Secure Coding in Python
1h 37mAdvanced2024-12-16
Authors

Ronnie Sheer
Software Developer and Instructor
Course details
Learn how to develop more secure Python applications. In this course, targeted uniquely at advanced Python users, instructor Ronnie Sheer reviews the most common vulnerabilities in Python apps and explains how to set up a coding environment that helps you develop code with security in mind. Learn how to avoid common pitfalls associated with loose typing and assertions and find out how to deserialize Pickle data. Then explore the security features—such as code generation and secrets management—in Django, a popular Python framework. Ronnie also explains how to secure a RESTful API in Django using permissions, data serialization, and automated testing. By the end of this course, you’ll also be equipped with practical tips and strategies for securing applications written with Flask, the powerful micro web framework.
Skills covered
Software Development SecurityGenerative AIPythonCybersecurityArtificial Intelligence (AI)Programming LanguagesOpen SourceSoftware DevelopmentOne-Off
Concepts
0. Introduction
- 01 - Developing Python securely
- 02 - What you should know
- 03 - What are secure coding, CERT and other standards
- 04 - What is the OWASP Top 10
- 05 - Using Codespaces
1. Setting Up
- 06 - Installing software with due caution
- 07 - Installing pipenv, Python, Django, Flask, and the Django REST Framework
- 08 - Common vulnerabilities and exposures checks
- 09 - A few words about encryption and injection
2. Avoiding Python Pitfalls
- 10 - Dynamic typing with Python
- 11 - Explicit assertions with Python
- 12 - Don't get yourself into a Pickle
- 13 - Challenge - Secure the endpoint
- 14 - Solution - Secure the endpoint
3. Securing Django
- 15 - Using a separate Python environment for isolation
- 16 - Django's batteries included approach
- 17 - Generating new projects
4. AI and Secure Coding
- 18 - Generative AI and software development
- 19 - AI-powered developer tools
- 20 - Prompt injection and jailbreaking
5. Securing a RESTful API
- 21 - Safe serializing
- 22 - Permissions
- 23 - Testing and security
- 24 - Challenge - Run the test, fix the code
- 25 - Solution - Serializer fields
6. Securing Flask
- 26 - The challenge of securing Flask
- 27 - Flask secrets
- 28 - Password hashing with Flask
Conclusion
- 29 - Next steps - Secure coding