Secure Coding in Python

Secure Coding in Python

1h 37mAdvanced2024-12-16

Authors

Ronnie Sheer

Ronnie Sheer

Software Developer and Instructor

Course details

Learn how to develop more secure Python applications. In this course, targeted uniquely at advanced Python users, instructor Ronnie Sheer reviews the most common vulnerabilities in Python apps and explains how to set up a coding environment that helps you develop code with security in mind. Learn how to avoid common pitfalls associated with loose typing and assertions and find out how to deserialize Pickle data. Then explore the security features—such as code generation and secrets management—in Django, a popular Python framework. Ronnie also explains how to secure a RESTful API in Django using permissions, data serialization, and automated testing. By the end of this course, you’ll also be equipped with practical tips and strategies for securing applications written with Flask, the powerful micro web framework.

Skills covered

Software Development SecurityGenerative AIPythonArtificial Intelligence (AI)CybersecurityProgramming LanguagesOpen SourceSoftware DevelopmentOne-Off

Concepts

Introduction

  • Developing Python securely
  • What you should know
  • What are secure coding, CERT and other standards
  • What is the OWASP Top 10
  • Using Codespaces

Setting Up

  • Installing software with due caution
  • Installing pipenv, Python, Django, Flask, and the Django REST Framework
  • Common vulnerabilities and exposures checks
  • A few words about encryption and injection

Avoiding Python Pitfalls

  • Dynamic typing with Python
  • Explicit assertions with Python
  • Don't get yourself into a Pickle
  • Challenge - Secure the endpoint
  • Solution - Secure the endpoint

Securing Django

  • Using a separate Python environment for isolation
  • Django's batteries included approach
  • Generating new projects

AI and Secure Coding

  • Generative AI and software development
  • AI-powered developer tools
  • Prompt injection and jailbreaking

Securing a RESTful API

  • Safe serializing
  • Permissions
  • Testing and security
  • Challenge - Run the test, fix the code
  • Solution - Serializer fields

Securing Flask

  • The challenge of securing Flask
  • Flask secrets
  • Password hashing with Flask

Conclusion

  • Next steps - Secure coding
40,000 Toman