{"id":8195,"date":"2020-03-26T20:42:39","date_gmt":"2020-03-26T20:42:39","guid":{"rendered":"https:\/\/staging-site.42crunch.com\/?p=8195"},"modified":"2022-11-24T10:15:39","modified_gmt":"2022-11-24T10:15:39","slug":"webinar-questions-azure-pipelines","status":"publish","type":"post","link":"https:\/\/staging2022.42crunch.com\/webinar-questions-azure-pipelines\/","title":{"rendered":"Questions Answered: REST API Security by Design with Azure Pipelines"},"content":{"rendered":"
Thank you for all the questions submitted on our “REST API Security by Design with Azure Pipelines<\/strong>” webinar. Below are all the answers to the questions that were asked. If you’d like more information please feel free to contact us<\/a>.<\/p>\n REST API Security for\u00a0Microsoft Azure Pipelines.\u00a0Watch Webinar<\/a><\/p>\n REST API Security for Microsoft\u00a0Azure Pipelines Slide Deck\u00a0Download<\/a><\/p>\n Neither the VS Code plugin nor the Azure DevOps extension have limits on the number of security audits run. However, there is a rate limit of 3 calls per minute from the same IP.\u00a0<\/span><\/p>\n There is a difference in behavior of these two extensions though. The VS Code extension is a personal developer tool, so the report is only shown to the individual developer using it and not stored anywhere.<\/span><\/p>\n The Azure DevOps extension is publishing the reports to the central 42Crunch platform so your whole team can get access to them. Thus, the licensing limits of the 42Crunch subscription starts playing a role here. 42Crunch has a free tier up to 3 APIs and monthly subscription options beyond that.<\/span>\u00a0The number of updates to these APIs or the number of times you call the platform for security testing is not limited.<\/span><\/p>\n <\/p>\n Yes, OpenAPI standard has a broad industry support. You can find most tools supporting it at <\/span>https:\/\/openapi.tools\/<\/span><\/a> as well as <\/span>https:\/\/github.com\/swagger-api\/swagger-core<\/span><\/a><\/p>\n <\/p>\n Azure DevOps is connecting to the 42Crunch platform via API and pushing OpenAPI files to be tested to it. The Azure DevOps extension then collects the security testing results, displays them in the pipeline, and makes the success or failure decision based on the criteria that you set.<\/span><\/p>\n <\/p>\n 42Crunch API Security platform can work with APIs developed and hosted in any cloud. It is not dependent on Azure in any way. In this particular webinar, we have been demonstrating our extension for Azure DevOps CI\/CD pipeline.\u00a0<\/span><\/p>\n We have a few internal plugins for other CI\/CD platforms so if you are using something else please fill out the Contact Us form on our website to request access.<\/span><\/p>\n <\/p>\n 42Crunch is indeed a multi-tenant cloud service. Please see our Terms & Conditions for details: <\/span>https:\/\/platform.42crunch.com\/terms-and-conditions<\/span><\/a><\/p>\n <\/p>\n Non VS Code plugins are in the works. Please fill out the Contact Us form on our website so we can notify you when we are ready to start our private beta for them.<\/span><\/p>\n <\/p>\n On-prem version of 42Crunch platform is available for large enterprise customers. If you are interested, please fill out the Contact Us form on our website.<\/span><\/p>\n <\/p>\n Stoplight.io does not have a model of 3rd-party extensions. We are hoping to find a way to work with Stoplight to plug our tests into their platform.<\/span><\/p>\n <\/p>\n <\/p>\n <\/a><\/p>\n <\/p>\n Try our security audit<\/a> for free. If you want to see the whole platform in action, request a demo now<\/a>!<\/p>\n","protected":false},"excerpt":{"rendered":" You had questions, and we’ve got answers! Thank you for all the questions submitted on our “REST API Security by Design with Azure Pipelines” webinar. Below are all the answers to the questions that were asked. If you’d like more information please feel free to contact us. REST API Security for\u00a0Microsoft Azure Pipelines.\u00a0Watch Webinar REST […]<\/p>\n","protected":false},"author":13,"featured_media":11308,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"none","_seopress_titles_title":"REST API Security by Design with Azure Pipelines, Webinar Q&A","_seopress_titles_desc":"Questions and answers from our webinar, "REST API Security by Design with Microsoft Azure Pipelines" .","_seopress_robots_index":"","site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"disabled","ast-hfb-above-header-display":"disabled","ast-hfb-below-header-display":"disabled","ast-hfb-mobile-header-display":"disabled","site-post-title":"disabled","ast-breadcrumbs-content":"disabled","ast-featured-img":"disabled","footer-sml-layout":"disabled","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[6],"tags":[22,16,25],"class_list":["post-8195","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-api-security-platform","tag-api-security-training","tag-api-testing"],"_links":{"self":[{"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/posts\/8195"}],"collection":[{"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/comments?post=8195"}],"version-history":[{"count":0,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/posts\/8195\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/media\/11308"}],"wp:attachment":[{"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/media?parent=8195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/categories?post=8195"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/tags?post=8195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}I know this API Security Audit requires a Token to call it from VS Code, is there any limitation on the # of calls or licensing associated?<\/b><\/h5>\n
Is there any software that can generate an API file for a code written in any programming language?<\/b><\/h5>\n
How is the 42Crunch Platform connected to Azure DevOps?<\/b><\/h5>\n
Will there be support for other Cloud vendors in the roadmap?<\/b><\/h5>\n
It’s a cloud service. How about privacy? How will my data be handled?<\/b><\/h5>\n
This is a real cool plugin. Is there one available for java developers (like IntelliJ, Eclipse)?<\/b><\/h5>\n
Do you have plans to make an on-prem version of your platform, or at least the audit service?<\/b><\/h5>\n
What about integration with Stoplight.io? Stoplight is a powerful design first platform. 42Crunch integration will be a great add.<\/b><\/h5>\n
42Crunch REST API Static Security Testing Extension for Azure Pipelines<\/h3>\n