äŸåé¢ä¿ã®ã»ãã¥ãªãã£ãšè匱æ§ã¹ãã£ã³ã«ã€ããŠåŠã³ããªãŒãã³ãœãŒã¹ã®ãªã¹ã¯ããã¢ããªã±ãŒã·ã§ã³ãä¿è·ããŸããããäžçäžã®éçºè åãã®å æ¬çãªã¬ã€ãã§ãã
äŸåé¢ä¿ã®ã»ãã¥ãªãã£ïŒè匱æ§ã¹ãã£ã³ã«é¢ããã°ããŒãã«ã¬ã€ã
仿¥ã®çžäºæ¥ç¶ãããäžçã§ã¯ããœãããŠã§ã¢éçºã¯ãªãŒãã³ãœãŒã¹ã®ã³ã³ããŒãã³ãã«å€§ããäŸåããŠããŸãããããã®ã³ã³ããŒãã³ãã¯ãå€ãã®å ŽåãäŸåé¢ä¿ãšåŒã°ããéçºãµã€ã¯ã«ãå éããããã«å©çšã§ããæ©èœãæäŸããŸãããã ãããã®äŸåã¯é倧ãªã»ãã¥ãªãã£äžã®èª²é¡ããããããŸããäŸåé¢ä¿ã®è匱æ§ã§ãããããã®è匱æ§ã«å¯ŸåŠããªããšãããŒã¿äŸµå®³ããã·ã¹ãã å šäœã®äŸµå®³ãŸã§ãã¢ããªã±ãŒã·ã§ã³ãæ·±å»ãªãªã¹ã¯ã«ãããããå¯èœæ§ããããŸãã
äŸåé¢ä¿ã®ã»ãã¥ãªãã£ãšã¯ïŒ
äŸåé¢ä¿ã®ã»ãã¥ãªãã£ãšã¯ããœãããŠã§ã¢éçºã§äœ¿çšããããµãŒãããŒãã£ã®ã©ã€ãã©ãªããã¬ãŒã ã¯ãŒã¯ãããã³ãã®ä»ã®ã³ã³ããŒãã³ãã«é¢é£ããã»ãã¥ãªãã£ãªã¹ã¯ãç¹å®ãè©äŸ¡ãããã³è»œæžãããã©ã¯ãã£ã¹ã§ããããã¯ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã®éèŠãªåŽé¢ã§ããããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³å šäœã®æŽåæ§ãšã»ãã¥ãªãã£ãä¿èšŒããŸãã
å®¶ã建ãŠããããªãã®ã ãšèããŠãã ããããã¬ããã®çªããã¢ã屿 ¹æïŒäŸåé¢ä¿ïŒã䜿çšãããããããŸããããããã¯æéãšåŽåãç¯çŽããŸãããäŸµå ¥è ãæ°è±¡è¢«å®³ãé²ãããã«ããããã匷åºã§å®å šã§ããããšã確èªããå¿ èŠããããŸããäŸåé¢ä¿ã®ã»ãã¥ãªãã£ã¯ããœãããŠã§ã¢ã«ãåãååãé©çšããŸãã
è匱æ§ã¹ãã£ã³ã®éèŠæ§
è匱æ§ã¹ãã£ã³ã¯ãäŸåé¢ä¿ã®ã»ãã¥ãªãã£ã®äžæ žãšãªãã³ã³ããŒãã³ãã§ããããã«ã¯ããœãããŠã§ã¢ãããžã§ã¯ãå ã§äœ¿çšãããäŸåé¢ä¿ã®æ¢ç¥ã®è匱æ§ãèªåçã«èå¥ããããšãå«ãŸããŸãããããã®è匱æ§ã¯ãå€ãã®å ŽåãNational Vulnerability DatabaseïŒNVDïŒãªã©ã®å ¬éããŒã¿ããŒã¹ã«ã«ã¿ãã°åãããCommon Vulnerabilities and ExposuresïŒCVEïŒèå¥åã䜿çšããŠè¿œè·¡ãããŸãã
è匱æ§ã«ã€ããŠäŸåé¢ä¿ãããã¢ã¯ãã£ãã«ã¹ãã£ã³ããããšã«ãããçµç¹ã¯æ¬¡ã®ããšãå¯èœã«ãªããŸãã
- ãªã¹ã¯ã®è»œæžïŒæ»æè ã«ãã£ãŠæªçšãããåã«ãè匱æ§ãç¹å®ããŠå¯ŸåŠããŸãã
