arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.00676cs.CRcs.SE

通过CI/CD流水线集成实现静态代码分析自动化

Automating Static Code Analysis Through CI/CD Pipeline Integration

Zachary Wadhams, Ann Marie Reinhold, Clemente Izurieta

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出一种自动化流程,将SAST工具输出聚合后集成到问题跟踪软件,在GitLab环境中用SonarQube实现,可提升软件开发安全态势,获开发人员积极反馈。

中文摘要 AI 辅助

在当代软件开发领域,保护敏感数据对维护组织声誉、防止财务损失及保护个人免受身份盗用至关重要。本文解决了在开发过程早期识别和修复安全漏洞这一普遍挑战,强调了静态应用安全测试(SAST)工具的作用。尽管SAST工具在检测漏洞方面发挥着关键作用,但其广泛采用受到可用性问题的阻碍,包括高误报率和缺乏原生流水线支持。本文提出了一种新颖、通用且自动化的流程,用于聚合SAST工具的输出并将其集成到开发人员熟悉的问题跟踪软件中。该流程简化了开发生命周期中安全漏洞的识别和沟通,促进了更高效的修复工作。我们在基于GitLab的开发环境中,通过SonarQube SAST工具成功实现了所提出的流程。开发人员对结构化实施、实时反馈和主动漏洞管理持积极态度。然而,尽管存在一些挑战,如潜在的学习曲线以及安全编码与工作流程中断之间的权衡,但对安全意识和响应能力的整体积极影响表明,所提出的流程有望提升软件开发实践的安全态势。

英文摘要

In the contemporary landscape of software devel-opment, securing sensitive data is paramount to safeguarding organizational reputation, preventing financial losses, and pro-tecting individuals from identity theft. This paper addresses the pervasive challenge of identifying and rectifying security vulnerabilities early in the development process, emphasizing the role of Static Application Security Testing (SAST) tools. While SAST tools play a crucial role in detecting vulnerabilities, widespread adoption has been hindered by usability issues, including high false positive rates and a lack of native pipeline support. This paper proposes a novel, generalized, and automated process for aggregating SAST tool outputs and integrating them into developers' familiar issue-tracking software. The process streamlines the identification and communication of security vulnerabilities during the development lifecycle, facilitating more efficient remediation efforts. We demonstrate the successful implementation of the proposed process with the SonarQube SAST tool in a GitLab-based development environment. Developers were positive about the structured implementation, real-time feedback, and proactive vulnerability management. However, despite some challenges such as a potential learning curve and tradeoffs between secure coding and workflow disruption, the overall positive impact on security awareness and responsiveness suggests that the proposed process holds promise in enhancing the security posture of software development practices

发表机构

  • Gianforte School of Computing Montana State University(蒙大拿州立大学吉安福特计算学院)
  • Pacific Northwest National Laboratory Idaho National Laboratory(太平洋西北国家实验室爱达荷国家实验室)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