Using Static Analysis to Catch Configuration Vulnerabilities
Offered By: Docker via YouTube
Course Description
Overview
Explore the critical role of static analysis in identifying and preventing configuration vulnerabilities in containerized environments and Infrastructure as Code (IaC) setups. Learn how misconfigurations can lead to security risks such as exposed secrets, data leaks, unauthorized access, and DDoS attacks. Discover the importance of shifting left in the software development lifecycle to catch vulnerabilities early. Examine common pitfalls in Dockerfile configurations that can introduce security vulnerabilities and poor practices. Gain insights into Static Analysis and Software Composition Analysis techniques for securing code and dependencies. Follow a practical demonstration on setting up Static Analysis in your IDE to scan Dockerfiles, receive suggested fixes, and implement gating mechanisms to block critical issues. Presented by Borja Burgos, Director of Product Management at DataDog, this 38-minute conference talk from DockerCon 2023 equips developers and DevOps professionals with essential knowledge to enhance the security of their containerized applications and infrastructure.
Syllabus
Using Static Analysis to Catch Configuration Vulnerabilities (DockerCon 2023)
Taught by
Docker
Related Courses
Cloud Computing Applications, Part 1: Cloud Systems and InfrastructureUniversity of Illinois at Urbana-Champaign via Coursera Introduction to Cloud Infrastructure Technologies
Linux Foundation via edX Introduction aux conteneurs
Microsoft Virtual Academy via OpenClassrooms The Docker for DevOps course: From development to production
Udemy Windows Server 2016: Virtualization
Microsoft via edX