Skip to main content

Developer Guide

Objective​

Ship features with security built into day-to-day development, reducing rework and fixing issues early in the lifecycle.

Main responsibilities​

  • Follow secure coding practices in feature implementation.
  • Validate code changes with security checks before merge.
  • Fix vulnerabilities with clear prioritization and ownership.
  • Keep requirements and evidence updated during remediation.

Follow-up routine​

  1. Run security checks on feature branches.
  2. Review newly assigned vulnerabilities.
  3. Prioritize fixes by severity and exploitability.
  4. Validate remediation with retest or new scan execution.
  5. Keep issue tracker tickets synchronized with fix status.
  6. Update implementation notes for recurring findings.
  7. Escalate blockers that depend on architecture or platform teams.
  8. Share lessons learned with the squad.

Core workflows in Conviso​

Defect tracker integration​

Integrate Conviso Platform with your issue management tool using Defect/Bug Tracking integrations to synchronize and manage vulnerabilities in your team workflow.

Automation with CLI and API​

Use New CLI and API to automate security checks, standardize command execution in pipelines, and reduce manual remediation overhead.

Management and collaboration tool​

  • Time to first fix after vulnerability assignment.
  • Reopen rate after remediation.
  • Vulnerability backlog by severity in the squad.
  • Security check pass rate in pull requests.

Playbooks​

Critical vulnerability blocks release​

  1. Confirm exploitability and affected scope.
  2. Apply mitigation or fix and open pull request with context.
  3. Request fast retest and status update.
  4. Document root cause and prevention action.

Recurring vulnerability pattern in multiple repos​

  1. Identify common coding pattern causing the issue.
  2. Propose reusable fix guidance or shared component change.
  3. Apply fix in priority repositories first.
  4. Validate reduction trend in the next scan cycle.

Contribute to the Docs

Found something outdated or missing? Help us improve the documentation with a quick suggestion or edit.

How to contribute

Resources

By exploring our content, you'll find resources that will enhance your understanding of the importance of a Security Application Program.

Conviso Blog: Explore our blog, which offers a collection of articles and posts covering a wide range of AppSec topics. The content on the blog is primarily in English.

Conviso's YouTube Channel: Access a wealth of informative videos covering various topics related to AppSec. Please note that the content is primarily in Portuguese.