Marco Lancini 12/12/2020

Semgrep for Cloud Security

Read Original

This technical article examines the application of the Semgrep static analysis tool for cloud security. It details experiments using Semgrep's generic pattern matching to detect vulnerabilities such as unencrypted EBS volumes and open security groups within Infrastructure as Code (IaC) like Terraform and Kubernetes YAML files, aiming to shift security left in the development lifecycle.

Semgrep for Cloud Security

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

2
Designing Design Systems
TkDodo Dominik Dorfmeister 2 votes
3
Introducing RSC Explorer
Dan Abramov 1 votes
5
Fragments Dec 11
Martin Fowler 1 votes
6
Adding Type Hints to my Blog
Daniel Feldroy 1 votes
7
Refactoring English: Month 12
Michael Lynch 1 votes
9