In today's rapidly evolving DevOps and DevSecOps processes, security testing is often sidelined or pushed to the final stage, which increases risks and delays releases. But what if you could automatically detect security risks with every code change and fix them proactively, before problems arise?
In this practical workshop, you will transcend the boundaries of traditional testing and master the DevSecOps philosophy. To achieve this, we will utilize N8N's visual platform and build automated workflows that make security testing an integral part of the CI/CD pipeline. Additionally, we'll have theoretical discussions about what DevSecOps does and how the role of test automation engineers is evolving within this system.
You will learn how to:
* Integrate automated security scanning into every GitHub Pull Request.
* Identify vulnerabilities in code (such as SQL Injection or XSS) and automatically notify the team about them.
* Leverage artificial intelligence to analyze scanning results and reduce false positives.
Throughout the workshop, we will build and run real workflows, allowing you to see firsthand how security automation works in DevOps processes. We'll also discuss security standards such as ISO 27001 and SOC 2, and their significance in the modern technical world.
- Presenter: David Mumladze - Senior DevOps/SRE Engineer
- Start Time and duration: 15:00-17:00
- Prerequisites: Active GitHub account, laptops.
- Audience: This workshop is ideal for testers who work in or plan to work in DevOps environments and want to deepen their knowledge in security testing automation. It's perfect for those who want to master globally recognized security standards. Prior knowledge of N8N or cybersecurity is not required.
- Language: Georgian