- ã»ãã¥ãªãã£äœå¶ã®æ¹åïŒãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã«é¢é£ããã»ãã¥ãªãã£ãªã¹ã¯ãå¯èŠåããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ã®ç¢ºä¿ïŒãœãããŠã§ã¢ã»ãã¥ãªãã£ã«é¢é£ããèŠå¶èŠä»¶ãæºãããŸããå€ãã®æ¥çã§ã¯ãå¥çŽã®æ¡ä»¶ãšããŠSoftware Bill of MaterialsïŒSBOMïŒãèŠæ±ãããããã«ãªã£ãŠããŸãã
- ä¿®åŸ©äœæ¥ã®åªå é äœä»ãïŒæãéèŠãªè匱æ§ãžã®å¯ŸåŠãæåã«éç¹çã«è¡ããŸãã
- ã»ãã¥ãªãã£ããã»ã¹ã®èªååïŒç¶ç¶çãªã»ãã¥ãªãã£ç£èŠã®ããã«ãè匱æ§ã¹ãã£ã³ããœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«ïŒSDLCïŒã«çµ±åããŸãã
è匱æ§ã¹ãã£ã³ã®ä»çµã¿
è匱æ§ã¹ãã£ã³ããŒã«ã¯ãæ¢ç¥ã®è匱æ§ããŒã¿ããŒã¹ãšç §åããŠããããžã§ã¯ãã®äŸåé¢ä¿ãåæããŸãããã®ããã»ã¹ã«ã¯éåžžãæ¬¡ã®æé ãå«ãŸããŸãã- äŸåé¢ä¿ã®èå¥ïŒããŒã«ã¯ããããžã§ã¯ãã®ãããã§ã¹ããã¡ã€ã«ïŒNode.jsã®å Žåã¯
package.json
ãJavaã®å Žåã¯pom.xml
ãPythonã®å Žåã¯requirements.txt
ãªã©ïŒãåæããŠããã¹ãŠã®çŽæ¥ããã³æšç§»çãªäŸåé¢ä¿ãèå¥ããŸããæšç§»çãªäŸåé¢ä¿ã¯ãäŸåé¢ä¿ã®äŸåé¢ä¿ã§ãã - è匱æ§ããŒã¿ããŒã¹ã®ã«ãã¯ã¢ããïŒããŒã«ã¯ãNVDãªã©ã®è匱æ§ããŒã¿ããŒã¹ã«ã¯ãšãªãå®è¡ããŠãèå¥ãããäŸåé¢ä¿ã«é¢é£ããæ¢ç¥ã®è匱æ§ãèå¥ããŸãã
- è匱æ§ã®ç §åïŒããŒã«ã¯ãèå¥ãããäŸåé¢ä¿ãšãã®ããŒãžã§ã³ãè匱æ§ããŒã¿ããŒã¹ãšç §åããŠãæœåšçãªè匱æ§ãèå¥ããŸãã
- ã¬ããŒãïŒããŒã«ã¯ãèå¥ãããè匱æ§ããã®é倧床ã¬ãã«ãããã³ä¿®åŸ©ã®æšå¥šäºé ãäžèŠ§è¡šç€ºããã¬ããŒããçæããŸãã
ã·ããªãªäŸ
Node.jsã䜿çšããŠéçºãããWebã¢ããªã±ãŒã·ã§ã³ãæ³åããŠã¿ãŠãã ããããã®ã¢ããªã±ãŒã·ã§ã³ã¯ã人æ°ã®ãããã®ã³ã°ã©ã€ãã©ãªãå«ããããã€ãã®ãªãŒãã³ãœãŒã¹ããã±ãŒãžã«äŸåããŠããŸããè匱æ§ã¹ãã£ã³ããŒã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã®package.json
ãã¡ã€ã«ãåæãããã®ã³ã°ã©ã€ãã©ãªã«ãæ»æè
ãä»»æã®ã³ãŒããå®è¡ã§ããæ¢ç¥ã®ã»ãã¥ãªãã£è匱æ§ïŒCVE-2023-1234ãªã©ïŒãããããšãç¹å®ããŸããããŒã«ã¯ãè匱æ§ã匷調ãããã®ã³ã°ã©ã€ãã©ãªãããããé©çšãããããŒãžã§ã³ã«æŽæ°ããããšãæšå¥šããã¬ããŒããçæããŸãã
è匱æ§ã¹ãã£ã³ããŒã«ã®çš®é¡
ããŸããŸãªè匱æ§ã¹ãã£ã³ããŒã«ãå©çšå¯èœã§ãããããããã«é·æãšçæããããŸãããããã®ããŒã«ã¯ã倧ãŸãã«æ¬¡ã®ããã«åé¡ã§ããŸãã
