Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Under the Hood: Building a DevSecOps Practice at Starburst

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Alex Olea
Word Count
2,509
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

Alex Olea, a DevSecOps Engineer at Starburst, emphasizes the importance of integrating security into development workflows, particularly in startups where security teams are small and agile. His approach involves building trust with developers by maintaining transparency, contributing to development tasks, and embedding himself within development teams to ensure security does not become a peripheral function. Olea highlights the significance of developer productivity and education in implementing secure defaults and practices. He discusses the challenges faced at Starburst, such as inadequate tools for software composition analysis (SCA) that led to issues like false positives without explanation and the inability to detect transitive dependencies. To address these, Olea evaluated and implemented Endor Labs, a tool that offers precise reachability analysis and pre-deployment scanning, thereby improving the accuracy and efficiency of AppSec processes. The integration of Endor Labs into CI/CD pipelines has enhanced the speed and accuracy of responding to vulnerabilities, and the tool's capabilities in analyzing transitive dependencies have been crucial. By allowing developers access to Endor Labs, Olea aims to further empower them to prioritize and address security issues effectively, while planning future improvements like preventative controls and upgrade impact analysis to bolster the AppSec program at Starburst.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.