Michael Mollard
Architech Developer @ Sipios
Avoid known vulnerabilities
14% of NPM packages
50M downloads /Months
OWASP Top 10 since 2013
Avoid common mistakes with static code analyzer
False positive
The developers knows it is a false positve and report it as such
Known vulnerability
The developers knows this vulnerability and can fix it alone
New vulnerability
The developers ask the security expert for an explanation
Dynamic analysis
A lot of tools can be brought to the developers IDE
https://github.com/mre/awesome-static-analysis
By security expert for developers
https://github.com/mre/awesome-static-analysis
https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project
https://snyk.io/
https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
https://www.sonarqube.org/