- ãœãããŠã§ã¢æ§æåæïŒSCAïŒããŒã«ïŒãããã®ããŒã«ã¯ããªãŒãã³ãœãŒã¹ã®äŸåé¢ä¿ãåæããè匱æ§ãç¹å®ããããã«ç¹å¥ã«èšèšãããŠããŸãããœãããŠã§ã¢ã®æ§æãšãé¢é£ããã»ãã¥ãªãã£ãªã¹ã¯ã«é¢ããå æ¬çãªæŽå¯ãæäŸããŸãã
- éçã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ãïŒSASTïŒããŒã«ïŒSASTããŒã«ã¯ãäŸåé¢ä¿ã®äœ¿çšã«é¢é£ãããã®ãå«ããæœåšçãªè匱æ§ã«ã€ããŠãœãŒã¹ã³ãŒããåæããŸãã
- åçã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ãïŒDASTïŒããŒã«ïŒDASTããŒã«ã¯ãå®éã®æ»æãã·ãã¥ã¬ãŒãããããšã«ãããå®è¡äžã®ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ããã¹ãããŸãã
- ã€ã³ã¿ã©ã¯ãã£ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ãïŒIASTïŒããŒã«ïŒIASTããŒã«ã¯ãSASTããã³DASTææ³ãçµã¿åãããŠãã¢ããªã±ãŒã·ã§ã³ãã¹ãäžã«ãªã¢ã«ã¿ã€ã ã®èåŒ±æ§æ€åºãæäŸããŸãã
é©åãªè匱æ§ã¹ãã£ã³ããŒã«ã®éžæ
é©åãªè匱æ§ã¹ãã£ã³ããŒã«ãéžæããããšã¯ãããã€ãã®èŠå ã«ãã£ãŠç°ãªããŸãã
- ããã°ã©ãã³ã°èšèªãšãã¬ãŒã ã¯ãŒã¯ïŒããŒã«ããããžã§ã¯ãã§äœ¿çšãããŠããããã°ã©ãã³ã°èšèªãšãã¬ãŒã ã¯ãŒã¯ããµããŒãããŠããããšã確èªããŸãã
- äŸåé¢ä¿ç®¡çãšã³ã·ã¹ãã ïŒããŒã«ãäŸåé¢ä¿ç®¡çãšã³ã·ã¹ãã ïŒnpmãMavenãpipãªã©ïŒãšçµ±åãããŠããããšã確èªããŸãã
- 粟床ãšã«ãã¬ããžïŒè匱æ§ãç¹å®ããéã®ããŒã«ã®ç²ŸåºŠãšãè匱æ§ããŒã¿ããŒã¹ã®ã«ãã¬ããžãè©äŸ¡ããŸãã
- SDLCãšã®çµ±åïŒæ¢åã®ãœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«ã«ç°¡åã«çµ±åã§ããããŒã«ãéžæããŸããçæ³çã«ã¯ãããã¯CI/CDãã€ãã©ã€ã³ã®äžéšãšããŠèªååãããŸãã
- ã¬ããŒããšä¿®åŸ©ïŒä¿®åŸ©ã®æšå¥šäºé ãå«ããæç¢ºã§å®çšçãªã¬ããŒããæäŸããããŒã«ãæ¢ããŸãã
- ã³ã¹ãïŒããŒã«ã®ã³ã¹ããšãäºç®ã«åã£ãŠãããã©ãããæ€èšããŸããåçšãªãã·ã§ã³ãšãªãŒãã³ãœãŒã¹ãªãã·ã§ã³ã®äž¡æ¹ãååšããŸãã
- ãµããŒãïŒããŒã«ãã³ããŒãåªããããã¥ã¡ã³ããšãµããŒããæäŸããŠãããã©ããã確èªããŸãã
è匱æ§ã¹ãã£ã³ããŒã«ã®äŸ
次ã«ãäžè¬çãªè匱æ§ã¹ãã£ã³ããŒã«ãããã€ã瀺ããŸãã
