · @sixfeetup
12 followers · 100 posts · Server sixfeetup.social

✨ Want to learn more about accelerating your Software Development Life Cycle ()? 🚀Schedule a free demo of the BEST™ framework: t.co/ceDGbMko2b

#sdlc

Last updated 2 years ago

AndiMann · @AndiMann
345 followers · 929 posts · Server masto.ai

"@datadoghq acquires @Codiga"

Love this! Lots of my time at @CATechnologies & @splunk was on -driven in , incl. code quality & security scanning.

Smart pickup for $DDOG esp. since $SPLK abandoned & tools.

datadoghq.com/blog/datadog-acq

#data #valuestreammanagement #sdlc #vsm #devteam

Last updated 2 years ago

Keith Davies · @kjdavies
78 followers · 422 posts · Server dice.camp

Whoo... this is a meaty one, capturing (at a high level) pretty much everything I know today about the media library manager. Technically I'm caught up on the A-Z Blog Challenge (no posts outstanding) but I don't have one yet for tomorrow.

kjd-imc.org/blog/media-library

#medialibrary #sdlc #azblogchallenge #datamodeling

Last updated 2 years ago

Keith Davies · @kjdavies
78 followers · 420 posts · Server dice.camp

What with being two days behind schedule for 'L Day', 'Little Bit Late' could've been an acceptable title also.

kjd-imc.org/blog/media-library

#medialibrary #sdlc #azblogchallenge #datamodeling

Last updated 2 years ago

Keith Davies · @kjdavies
77 followers · 410 posts · Server dice.camp

Expanding a little on column type definitions, tomorrow probably looking more specifically at how entities would be modeled.

kjd-imc.org/blog/keiths-custom

#medialibrary #sdlc #azblogchallenge #datamodeling

Last updated 2 years ago

Keith Davies · @kjdavies
76 followers · 409 posts · Server dice.camp

There's a reason 'J' is worth 8 points in Scrabble. I ended up with something of a contrived post title for 'J' day.

Here, I take a look at the metadata options in calibre, and touch a little on how I think I might implement a similar concept in my media library (which I might expand on in tomorrow's post, if I can come up with a title starting with 'K').

kjd-imc.org/blog/media-library

#medialibrary #sdlc #azblogchallenge #datamodeling

Last updated 2 years ago

Keith Davies · @kjdavies
76 followers · 407 posts · Server dice.camp

Right, I knew not all programming is the same, but I haven't had it hit this hard in a while. Time to crack some books.

kjd-imc.org/blog/media-library

#medialibrary #sdlc #azblogchallenge #todayilearn

Last updated 2 years ago

AndiMann · @AndiMann
342 followers · 906 posts · Server masto.ai

"When Meets to Protect "

Great in-depth piece w/ practical & actionable steps for developers & engineers to meet the imperative in their Software Supply Chain. So much more than lip service to !

infoq.com/articles/devops-secu

#devops #security #software #sdlc #cybersecurity #devsecops

Last updated 2 years ago