DEV Community

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Mapping Your Codebase to OWASP Top 10 with 247 ESLint Rules

Mapping Your Codebase to OWASP Top 10 with 247 ESLint Rules

Comments
5 min read
New Year, Same Curiosity Building Better in Tech

New Year, Same Curiosity Building Better in Tech

Comments
1 min read
The 30-Minute Security Audit: Onboarding a New Codebase

The 30-Minute Security Audit: Onboarding a New Codebase

Comments
2 min read
My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

Comments
4 min read
Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Comments
7 min read
My Perspective on SBOM: The Glue for DevSecOps

My Perspective on SBOM: The Glue for DevSecOps

Comments
2 min read
The 100:1 Deficit: Why Your Security Team Needs an AI Multiplier

The 100:1 Deficit: Why Your Security Team Needs an AI Multiplier

Comments
5 min read
The Missing Piece for AI-Assisted Infrastructure Management

The Missing Piece for AI-Assisted Infrastructure Management

Comments
7 min read
Building a Secure CI/CD Pipeline: Or How I Learned to Stop Worrying and Love DevSecOps

Building a Secure CI/CD Pipeline: Or How I Learned to Stop Worrying and Love DevSecOps

Comments
9 min read
Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026

Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026

Comments
4 min read
Cuidados com volumes no Docker

Cuidados com volumes no Docker

5
Comments
1 min read
Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security

Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security

1
Comments
10 min read
My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

Comments
4 min read
HashiCorp Vault: A Core Security Tool in DevSecOps

HashiCorp Vault: A Core Security Tool in DevSecOps

Comments
2 min read
Why 87% of Security Findings Never Get Fixed (And How We Solved It)

Why 87% of Security Findings Never Get Fixed (And How We Solved It)

Comments
3 min read
🔧Jenkins: The Heart of Continuous Integration in DevSecOps

🔧Jenkins: The Heart of Continuous Integration in DevSecOps

5
Comments 1
3 min read
DevSecOps Periodic Table-Tekton (TK)

DevSecOps Periodic Table-Tekton (TK)

Comments
1 min read
Atlassian Bamboo in the DevSecOps Periodic Table

Atlassian Bamboo in the DevSecOps Periodic Table

Comments
1 min read
How to Enforce Allowed Kubernetes Image Registries with Kyverno

How to Enforce Allowed Kubernetes Image Registries with Kyverno

Comments
4 min read
Building a DevSecOps Terraform Review Loop with Checkov, Infracost, and AI

Building a DevSecOps Terraform Review Loop with Checkov, Infracost, and AI

Comments
3 min read
Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Comments
7 min read
# Defending the Cloud-Native Frontier: Security as Code with Terraform & OPA

# Defending the Cloud-Native Frontier: Security as Code with Terraform & OPA

Comments
1 min read
🔧 Puppet: Automating Infrastructure as Code in DevSecOps

🔧 Puppet: Automating Infrastructure as Code in DevSecOps

Comments 1
3 min read
Idempotent Dockerfiles: Desirable Ideal or Misplaced Objective?

Idempotent Dockerfiles: Desirable Ideal or Misplaced Objective?

Comments
5 min read
Commit Signing - GnuPG

Commit Signing - GnuPG

Comments
3 min read
loading...