Software Company-X releases cloud services. The Android development team in company-X is using IDE developer tools to do secure code review for released Android applications. However, the uses of the IDE developer tools may have less visibility of the whole project security status. The development manager is also looking for a secure coding inspection service that can establish consistent secure coding quality across projects. Therefore, a secure coding scanning service will be in a need.
Case study – automating a secure code review
Secure coding scanning service – SWAMP
The following diagram shows an ideal secure coding inspection service. It provides users or developers with interfaces to submit the source...