Inglese
Carlo Bottaro
Inglese.
Rel. Fulvio Giovanni Ottavio Risso, Francesco Pizzato. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2025
|
Preview |
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (5MB) | Preview |
Abstract
This thesis presents a practical framework for automating vulnerability assessment and remediation in cloud-native environments, with a strong focus on developer-centric workflows and integration within CI/CD pipelines. It investigates the challenges posed by fragmented vulnerability data, inconsistent tooling, and the lack of actionable remediation strategies in modern software supply chains. At the core of this research is Vulnbot, a modular and CI-integrated automation agent that orchestrates vulnerability detection, prioritization, and remediation. Vulnbot supports multiple ecosystems, interfaces with scanners like OSV-Scanner and Trivy, and automates dependency patching and pull request generation, streamlining remediation and reducing mean-time-to-remediation (MTTR). First, it establishes a foundation in vulnerability databases and their relevance in cloud-native security.
Second, it explores how security can be embedded into CI/CD processes using SBOMs, IaC validation, and policy-as-code
Tipo di pubblicazione
URI
![]() |
Modifica (riservato agli operatori) |
