In modern-day software program development, continuous integration and non-stop deployment (CI/CD) pipelines have become critical for automating and accelerating the discharge system. However, the short-paced nature of CI/CD pipelines can introduce safety vulnerabilities if not nicely managed. This paper surveys the mixing of computerized security testing within CI/CD pipelines, specializing in broadly adopted strategies like Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Vulnerability Assessment and Penetration Testing (VAPT). These techniques enable the early detection of essential vulnerabilities such as buffer overflows, injection attacks, and insecure authentication mechanisms. By incorporating automatic security assessments into the CI/CD workflow, groups can continuously check the safety of their packages without delaying development. The survey offers a realistic framework for groups aiming to deliver stable software at speed, leveraging automation to guard against common vulnerabilities.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Automated Security Testing Using CI/CD Pipeline

  • Shravani Deshmukh,
  • Rushikesh Patil,
  • Satish Narkhede

摘要

In modern-day software program development, continuous integration and non-stop deployment (CI/CD) pipelines have become critical for automating and accelerating the discharge system. However, the short-paced nature of CI/CD pipelines can introduce safety vulnerabilities if not nicely managed. This paper surveys the mixing of computerized security testing within CI/CD pipelines, specializing in broadly adopted strategies like Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Vulnerability Assessment and Penetration Testing (VAPT). These techniques enable the early detection of essential vulnerabilities such as buffer overflows, injection attacks, and insecure authentication mechanisms. By incorporating automatic security assessments into the CI/CD workflow, groups can continuously check the safety of their packages without delaying development. The survey offers a realistic framework for groups aiming to deliver stable software at speed, leveraging automation to guard against common vulnerabilities.