This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP DevSlop Project"
From OWASP
m (→Team Members) (Tag: Visual edit) |
Tanyajanca (talk | contribs) (→Description: More updates) (Tag: Visual edit) |
||
(4 intermediate revisions by the same user not shown) | |||
Line 7: | Line 7: | ||
==OWASP [http://devslop.co DevSlop] Tool Project== | ==OWASP [http://devslop.co DevSlop] Tool Project== | ||
− | '' | + | ''DevSlop: learning how application security professionals fit into DevOps.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] |
Project Website: [http://devslop.co DevSlop] | Project Website: [http://devslop.co DevSlop] | ||
− | Modern applications often use APIs, microservices and containerization to deliver faster and better products and services | + | Modern applications often use APIs, microservices and containerization to deliver faster and better products and services, however this changing landscape means security people need to step up their game. DevSlop, "Sloppy DevOps", is an exploration into this area, via several different modules consisting of pipelines, vulnerable apps, and [https://www.youtube.com/channel/UCSmjcWvgVBqF3x_7e5rfe3A The DevSlop Show], where project members learn and share. |
==Description== | ==Description== | ||
− | DevSlop's '''Pixi''' | + | DevSlop has many modules, including: |
+ | |||
+ | '''Patty''' - An Azure DevSecOps pipeline, with constantly changing components, which published the project's website, [http://devslop.co DevSlop.co]. | ||
+ | |||
+ | '''Pixi-CRS''' & '''Pixi-CRS-ZAP''' are two Circle-CI pipelines that demonstrate adding a WAF to your pipeline for automatic tuning before moving your apps to prod. | ||
+ | |||
+ | '''Pixi''' is an intentionally vulnerable app and consists of a vulnerable web app and API service. | ||
+ | |||
+ | [https://www.youtube.com/channel/UCSmjcWvgVBqF3x_7e5rfe3A '''The DevSlop Show'''] is a video streaming series where project members build things live, interview members of the OWASP and InfoSec community, and learn where they fit into DevOps. | ||
+ | |||
+ | [[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]] | ||
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here. | As more pieces of [http://devslop.co DevSlop] are released they will be introduced here. | ||
Line 24: | Line 34: | ||
== Project Resources == | == Project Resources == | ||
− | |||
− | |||
[https://github.com/DevSlop/ Source Code] | [https://github.com/DevSlop/ Source Code] | ||
Line 46: | Line 54: | ||
== Project Leader == | == Project Leader == | ||
− | [[User: | + | [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] |
− | + | Nancy Gariché [https://twitter.com/nanzgtweets Twitter] | |
− | [[User: | + | [[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] |
Line 82: | Line 90: | ||
== News and Events == | == News and Events == | ||
+ | * Nancy Gariché was promoted to leader, making 3 leaders of this project! | ||
* [http://devslop.co/Home/Schedule Check out our schedule!] | * [http://devslop.co/Home/Schedule Check out our schedule!] | ||
* [July 2] Tanya Janca will be giving the "Hack Your Own Apps" workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. | * [July 2] Tanya Janca will be giving the "Hack Your Own Apps" workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. | ||
Line 131: | Line 140: | ||
'''How can I follow updates on the project?''' | '''How can I follow updates on the project?''' | ||
− | [https://twitter.com/ | + | [https://twitter.com/OWASP_DevSlop DevSlop on Twitter] |
[https://twitter.com/shehackspurple Tanya Janca on Twitter] | [https://twitter.com/shehackspurple Tanya Janca on Twitter] | ||
Line 148: | Line 157: | ||
The first contributors to the project were: | The first contributors to the project were: | ||
− | |||
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] | * [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] | ||
− | * [ | + | * Nancy Gariché [https://twitter.com/nanzgtweets Twitter] |
+ | * Nicole Becher [https://twitter.com/thedeadrobots Twitter] | ||
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter] | * [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter] | ||