aws-samples / aws-samples/aws-devsecops-workshop
Automated Security Assessment Chapter
- 主要言語
- HTML
- スター
- 18
- フォーク
- 12
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
**Is your feature request related to a problem? Please describe.**
Customers want to identify security vulnerabilities as well as deviations from security best practices in applications, both before they are deployed, and while they are running in a production environment.
**Describe the solution you'd like**
Adding a chapter focused on Amazon Inspector. We want to make it easy to build Inspector assessments right into the existing DevSecOps process, decentralising and automating vulnerability assessments.
**Describe alternatives you've considered**
Amazon Detector - hard to integrate as per a pipeline.
コントリビューションガイド
調査の方向性
既存の DevSecOps ワークショップの章とパイプラインのフローを確認し、Amazon Inspector のアセスメントに関する章をどこに組み込むべきかを判断します。その章のデプロイと本番環境でのアセスメントの範囲を定義し、プロセスとの統合方法を文書化して、完成したワークショップで自動化された脆弱性およびベストプラクティスのアセスメントについて説明されていることを確認します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- aws
- 領域
- devops, documentation, security
- issue の種類
- ドキュメント
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 25/100