- SnykïŒããŸããŸãªéçºç°å¢ãšçµ±åããã詳现ãªè匱æ§ã¬ããŒããšä¿®åŸ©ã¬ã€ãã³ã¹ãæäŸããå æ¬çãªSCAããŒã«ã
- JFrog XrayïŒJFrog Artifactoryãšçµ±åããããœãããŠã§ã¢ã®äŸåé¢ä¿ã«å¯Ÿããå æ¬çãªå¯èŠæ§ãæäŸãããŠãããŒãµã«ãœãããŠã§ã¢æ§æåæãœãªã¥ãŒã·ã§ã³ã
- Sonatype Nexus LifecycleïŒSDLCå šäœã§ãªãŒãã³ãœãŒã¹ã®ãªã¹ã¯ã管çããã³è»œæžããã®ã«åœ¹ç«ã€SCAããŒã«ã
- OWASP Dependency-CheckïŒãããžã§ã¯ãã®äŸåé¢ä¿ã§æ¢ç¥ã®è匱æ§ãèå¥ããç¡æã®ãªãŒãã³ãœãŒã¹SCAããŒã«ãç¹ã«Javaãããžã§ã¯ãã§äººæ°ããããŸãã
- Anchore GrypeïŒã³ã³ããã€ã¡ãŒãžããã³ãã¡ã€ã«ã·ã¹ãã ã®ãªãŒãã³ãœãŒã¹è匱æ§ã¹ãã£ããŒã
- TrivyïŒAqua Securityã®å¥ã®ãªãŒãã³ãœãŒã¹ã¹ãã£ããŒã§ãInfrastructure as CodeïŒIaCïŒæ§æãã¹ãã£ã³ã§ããŸãã
SDLCãžã®è匱æ§ã¹ãã£ã³ã®çµ±å
è匱æ§ã¹ãã£ã³ã®æå¹æ§ãæå€§åããã«ã¯ããœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«ã®ãã¹ãŠã®æ®µéã«çµ±åããå¿ èŠããããŸãããã®ã¢ãããŒãã¯ãå€ãã®å ŽåãShift Leftãã»ãã¥ãªãã£ãšåŒã°ããçµç¹ã¯éçºããã»ã¹ã®æ©ã段éã§è匱æ§ãç¹å®ããŠå¯ŸåŠã§ããããã修埩ã«å¿ èŠãªã³ã¹ããšåŽåãåæžãããŸãã
è匱æ§ã¹ãã£ã³ãSDLCã®ããŸããŸãªæ®µéã«çµ±åããæ¹æ³ã次ã«ç€ºããŸãã
- éçºïŒéçºè ã¯ãè匱æ§ã¹ãã£ã³ããŒã«ã䜿çšããŠãã³ãŒããã³ãããããåã«äŸåé¢ä¿ã確èªã§ããŸããå€ãã®ããŒã«ãIDEçµ±åãæäŸããŠããŸãã
- ãã«ãïŒãã«ãããã»ã¹ã«è匱æ§ã¹ãã£ã³ãçµ±åããŠãã³ãŒãã®ã³ã³ãã€ã«äžã«è匱æ§ãèªåçã«èå¥ããŸããç¹å®ã®ãããå€ãè¶ ããè匱æ§ãèŠã€ãã£ãå Žåã¯ããã«ãã倱æãããå¿ èŠããããŸãã
- ãã¹ãïŒäŸåé¢ä¿ãè匱æ§ã«ã€ããŠåŸ¹åºçã«ãã¹ããããããã«ããã¹ããã€ãã©ã€ã³ã«è匱æ§ã¹ãã£ã³ãçµã¿èŸŒã¿ãŸãã
- ãããã€ã¡ã³ãïŒè匱ãªã³ã³ããŒãã³ããæ¬çªç°å¢ã«ãããã€ãããªãããã«ããããã€ã¡ã³ãããã»ã¹ã®äžéšãšããŠäŸåé¢ä¿ãã¹ãã£ã³ããŸãã
- ç£èŠïŒãããã€ãããã¢ããªã±ãŒã·ã§ã³ããäŸåé¢ä¿ã®æ°ããè匱æ§ã«ã€ããŠç¶ç¶çã«ç£èŠããŸããè匱æ§ã¯åžžã«çºèŠãããŠããããã以åã¯å®å šã ã£ãäŸåé¢ä¿ãè匱ã«ãªãå¯èœæ§ããããŸãã
çµ±åã®ãã¹ããã©ã¯ãã£ã¹
- ããã»ã¹ã®èªååïŒCI/CDãã€ãã©ã€ã³ãšã¹ã¯ãªããã䜿çšããŠãã¹ãã£ã³ãèªååããç¹å®ã®CVSSã¹ã³ã¢ãŸãã¯é倧床ãè¶ ããè匱æ§ã§å€±æããŸãã
