IP Library Patent Application 16549350
Patent Application
App. No. 16/549,350

SYSTEMS, METHOD, AND MEDIA FOR DETERMINING SECURITY COMPLIANCE OF CONTINUOUS BUILD SOFTWARE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/549,350
Abstract

Mechanisms for determining security compliance of continuous build software are provided. In some embodiments, the mechanisms comprise: receiving a trigger at a hardware processor from a continuous build tool indicating that code has been created or updated; receiving a code template corresponding to the code at the hardware processor; checking the code template against a plurality of policies to determine if there is a security violation; and indicating that the code template has passed a compliance check prior to a code stack for the template being built by the continuous build tool.

Claims (34)

1 . A system for determining security compliance of continuous build software, comprising:

a memory; and

a hardware processor coupled to the memory and configured to:

receive a trigger from a continuous build tool indicating that code has been created or updated;

receive a code template corresponding to the code;

check the code template against a plurality of policies to determine if there is a security violation; and

indicate that the code template has passed a compliance check prior to a code stack for the template being built by the continuous build tool.

2 . The system of claim 1 , wherein the trigger is based on a trigger sent to the continuous build tool by a serverless application.

3 . The system of claim 1 , wherein the hardware processor is also configured to receive metadata with the trigger.

4 . The system of claim 3 , wherein the metadata indicates that code was checked-in to a code repository.

5 . The system of claim 3 , where the metadata indicates that code was uploaded to a storage service.

6 . The system of claim 3 , wherein the metadata indicates that the code was created or updated.

7 . The system of claim 1 , wherein the hardware processor is also configured to scan the code stack for security violations after the code stack is built.

8 . A method for determining security compliance of continuous build software, comprising:

receiving a trigger at a hardware processor from a continuous build tool indicating that code has been created or updated;

receiving a code template corresponding to the code at the hardware processor;

checking the code template against a plurality of policies to determine if there is a security violation; and

indicating that the code template has passed a compliance check prior to a code stack for the template being built by the continuous build tool.

9 . The method of claim 8 , wherein the trigger is based on a trigger sent to the continuous build tool by a serverless application.

10 . The method of claim 8 , further comprising receiving metadata with the trigger.

11 . The method of claim 10 , wherein the metadata indicates that code was checked-in to a code repository.

12 . The method of claim 10 , where the metadata indicates that code was uploaded to a storage service.

13 . The method of claim 10 , wherein the metadata indicates that the code was created or updated.

14 . The method of claim 8 , further comprising scanning the code stack for security violations after the code stack is built.

15 . A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method for determining security compliance of continuous build software, the method comprising:

receiving a trigger at a hardware processor from a continuous build tool indicating that code has been created or updated;

receiving a code template corresponding to the code at the hardware processor;

checking the code template against a plurality of policies to determine if there is a security violation; and

indicating that the code template has passed a compliance check prior to a code stack for the template being built by the continuous build tool.

16 . The non-transitory computer-readable medium of claim 15 , wherein the trigger is based on a trigger sent to the continuous build tool by a serverless application.

17 . The non-transitory computer-readable medium of claim 15 , where the method further comprises receiving metadata with the trigger.

18 . The non-transitory computer-readable medium of claim 17 , wherein the metadata indicates that code was checked-in to a code repository.

19 . The non-transitory computer-readable medium of claim 17 , where the metadata indicates that code was uploaded to a storage service.

20 . The non-transitory computer-readable medium of claim 15 , wherein the method further comprises scanning the code stack for security violations after the code stack is built.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2021
From: SKYHIGH NETWORKS, LLC
To: MCAFEE, LLC
Reel/Frame 057010/0244 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2019
From: SARUKKAI, SEKHAR; SOMASAMUDRAM, PRASAD
To: SKYHIGH NETWORKS, LLC
Reel/Frame 051105/0116 →