In this video case study, Ritu Maheshwari, Associate Director of Security at Fareportal, discusses the massive efficiencies that Semgrep unlocked for developers, and the enthusiastic use of Semgrep by engineers (beyond what was required by the security team).
Ritu talks about:
Seamlessly integrating Semgrep into their Azure environment, where Fareportal's repos, pipelines, and developers live.
Developers leveraging and customizing Semgrep rules on their own to proactively find and fix issues (before ever being flagged by security).
The criticality of bi-directional feedback in fostering a collaborative relationship between security and engineering
How Semgrep and Azure helped break down silos between developers, security engineers, and leadership.
About
Semgrep enables teams to use industry-leading AI-assisted static application security testing (SAST), supply chain dependency scanning (SCA), and secrets detection. The Semgrep AppSec Platform is built for teams that struggle with noise by helping development teams apply secure coding practices.