- SBOMã®äœ¿çšïŒãœãããŠã§ã¢éšå衚ãçæããŠäœ¿çšãã䜿çšäžã®ãã¹ãŠã®ã³ã³ããŒãã³ãã远跡ããŸãã
- ããªã·ãŒã®èšå®ïŒèš±å®¹ããããªã¹ã¯ã¬ãã«ãšä¿®åŸ©ã¿ã€ã ã©ã€ã³ãæå®ããæç¢ºãªè匱æ§ç®¡çããªã·ãŒãå®çŸ©ããŸãã
- éçºè ã®æè²ïŒå®å šãªã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ãšäŸåé¢ä¿ã®ã»ãã¥ãªãã£ã®éèŠæ§ã«ã€ããŠéçºè ããã¬ãŒãã³ã°ããŸãã
- è匱æ§ã®åªå é äœä»ãïŒæãéèŠãªè匱æ§ãžã®å¯ŸåŠãæåã«éç¹çã«è¡ããŸããCVSSã¹ã³ã¢ãšã³ã³ããã¹ãæ å ±ã䜿çšããŠãä¿®åŸ©äœæ¥ã®åªå é äœãä»ããŸãã
- èªå修埩ïŒå¯èœãªå Žåã¯ãææ°ã®ããããé©çšãããããŒãžã§ã³ã«æŽæ°ããŠãè匱æ§ãèªåçã«ä¿®åŸ©ããããã«ã¹ãã£ããŒãæ§æããŸãã
Common Vulnerabilities and ExposuresïŒCVEïŒã®çè§£
Common Vulnerabilities and ExposuresïŒCVEïŒã·ã¹ãã ã¯ãå ¬éãããŠããæ¢ç¥ã®ã»ãã¥ãªãã£è匱æ§ã«å¯ŸããæšæºåãããåœåèŠåãæäŸããŸããåè匱æ§ã«ã¯äžæã®CVEèå¥åïŒCVE-2023-1234ãªã©ïŒãå²ãåœãŠãããŠãããããŸããŸãªããŒã«ãããŒã¿ããŒã¹éã§è匱æ§ã®äžè²«ããåç §ãšè¿œè·¡ãå¯èœã§ãã
CVEã¯ãMITRE Corporationã«ãã£ãŠå ¬éããã³ç¶æãããäžçäžã®çµç¹ãã»ãã¥ãªãã£è匱æ§ãç¹å®ããŠå¯ŸåŠããããã«äœ¿çšããŠããŸãã
CVEãçè§£ããããšã¯ã广çãªè匱æ§ç®¡çã«ãšã£ãŠéåžžã«éèŠã§ããè匱æ§ã¹ãã£ã³ããŒã«ãè匱æ§ãèå¥ãããšãéåžžã察å¿ããCVEèå¥åãæäŸãããè匱æ§ã調æ»ããŠæœåšçãªåœ±é¿ãçè§£ã§ããŸãã
ãœãããŠã§ã¢éšå衚ïŒSBOMïŒ
ãœãããŠã§ã¢éšå衚ïŒSBOMïŒã¯ãäŸåé¢ä¿ãã©ã€ãã©ãªããã¬ãŒã ã¯ãŒã¯ãªã©ããœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ãæ§æãããã¹ãŠã®ã³ã³ããŒãã³ãã®å æ¬çãªãªã¹ãã§ããSBOMã¯ããœãããŠã§ã¢ã®æ é€ã©ãã«ã®ãããªãã®ã§ãã¢ããªã±ãŒã·ã§ã³ã®æ§æãšãé¢é£ããã»ãã¥ãªãã£ãªã¹ã¯ã«å¯Ÿããéææ§ãæäŸããŸãã
SBOMã¯ãäŸåé¢ä¿ã®ã»ãã¥ãªãã£ã«ãšã£ãŠãŸããŸãéèŠã«ãªã£ãŠããŸããSBOMã䜿çšãããšãçµç¹ã¯æ°ããè匱æ§ããœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã«äžãã圱é¿ãè¿ éã«ç¹å®ããŠè©äŸ¡ã§ããŸããæ°ããCVEãçºè¡šãããå ŽåãSBOMãåç §ããŠã圱é¿ãåããã¢ããªã±ãŒã·ã§ã³ãè¿ éã«ç¹å®ã§ããŸããCycloneDXãSPDXãªã©ãSBOMã®çæã«åœ¹ç«ã€ããŒã«ãããã€ããããŸãã
