Automated DevSecOps Pipeline for Vulnerability Detection and Remediation - #2990
Conversation
|
Readme is not correctly formatted Got: ['Assignment Proposal', 'Title', 'Names and KTH ID', 'Deadline', 'Category', 'Description', 'Relevance'] |
ericcornelissen
left a comment
There was a problem hiding this comment.
The demo seems a bit minimal. While gating pull requests should definitely be part of the demo, it's a concept already covered by earlier weeks. While demonstrating automated remediation of Dependabot and CodeQL-identified problems is a great proposal, I think it's too short and simple.
I would like you to add something (relevant) to the demo. One suggestion I have is to showcase one of the limitations you already plan to talk about, for example incomplete automated remediation.
ericcornelissen
left a comment
There was a problem hiding this comment.
The proposal looks good, please fix the duplication and then I will accept and merge.
Assignment Proposal
Title
Automated DevSecOps CI Pipeline for Vulnerability Detection and Remediation.
Names and KTH ID
Deadline
Week 6
Category
Demo
Description
Our demo investigates how automated security testing and remediation can prevent vulnerable code from being merged into a shared codebase, using a small room-booking application (React frontend, Express API, a separate audit microservice, Supabase/Postgres) as the system under test. We use GitHub Actions together with CodeQL and Dependabot to detect vulnerabilities and automatically create fixes, without requiring a developer to manually triage every alert.
We will introduce a controlled vulnerability and We demonstrate automatic detection and remediation for both, showing how tests, security checks, and a security gate validate a fix before a pull request is allowed to merge.
The core workflow is:
Detect → Remediate → Validate → Security Gate → Merge/Block
Our demo investigates how automated security testing and remediation can prevent vulnerable code from being merged into a shared codebase, using a small room-booking application (React frontend, Express API, a separate audit microservice, Supabase/Postgres) as the system under test. We use GitHub Actions together with CodeQL and Dependabot to detect vulnerabilities and automatically create fixes, without requiring a developer to manually triage every alert.
We introduce two controlled vulnerabilities and demonstrate their automatic detection and remediation, showing how tests, security checks, and a security gate validate a fix before a pull request is allowed to merge.
The core workflow is:
Detect → Remediate → Validate → Security Gate → Merge/Block
Critically, the two vulnerabilities are chosen to contrast a case where automation completes the fix end-to-end against a case where it structurally cannot. We showcase this limitation live either no automated fix is offered for that alert, or a suggested fix is generated but fails CI, correctly blocking the merge until a human completes the remaining step. This directly demonstrates incomplete automated remediation as an observed limitation, alongside the related risk of fix-induced regressions and the fact that passing security checks does not guarantee complete security.
Relevance
The demo demonstrates DevSecOps by integrating security into the CI workflow. Automation provides fast feedback, reduces manual work, and ensures that vulnerable changes are blocked before reaching the main branch.