📞 +91-7667918914 | ✉️ ijarcce@gmail.com
IJARCCE Logo
International Journal of Advanced Research in Computer and Communication Engineering A monthly Peer-reviewed & Refereed journal
ISSN Online 2278-1021ISSN Print 2319-5940Since 2012
IJARCCE adheres to the suggestive parameters outlined by the University Grants Commission (UGC) for peer-reviewed journals, upholding high standards of research quality, ethical publishing, and academic excellence.
← Back to VOLUME 14, ISSUE 4, APRIL 2025

Integrating Automated Security tools into the SDLC framework to improve Software Security.

Pravinkumar Jha , Anil Vasoya

DOI: 10.17148/IJARCCE.2025.14402

Abstract: Integration of security automation tools within the Software Development Life Cycle (SDLC) is important to enhance the security posture and establish a Secure Software Development Lifecycle. We have reviewed existing research papers, articles and identified gaps in them and tried to reduce and mitigate those gaps with our proposed solution Tools like SonarQube and Dependency check can be integrated with CI/CD pipeline and help in identifying security vulnerabilities early in software development lifecycle. GitHub is source code management and version control tool, which also helps in automation of the code merge and review process. Results of this scan will be uploaded in Defect Dojo, which is an open-source tool by OWASP. Defect Dojo will serve as a central vulnerability management solution. Proposed solution in this paper will help in achieving increased detection of vulnerabilities, reduction in manual effort and a better collaboration between engineering teams and security teams. The goal of this research is to offer a solid framework for incorporating security automation into the SDLC, utilising the advantages of different tools to improve security procedures by facilitating early detection and lower risks.

Keywords: DevSecOps, Security Automation, SAST, Secure SDLC, Security Integration, SonarQube, Continuous Security Assessment

How to Cite:

[1] Pravinkumar Jha , Anil Vasoya, “Integrating Automated Security tools into the SDLC framework to improve Software Security.,” International Journal of Advanced Research in Computer and Communication Engineering (IJARCCE), DOI: 10.17148/IJARCCE.2025.14402