We may earn a commission from partner links, which help us to research and write, this never affects our product reviews and recommendations. How to Find Security Vulnerabilities in Python Application?
Python ãã®2 Advent Calendar 2018 16æ¥ç®ã®æ稿ã空ãã¦ããã®ã§ããã£ã¡ãæ¥ãéãã¦ã¾ããé£ã³è¾¼ã¿æ稿ã ä»åã¯ãæ¨ä»ããèãããã«ãªã£ããDevSecOpsã(DevOps + Security) æ´»åã§éè¦ã«ãªã£ã¦ããããã»ãã¥ãªãã£ãã¹ããèªåã§åãããå®ç¾ããããã®ãã¼ã«ãç´¹ä»ãã¾ãã DevSecOpsã«ã¤ãã¦ã¯ãã®ããããåç §ã2018å¹´ã®ãã¬ã³ããããã§ãã 2018å¹´ã®ãã¬ã³ãã¯ãDevOpsã«ã»ãã¥ãªãã£ãèåãããDevSecOpsã (1/2) - ITmedia ã¨ã³ã¿ã¼ãã©ã¤ãº èªåã»ãã¥ãªãã£ãã¹ãã«ã¯ SAST, DAST, IAST ã¨å¼ã°ãããã®ãããã¾ãã SAST: Static Application Security Testingï¼éçã»ãã¥ãªãã£æ¤æ»ï¼ ã½ã¼ã¹ã³ã¼ãèªä½ã解æã»æ¤æ»ãã¦èå¼±æ§ãè¦ã¤ãåºããã® åãã³
åå¿é²ã¨ãã¦ã ã³ã¼ãã¡ããªã¯ã¹è§£æãã¼ã« Radon ä¸è¨ææ¨ãè¨æ¸¬å¯è½ã 循ç°çè¤é度ï¼Cyclomatic complexityï¼ ä¿å®å®¹ææ§ææ°ï¼Maintainability Index ï¼ å¾ªç°çè¤é度ï¼Cyclomatic complexityï¼ã®è¨æ¸¬ä¾ã radon cc -s -e "*/tests/*" --min F src/ä¿å®å®¹ææ§ææ°ï¼Maintainability Index ï¼ã®è¨æ¸¬ä¾ã radon mi -s -e "*/tests/*" --min C src/ åè GitHub - rubik/radon: Various code metrics for Python code ä¿å®æ§ã»å¯èªæ§ã®é«ãPythonã³ã¼ããå®è£ ããããã«ã¯ã©ãããã°ããã - ã¯ã¦ãªã®é次é ãã¡ã¸ã³ã°ãã¼ã« syzkaller/syzbot åè "syzbot"ã¨"
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}