Security Testing in the Pipeline
SAST, DAST, dependency and secret scanning, and what to do with the findings.
4 to work through
-
beginner
A dependency scanner reports a critical vulnerability in a library your application includes. Reading the advisory, the flaw is in a parser your code never calls. Why does the scanner report it anyway, and what should that change about how you triage?
3 min answer -
intermediate
A pipeline runs security scanning and produces hundreds of findings that nobody acts on. What should change?
2 min answer -
intermediate
Which security checks belong in the pipeline, and what makes them useful rather than noise?
2 min answer -
advanced
You enable dependency scanning. It reports 4,200 vulnerabilities across the estate, 380 critical. What do you do on Monday?
2 min answer
2 terms in this topic
Security Testing in the Pipeline
Automated security analysis embedded in the build, chosen and tuned so that findings are actionable rather than overwhelming.
practiceShift-Left Security
Moving security checks earlier so findings arrive while the author still has context, on the condition that the signal-to-noise ratio justifies it.
Neighbouring topics
Testing & Quality Architecture
General material on designing a testing strategy as an architectural concern.
Test Architecture Strategy
Choosing what to verify where, given the failure modes that actually occur.
Test Pyramid Shapes
Pyramid, trophy and honeycomb, and the system properties that justify each shape.
Integration Test Boundaries
What sits inside a test's boundary, what is faked, and the confidence that follows.
Contract Testing at Scale
Keeping dozens of services compatible without an environment that runs all of them.
Consumer-Driven Contracts
Consumers declaring what they rely on, and providers verifying against those declarations.
Test Data Management
Realistic data without copying production personal data into a weaker environment.
Synthetic Data
Generating data with the shape and edge cases of the real thing, and where it misleads.
Environment Parity
The differences between staging and production that decide which bugs survive to release.
Service Virtualisation
Standing in for a dependency you cannot call, and keeping the stand-in honest.
End-to-End Test Economics
Why broad end-to-end suites get slow, flaky and abandoned, and what to keep.
Non-Functional Test Strategy
Testing availability, latency, security and recovery rather than only behaviour.
Performance Test Design
Workload models, warm-up, think time, and the distribution the average hides.
Chaos as a Test
Fault injection with a hypothesis, a blast radius and an abort condition.
Accessibility Testing
Automated checks, their ceiling, and the manual testing that has to sit above it.
Mutation Testing
Measuring whether tests would actually notice a defect, not just cover a line.
Flaky Test Management
Quarantine, detection, and the trust a suite loses once red stops meaning broken.
Testing in Production
Synthetic transactions, dark launches and shadow traffic, done deliberately and safely.
Quality Gates
Thresholds that block a release, who may override them, and how they decay.