Security/Developers

From MozillaWiki
Jump to navigation Jump to search

This page contains details about the Security Assurance teams efforts to deploy tools into the software development lifecycle, and to make security tools available to developers.

2012 - Q3 Efforts

Proxy Integration

  • Work with QA team to get web testing run through ZAP (allows fuzzing, and analysis of testing to determine new ways to improve security testing)
  • Status: Completed. POC complete with one QA test proxying via ZAP.

Meta Scanner

  • Implement a tool (Minion) to facilitate usage of security tools by developers
  • Status: Completed. POC Task Engine and Plugin Service with basic ZAP plugin implemented.

Security evangelism