Meta tags:
description= By shifting security left, you can significantly de-risk your code vulnerabilities. ;
Headings (most frequently used words):
security, the, in, enterprise, support, incorporating, devops, workflows, more, stories, product, platform, company, planning, our, approach, using, github, advanced, search, queries, outcome, moving, forward, with, mind, securing, platforms, scaling, mlops, education, autonomy, vs, governance, delicate, balance, of, power, privacy, engineering, tips, to, mitigate, risks, and, secure, your, data, about, readme, project, follow, us, nominate, developer, community, sign, up, for, newsletter,
Text of the page (most frequently used words):
the (91), and (54), #github (41), #security (41), vulnerabilities (30), for (29), our (26), advanced (16), are (16), with (15), you (14), that (13), open (13), code (13), audit (12), search (12), your (11), can (11), readme (11), how (10), queries (10), community (9), caregility (9), third (9), party (9), all (9), services (8), project (8), from (8), they (8), these (8), were (8), each (8), severity (8), this (7), source (7), risk (7), have (7), developer (6), also (6), customers (6), into (6), development (6), production (6), would (6), remediate (6), repositories (6), progress (6), vulnerability (6), time (5), stories (5), enterprise (5), team (5), developers (5), need (5), but (5), process (5), not (5), internal (5), since (5), able (5), monitor (5), bucket (5), service (5), use (5), first (5), devops (5), jump (5), about (4), platform (4), sign (4), get (4), virtual (4), codebase (4), like (4), their (4), results (4), repo (4), closed (4), them (4), address (4), work (4), priority (4), what (3), 2022 (3), organization (3), support (3), resources (3), features (3), every (3), new (3), articles (3), nominate (3), explore (3), world (3), teams (3), manage (3), workflow (3), helps (3), only (3), trust (3), stakeholders (3), companies (3), prioritize (3), tooling (3), than (3), once (3), prepare (3), needed (3), forward (3), when (3), actions (3), run (3), allows (3), review (3), using (3), which (3), within (3), where (3), blockers (3), then (3), remediation (3), order (3), resolution (3), bandwidth (3), tolerable (3), find (3), query (3), repository (3), was (3), dashboard (3), plan (3), had (3), quickly (3), scanning (3), incorporating (3), workflows (3), signed (2), another (2), tab (2), window (2), refresh (2), session (2), reload (2), action (2), privacy (2), 2023 (2), blog (2), skills (2), pricing (2), customer (2), product (2), podcast (2), other (2), content (2), around (2), working (2), help (2), projects (2), effort (2), voices (2), culture (2), seen (2), maintainers (2), long (2), software (2), fix (2), issues (2), field (2), secure (2), education (2), more (2), provides (2), two (2), way (2), introduced (2), prepared (2), investors (2), after (2), prioritizing (2), potential (2), down (2), helped (2), made (2), realize (2), moving (2), feedback (2), secrets (2), ensure (2), left (2), mind (2), preparing (2), remediating (2), over (2), cleaner (2), otherwise (2), users (2), outcome (2), shows (2), easily (2), information (2), short (2), any (2), sort (2), list (2), specific (2), example (2), some (2), because (2), below (2), easy (2), type (2), utilize (2), three (2), critical (2), close (2), state (2), released (2), expose (2), classified (2), approach (2), across (2), will (2), organize (2), make (2), discovered (2), term (2), dependabot (2), codeql (2), secret (2), enabled (2), started (2), audits (2), topics (2), guides (2), packages (2), web (2), 2024 (2), out, perform, git, site, map, updated, terms, inc, tiktok, twitch, youtube, linkedin, facebook, twitter, shop, social, impact, inclusion, press, careers, company, contact, status, professional, forum, docs, desktop, electron, partners, api, roadmap, thank, subscribe, month, share, episodes, great, newsletter, recognize, behind, scenes, inspiring, think, should, feature, follow, part, ongoing, amplify, evolving, space, engage, challenges, technology, surround, coding, usually, solitary, activity, actually, largest, led, contributors, unsung, heroes, put, hours, build, questions, communities, ayden, férdeline, engineering, tips, mitigate, risks, data, gabriel, kohen, blue, yonder, autonomy, governance, delicate, balance, power, noah, gift, pragmatic, labs, scaling, mlops, healthcare, hipaa, compliant, access, audio, video, communication, clinical, integrations, span, inpatient, outpatient, telemedicine, settings, ensuring, unending, notify, eliminating, mitigating, decreased, breach, successfully, solidifying, experience, recommend, adopt, during, avoid, problems, road, handling, rather, securing, platforms, tightly, weave, provisioned, preparation, configured, pipelines, pull, request, immediate, continuous, stance, add, directly, enable, policies, don, leak, found, early, shifting, significantly, derisked, effect, branch, protection, increased, posture, thousand, came, back, many, beforehand, protect, breaches, preserving, products, spending, rewarded, report, crucial, minimized, business, allow, far, along, while, showing, remaining, give, weekly, meetings, repo_names, finally, combine, few, different, come, searching, sorted, now, previously, reasons, acceptable, may, been, didn, deal, tailoring, reopen, those, alerts, auth_service_frontend, customized, show, prefix, specify, front, end, authentication, pretty, essentially, just, key, value, pair, pass, selection, associated, method, sorting, want, most, often, utilized, common, scoring, system, cvss, classification, given, downwards, prototype, remediated, descending, extensive, let, break, low, automated, tests, prototypes, lowest, facing, much, less, likely, exposed, exploited, planned, soon, marked, lower, still, important, unpatched, currently, high, harm, decided, take, centered, components, stage, affected, component, buckets, visualize, tackle, graphic, understand, scope, 100, comprising, its, own, menial, task, however, offers, single, pane, glass, showcases, detected, enter, looking, addition, proactively, encounter, planning, shift, guide, learn, accomplished, running, entire, language, java, javascript, python, ruby, included, continuously, created, initial, lasting, change, processes, future, there, readying, ourselves, tool, overwhelming, anyone, integrating, here, best, practices, efforts, toward, tighter, both, tools, approaching, began, depth, done, showed, errors, highlighted, improperly, stored, credentials, notified, dependencies, felt, opening, pandora, box, devise, strategy, newly, before, connect, providers, clinicians, patients, interpreters, family, members, wherever, whether, enabling, nursing, observation, consultations, paramount, infrastructure, areas, provide, peace, bad, actors, hack, databases, compromise, patient, exploit, catastrophic, see, featured, browse, story, menu, amplifies, whose, contributions, move, day, justin, trugman, babitha, singh, artwork, micha, huigen, message, suggested, collections, trending, fund, sponsors, case, studies, devsecops, automation, solution, startups, solutions, documentation, collaborate, outside, discussions, track, changes, write, better, copilot, instant, dev, environments, codespaces, host, automate, toggle, navigation, skip, wayback, machine, http, archive, org, 20230202224625, https, com, timestamps, capture, fail, success, mar, feb, jan, nov, dec, 178, captures,
