Learning Static Code Analysis

Learning Static Code Analysis

55mBeginner2023-12-05

Authors

Kalyna Reda

Kalyna Reda

Course details

If you’re just getting started in your career or are interested in landing a new role in DevSecOps, you may want to consider boosting your skills in static code analysis. In this course, explore the tangible benefits of DevSecOps, particularly static code analysis, along with some of the common tools and techniques used frequently in Azure to perform it. Instructor Kalyna Reda provides hands-on, interactive demonstrations that show you how to scan open-source code, set up and scan a YAML pipeline, publish the results of a scan, and improve your code based on a scan’s findings. By the end of this course, you’ll be prepared to take your new skills to the next level with additional deployments and other cutting-edge DevSecOps tools.

Skills covered

Software Development SecurityDevOps FoundationsAmazon Web Services (AWS)AmazonDevOpsProjectCybersecurity

Concepts

Introduction

  • Static code analysis overview
  • What you should know

DevSecOps

  • DevSecOps overview
  • Benefits of DevSecOps
  • Defining static code analysis
  • How static code analysis differs from other scanning methods

Static Code Analysis

  • Static code analysis on Azure DevOps
  • Decisions to consider when choosing between tools

Demo - Scan Your Code

  • Open-source code
  • Introduction to YAML
  • Set up your YAML pipeline
  • Add scanning ability
  • Publish the results

Demo - Improve Your Code Based on the Findings

  • Review the results
  • Take action to improve the environment
  • Rerun and verify

Conclusion

  • Next steps
40,000 Toman