2
5 Comments

Building Application Security in the Azure DevOps Pipeline

  1. 1

    Security testing is a critical component of the SDLC that should not be overlooked. With DevOps practises taking centre stage in software development, including security testing in your CI/CD pipeline is more important than ever before as you ship new features faster than ever before.

  2. 1

    When we say "Application security" usually we mean Authentication and IAM, I'm not really following what application security has to do with a Azure DevOps pipeline. This just seems like an ad and an unclear one at that.

    1. 0

      Authorization and authentication is not part of Application Security. Although as part of an application they might be affected by Application Security. You kind of have a wrong understanding of the terminus. Wikipedia might be a good resource to get a correct overview how the terminus is generally used. https://en.m.wikipedia.org/wiki/Application_security

      1. 1

        All I can really say is LOL:

        • terminus doesn't mean what you think it means
          And
        • Both of those are listed as prominent on the page you linked.

        Did you even read the wiki page before you posted on here?

        1. 1

          "Application security" === "measures taken to improve the security of an application".

          Running penetration tests in an Azure DevOps pipeline might be a good "measure taken to improve the security of an application", therefore the article holds the promise of its title.

          As authZ/authN are part of an application or an application by itself, they might need "measures taken to improve the security of that said application" and therefore might be affected by "Application security". Thats why they are listed on the wiki, together with Cryptography, Configuration management, Parameter Manipulation, SQL Injection, XSS, ...

          So when we say "Application security" we usually do not mean Authentication and IAM per se.

          I can feel with you that you felt disappointed that the article didn't deal with authN, authZ and IAM as you expected. But the author has a valid point.

          Btw: good catch with the term "terminus".

Trending on Indie Hackers
I talked to 8 SaaS founders, these are the most common SaaS tools they use 20 comments What are your cold outreach conversion rates? Top 3 Metrics And Benchmarks To Track 19 comments How I Sourced 60% of Customers From Linkedin, Organically 12 comments Hero Section Copywriting Framework that Converts 3x 12 comments Promptzone - first-of-its-kind social media platform dedicated to all things AI. 8 comments How to create a rating system with Tailwind CSS and Alpinejs 7 comments