ç±³åœæ¿åºã¯ãé£éŠæ©é¢ã«è²©å£²ããããœãããŠã§ã¢ã«å¯ŸããŠSBOMã®äœ¿çšã矩åä»ããŠãããããŸããŸãªæ¥çã§SBOMã®æ¡çšãå éããŠããŸãã
äŸåé¢ä¿ã®ã»ãã¥ãªãã£ã®å°æ¥
äŸåé¢ä¿ã®ã»ãã¥ãªãã£ã¯é²åããåéã§ãããåžžã«æ°ãã課é¡ãšæ©äŒãçŸããŠããŸããäŸåé¢ä¿ã®ã»ãã¥ãªãã£ã®å°æ¥ã圢äœãäž»èŠãªãã¬ã³ãã«ã¯ã次ã®ãããªãã®ããããŸãã
- èªååã®åŒ·åïŒèªååãããè匱æ§ã¹ãã£ã³ãšä¿®åŸ©ãããã«æ®åããçµç¹ã¯äŸåé¢ä¿ã®ãªã¹ã¯ãå€§èŠæš¡ã«ããã¢ã¯ãã£ãã«ç®¡çã§ããããã«ãªããŸãã
- ã€ã³ããªãžã§ã³ã¹ã®åŒ·åïŒè匱æ§ã¹ãã£ã³ããŒã«ã¯ãæ©æ¢°åŠç¿ãšäººå·¥ç¥èœã掻çšããŠãç²ŸåºŠãšæå¹æ§ãåäžãããŸãã
- SBOMã®æ¡çšïŒSBOMã¯ããœãããŠã§ã¢éçºã®æšæºçãªãã©ã¯ãã£ã¹ã«ãªãããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã«å¯Ÿããéææ§ãåäžããŸãã
- ãµãã©ã€ãã§ãŒã³ã®ã»ãã¥ãªãã£ïŒçŠç¹ã¯ããªãŒãã³ãœãŒã¹ã®ã¡ã³ãããšãµãŒãããŒãã£ãã³ããŒã®ã»ãã¥ãªãã£ãã©ã¯ãã£ã¹ãå«ãããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³å šäœãå«ãããã«æ¡å€§ããŸãã
- DevSecOpsã®çµ±åïŒã»ãã¥ãªãã£ã¯ããœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«ã®ãã¹ãŠã®æ®µéã«çµ±åãããéçºãã»ãã¥ãªãã£ãããã³éçšããŒã éã®ã»ãã¥ãªãã£ã«å¯Ÿããå ±åã¢ãããŒããä¿é²ããŸãã
çµè«
äŸåé¢ä¿ã®ã»ãã¥ãªãã£ãšè匱æ§ã¹ãã£ã³ã¯ãå æ¬çãªã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ããã°ã©ã ã®äžå¯æ¬ ãªã³ã³ããŒãã³ãã§ãããªãŒãã³ãœãŒã¹ã®äŸåé¢ä¿ã®è匱æ§ãããã¢ã¯ãã£ãã«ç¹å®ããŠå¯ŸåŠããããšã«ãããçµç¹ã¯ãªã¹ã¯ãšã¯ã¹ããŒãžã£ãŒãå€§å¹ ã«åæžãããœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãšæŽåæ§ã確ä¿ã§ããŸãããœãããŠã§ã¢ã®ç¶æ³ãé²åãç¶ããã«ã€ããŠããªãŒãã³ãœãŒã¹ã³ã³ããŒãã³ãã«é¢é£ãããªã¹ã¯ã广çã«ç®¡çããã³è»œæžããããã«ãäŸåé¢ä¿ã®ã»ãã¥ãªãã£ã®ææ°ã®ãã¬ã³ããšãã¹ããã©ã¯ãã£ã¹ã«ã€ããŠåžžã«æ å ±ãå ¥æããããšãéèŠã§ãã
ãã®å æ¬çãªã¬ã€ãã¯ã广çãªäŸåé¢ä¿ã®ã»ãã¥ãªãã£ãã©ã¯ãã£ã¹ãçè§£ããå®è£ ããããã®åºçºç¹ãæäŸããŸãããããã®æŠç¥ãæ¡çšããŠãçžäºæ¥ç¶ãããããžã¿ã«äžçã§é²åããè åšãããœãããŠã§ã¢ã匷åããŠãã ããã