Security architect and open source contributor James Sörling talks about open source tools that make high velocity development more secure.
Sörling, currently security architect for Wireless Car, is an open source contributor for cfn-nag, which performs infrastructure as code (IaC) static analysis of AWS CloudFormation. He also wrote an open source module that integrated CFN-nag into SonarQube. Now, developers, DevOps, and SREs can get their CloudFormation scanned during development, to help them fix issues early. It also helps with audit and compliance to associate owners to IaC early in development.