Text of the page (random words):
incorporating security in enterprise devops workflows github 178 captures 15 nov 2022 17 dec 2024 jan feb mar 02 2022 2023 2024 success fail about this capture timestamps the wayback machine http web archive org web 20230202224625 https github com readme guides github advanced security caregility skip to content toggle navigation sign up product actions automate any workflow packages host and manage packages security find and fix vulnerabilities codespaces instant dev environments copilot write better code with ai code review manage code changes issues plan and track work discussions collaborate outside of code explore all features documentation github skills blog solutions for enterprise teams startups education by solution ci cd automation devops devsecops case studies customer stories resources open source github sponsors fund open source developers the readme project github community articles repositories topics trending collections pricing search all github jump to no suggested jump to results search all github jump to search all github jump to search all github jump to sign in sign up message artwork micha huigen incorporating security in enterprise devops workflows how caregility prepared for third party security audits with github advanced security justin trugman babitha singh vp software development vp devops caregility the readme project amplifies the voices of the open source community the maintainers developers and teams whose contributions move the world forward every day the readme project menu close browse by story type featured articles developer stories guides the readme podcast explore topics see all open source culture security devops nominate a developer support the community at caregility we connect providers clinicians patients interpreters and family members wherever they are whether we re enabling virtual nursing virtual observation or virtual consultations trust is paramount for our users for companies in critical infrastructure areas like caregility third party security audits can provide customers investors and internal stakeholders peace of mind if bad actors were able to hack into our databases compromise patient information or otherwise exploit a code vulnerability the results would be catastrophic with github advanced security and tools like dependabot codeql and secret scanning we were able to more easily prepare for a third party audit and ensure the security of our code when we first started incorporating github advanced security into our github actions workflows we were quickly approaching a third party security audit as we enabled each new service on github advanced security we began to realize the depth of the work that needed to be done github s code scanning with codeql showed vulnerabilities and errors in our code secret scanning highlighted improperly stored secrets and credentials and dependabot notified us of the vulnerabilities in our dependencies it felt like opening a pandora s box with each service we enabled and we had to devise a strategy for how to remediate newly discovered vulnerabilities quickly before the audit started we accomplished this by running github advanced security features across our entire codebase for each language in use java javascript python go and ruby once all of the vulnerabilities were discovered we then included these services in a github workflow to run continuously for repositories created after the initial run to make a lasting change in our development processes that would prepare us for the future from there it was time to get to work prioritizing and remediating vulnerabilities and readying ourselves for the third party audit since each tool can expose new vulnerabilities in your codebase it can be overwhelming for anyone integrating github advanced security for the first time here are some best practices on how to organize your efforts toward tighter security both short term and long term in this guide you will learn how to prioritize vulnerability remediation how to use search queries to monitor progress and address blockers how github advanced security helps shift security left planning our approach to make a plan we first had to understand the scope of the vulnerabilities we had to remediate with over 100 services comprising the caregility platform each with its own repository this was not a menial task github advanced security s dashboard however offers a single pane of glass that showcases all detected vulnerabilities and a search field where we can enter queries to quickly find what we are looking for in addition the dashboard provides an easy way to monitor the team s progress which helps us to proactively address blockers as we encounter them once you can visualize the state of security across your organization with the dashboard you ll need to prioritize which vulnerabilities you tackle first this graphic below will help you organize an action plan to address your vulnerabilities by repository priority and vulnerability severity the approach we decided to take centered around two components what stage of development the service with the affected code was in and the severity of the vulnerabilities in the repositories for the first component we classified our services into three buckets services currently in production these are classified as the high priority repositories for us to remediate since the vulnerabilities would risk harm to our customers and platform services close to production state and planned to be released soon these are marked as lower priority than production services but are still important to remediate since unpatched vulnerabilities would expose customers when the service is released to production internal tooling automated tests and in progress prototypes these are the lowest priority since these services are internal facing and are much less likely to be