In this video case study, Devyani Vij, Sr. Product Security Engineer at Tide, discusses how enables her team to deploy a secure SDLC model that empowers developers to understand security issues and make long term improvements to their coding decisions.
Devyani talks about:
Embedding tools in the SDLC process so that each step of SDLC is secured
Choosing security products that are developer-first
Successfully implementing a Security Champions program, democratizing security and fostering its widespread adoption
Reducing false positives in Software Composition Analysis (SCA) by 80% using Semgrep Supply Chain’s reachability analysis
Achieving a remarkable 100% fix rate using Semgrep Code’s (SAST) custom rules
Leveraging Semgrep Assistant, an AI-powered tool, for enhanced understanding and efficient remediation of vulnerabilities.
Implementing Semgrep’s IDE extensions to proactively address security concerns at an early stage, thereby promoting shift-left approach.
About
Semgrep enables teams to use industry-leading AI-assisted static application security testing (SAST), supply chain dependency scanning (SCA), and secrets detection. The Semgrep AppSec Platform is built for teams that struggle with noise by helping development teams apply secure coding practices.