Aller au contenu principal
Accès ouvert déclaré 2025 conference-paper

Securing Applied Information Systems With SAST Integration Into the Gulp Pipeline

0Citations signalées, ce qui n’est pas une note de qualité
3Institutions déclarées
1Pays d’affiliation déclarés

Rattachement africain : ua. Niveau de preuve : code pays fourni par la source.

Le résumé fourni par la source

The growth of cyber threats in modern web development and the need to implement DevSecOps practices demand innovative approaches to code protection. Traditional security testing methods, applied in late stages, face significant limitations, including the inability to respond quickly to vulnerabilities and non- compliance with the "shift-left" principle. This article presents a practical approach to integrating static application security testing (SAST) tools directly into the automated build process for front-end projects using the Gulp task runner. By leveraging the ESLint linter, configured to detect dangerous constructs (such as no-eval and no-implied-eval), the proposed system provides continuous code monitoring and automatic vulnerability detection. The Gulp pipeline, implemented via the gulp-eslint-new plugin, is modified to immediately interrupt the build process (failAfterError) upon error detection. These capabilities contribute to strengthening cybersecurity capacities, serve as an effective first line of defense, and prevent obvious vulnerabilities corresponding to the OWASP Top Ten from entering the repository. Furthermore, the approach demonstrates simple implementation without the need for complex external tools. Through the integration of SAST into the Gulp pipeline, the proposed framework is well-equipped to address modern security challenges, enhancing the overall code reliability in the Node.js environment.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Le contrôle bibliographique ouvert

DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.

Titre Crossref
Securing Applied Information Systems With SAST Integration Into the Gulp Pipeline
Date Crossref
16/12/2025
Éditeur
CEUR-WS.org
Type
proceedings-article

Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.

Où se fait cette recherche

  • Academician Yuriy Bugay International Scientific and Technical University pays non établi dans la notice
    Université ou école supérieure
  • Institute of Electrodynamics pays non établi dans la notice
    Structure de recherche
  • National University of Life and Environmental Sciences of Ukraine pays non établi dans la notice
    Université ou école supérieure

Academician Yuriy Bugay International Scientific and Technical University, Institute of Electrodynamics et National University of Life and Environmental Sciences of Ukraine.

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

Les sujets associés

Web Application Security VulnerabilitiesInformation and Cyber SecuritySAS software applications and methods

BNTIC News n’est pas le producteur de ces données. Les publications sont interrogées à la demande dans Crossref, OpenAIRE, DOAJ, Europe PMC, HAL, DataCite, AfricArXiv, ROR et la Banque mondiale, sans clé d’accès. OpenAlex reste optionnel. Aucun service payant n’est nécessaire et aucune donnée externe n’est enregistrée en base. Consulter les sources et leurs limites.