15
Heard a security engineer say 'shift left is dead' at a meetup last night
I was at a DC area devsecops meetup and this guy from a big bank said too many teams are pushing security into dev without actually fixing their deployment pipelines. He claimed they end up with broken builds and angry devs who just bypass the checks. Made me wonder if we are focusing on the wrong thing when we talk about shifting left?
2 comments
Log in to join the discussion
Log In2 Comments
robinson.leo1mo ago
Oh sure, let's just hand devs a shiny new security tool and pretend our CI/CD pipeline isn't held together with duct tape and prayers. What could possibly go wrong? Have they tried blaming the QA team next?
3
matthewsullivan1mo ago
Funny you mention that. I caught a talk online where someone called it "shifting the blame" instead of shifting left. Their point was that you cant just throw security tools at devs and call it a day. You gotta fix the underlying pipeline stuff first (like making sure tests actually run fast and dont block things for hours). Otherwise you end up with this huge mess where devs learn to work around the checks instead of working with them. That bank security guy might have been onto something.
1