Developing Secure Scala Applications With Fortify For Scala
Developing Secure Scala Applications With Fortify For Scala
▪
▪
▪
▪
Why static analysis?
● Step 1: Translate
● Step 2: Scan
● Step 3: View results
details in demo
How it works: Translation source code
credentials += ...
resolvers += ...
addCompilerPlugin(...)
scalacOptions += ...
details in demo
How it works: Scanning
details in demo
Vulnerabilities
● sbt plugin
● coverage for more libraries and frameworks
● support Fortify on Demand
● …?
It’s demo time!
lightbend.com/fortify
Q&A