Are you tired of wasting time on false positives flagged by traditional static analysis tools? 🤔
Join us tomorrow, March 11th at 9 AM PT, to learn how Semgrep combines AI and static analysis to transform your code scanning process.
🔍 What you'll learn:
✅ How Semgrep Assistant reduces false positives with a 95% human agreement rate
✅ How this approach cuts triage efforts by 20%
✅ Why integrating AI into your security process makes shift-left more practical for AppSec and developers
🔗 Register Now: semgrep.dev/events/ai-powere…#AI#Security#Semgrep#AppSec#LLMs#CodeScanning#DevSecOps
#AmazonInspector now supports code scanning of #AWSLambda functions (in preview), expanding the existing capability to scan Lambda functions.
🎞️ Watch the demo to learn how to activate this expanded #codescanning capability: go.aws/3AT4kZV
0:39
Amazon Inspector: How to use Lambda Code Scanning | AWS
News: With only a few clicks, developers can configure code scanning for a repository using the new default setup introduced by GitHub. Although GitHub’s code scanning is powered by the CodeQL… dlvr.it/SggSrs#Devops#coderepository#codescanning#GitHub Follow us now
With betterscan.io you can store state in Database (PostgreSQL, MySQL/MariaDB, Oracle, Microsoft SQL Server) or in you Git repo. Outputs in CLI, HTML, SARIF, JSON. This works nicely with GitHub Codescanning, GitLab Security and Compliance and Azure DevOps Server
Great read on how GitHub Advanced Security can help move towards DevSecOps with tools such as CodeScanning, CodeQL, Secret Scanning, and a unified view of the results close to the developers. @github, #advancedsecurity. nickliffen.dev/articles/why-…
Looking for a security researcher! You'll help to generate automated code fixes for static analysis findings across a range of popular programming languages. Software development or SDLC experience a plus. veracode.com/job-post?gh_jid…