3 ms·
Let me break your points down (using python 2.7/3.0 as the example): a. Code quality - tackled at code review time, and probably not dependent on python 2.7/3.
by heretoo 7y ago
Let me break your points down (using python 2.7/3.0 as the example):
a. Code quality - tackled at code review time, and probably not dependent on python 2.7/3.0 differences; if they are version dependent then again it's a code review process.
b. Code security - again, code review
Additional:
c. Third party dependency vulnerabilities: detection should be automated; github now supports automatic checks that open pull requests for vulnerable artifacts.
d. user acceptance tests - seems unlikely that two versions of python are used for the same part of the system.
Docker (especially docker-compose) makes it more visible as to what will be deployed. In fact, it may actually be better for security when those security checks of a system can be made before it goes to production, because the whole stack can be built, audited and executed locally.
- geggam 7y agoSo you dont use automation like sonarcube / qualys and other tools ? Our corp requires this at a minimum to even be deployed to development. Let alone staging / prod