Tool optimization

Once the teams have been using the code scanning tools for a while, the security team may help to optimize the tools, processes, or rules based on user feedback. Here are some key factors to be optimized for a large-scale code scanning adoption:

Key factors

Suggestions

Scanning rules customization

The purpose of rules customization is to help the project team reduce false positives. The security team may help to disable some rules that don't apply to the projects or change rules that always result in false positives.

Recommendation fixes

Ideally, IDE plugins will present not only security warnings but also suggested fixes. However, if the tools you are using don't support the team, using the OWASP Security ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.