Description
In this episode we discussed all-things application security; from scanning, to designing with security in mind, through OWASP and sources of information we feel engineers in the world of dev / ops should be aware of and familiar with!
We talked about:
OWASP Top 10 - https://owasp.org/www-project-top-tenGit leaks - https://github.com/zricethezav/gitleaks12 Factor - https://12factor.netScanners: [Python Bandit: https://bandit.readthedocs.io/en/latest, Go: https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck]Clair static analysis for containers: https://github.com/quay/clairBug Bounty platforms: HackerOne, Bugcrowd, IntigrityBGP repo cleaner - remove secrets from git history: https://rtyley.github.io/bfg-repo-cleanerHarden EKS - https://github.com/aws-samples/hardeneks
Meir's blog: https://meirg.co.il
Omer's blog: https://omerxx.com
Telegram channel: https://t.me/espressops
Send us a Text Message.In this episode we talked about k8s nodes monitoring and as always, found ourselves going way beyondLinks - https://dotenvx.com/Meir's blog: https://meirg.co.ilOmer's blog: https://omerxx.com Telegram channel: https://t.me/espressops
Published 07/27/24
This week we had a debate around how AI is moving forward, the outlook on engineering jobs and how we use it daily as time progresses.Links: - https://blog.pragmaticengineer.com/the-ai-developer/- https://blog.pragmaticengineer.com/the-ai-developer/The Neil Ashton PodcastThis podcast focuses on...
Published 05/09/24