exposed and exploited within each bucket we utilized the common vulnerability scoring system cvss classification given to the vulnerability working downwards from the production bucket to the prototype bucket we remediated the vulnerabilities in descending order from critical to low severity in order to monitor the team s progress we made extensive use of search queries let s break down how they work and how you can utilize them to monitor your team s remediation progress using github advanced security search queries github advanced security search queries are pretty easy to use they re essentially just a key value pair where you pass in the selection or sort type and then the associated method of search or sorting that you want to utilize the three queries we use most often are resolution repo and severity queries can be customized to show open and closed vulnerabilities using is open or is closed and the repo prefix allows us to specify the specific repository to query for example the query below shows the open vulnerabilities in our front end authentication service is open repo auth_service_frontend we are also able to find the vulnerabilities that were closed previously for reasons that would not be acceptable for the third party audit for example some vulnerabilities may have been closed because we didn t have the bandwidth to deal with them at the time or because they were seen as a tolerable risk by tailoring the query to search for no bandwidth and tolerable risk we can reopen those vulnerability alerts and address them as needed resolution no bandwidth resolution tolerable risk finally we are then able to combine a few different queries to come up with a list of vulnerabilities we need to remediate by searching for open vulnerabilities in specific repositories sorted by severity we now have a list of vulnerabilities that need remediation in order of severity is open repo repo_names sort severity these queries allow us to easily monitor how far along we are within each bucket of repositories while also showing the severity of the remaining vulnerabilities within each bucket these search queries give us the information we need for short weekly meetings where we review the results and get feedback from the team about their progress and any blockers the outcome by preparing for the third party audit using github advanced security we not only increased the security posture of caregility by remediating over a thousand vulnerabilities but our audit results came back cleaner than they would have otherwise since we were able to remediate so many vulnerabilities beforehand github advanced security helped us to protect our customers and users from security breaches preserving their trust in our products and by spending time preparing for our audit we were rewarded with a cleaner security audit report which is a crucial outcome for our customers and internal stakeholders as it shows how we have minimized the security risk to the business moving forward with security in mind github advanced security not only helped us to prepare for our third party audit it also made us realize that we needed to tightly weave security into our development process moving forward when we provisioned the tooling for the audit preparation we also configured it in our github actions pipelines to run on every pull request this allows developers to get immediate and continuous feedback on the security stance of their code it also allows us to add security directly to our code review process enable branch protection policies so secrets don t leak into production code and ensure other potential vulnerabilities are found early by shifting our security left we have significantly derisked the effect code vulnerabilities can have on caregility securing enterprise platforms ensuring the security of your codebase is an unending process but github advanced security helps to notify you of vulnerabilities as they re introduced eliminating vulnerabilities from your codebase and mitigating risk to your organization we not only decreased our risk of a security breach but we also successfully prepared for our third party audit solidifying the trust of our customers investors and internal stakeholders after our experience we recommend that companies prioritize security and adopt tooling like github advanced security into their development process by prioritizing security during the development process companies can avoid potential problems down the road handling vulnerabilities as they are introduced rather than all at once caregility is a virtual healthcare platform that provides 24 7 secure hipaa compliant access to two way audio and video communication and clinical workflow integrations that span inpatient and outpatient telemedicine settings more stories scaling mlops education noah gift pragmatic ai labs autonomy vs governance a delicate balance of power gabriel kohen blue yonder privacy engineering 8 tips to mitigate risks and secure your data ayden férdeline about the readme project coding is usually seen as a solitary activity but it s actually the world s largest community effort led by open source maintainers contributors and teams these unsung heroes put in long hours to build software fix issues field questions and manage communities the readme project is part of github s ongoing effort to amplify the voices of the developer community it s an evolving space to engage with the community and explore the stories challenges technology and culture that surround the world of open source follow us nominate a developer nominate inspiring developers and projects you think we should feature in the readme project support the community recognize developers working behind the scenes and help open source projects get the resources they need sign up for newsletter every month we ll share new articles from the readme project episodes of the readme podcast and other great developer content from around the community subscribe thank you product features security team enterprise customer stories the readme project pricing resources roadmap platform developer api partners electron github desktop support docs community forum professional services skills status contact github company about blog careers press inclusion social impact shop github on twitter github on facebook github on linkedin github on youtube github on twitch github on tiktok github s organization on github 2023 github inc terms privacy updated 08 2022 site map what is git you can t perform that action at this time you signed in with another tab or window reload to refresh your session you signed out in another tab or window reload to refresh your session
|