Skip to content

Latest commit

 

History

History
35 lines (19 loc) · 3.05 KB

CODE-007-Inline-IDE-Secure-Code-Analysis.md

File metadata and controls

35 lines (19 loc) · 3.05 KB

Inline IDE Secure Code Analysis

ID
DSOVS-CODE-007

Summary

IDE powered code scanning is the process of automatically scanning source code for potential security vulnerabilities, using an integrated development environment (IDE) as a platform.

It is an important part of DevSecOps because it helps developers identify any potential security issues before the application is deployed.

By scanning code for vulnerabilities in the IDE, developers can be sure that applications remain secure and help protect users from potential threats.

Additionally, many IDEs come with built-in security scanning tools which can help speed up the process of identifying and addressing any potential vulnerabilities.

This helps to ensure that applications are secure and that any security issues are addressed quickly and effectively.

Level 0 - No tool to assist developer with inline code analysis

lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum

Level 1 - Verify the use of integrated development environment (IDE) plugin to perform inline secure code or hardcoded secrets analysis with locally defined rules

lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum

Level 2 - Verify implementation of centralised managed rules for integrated development environment (IDE) plugin

lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum

Level 3 - Verify a mechanism to prevent insecure changes to be stored to source code repository

lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum

References