DEV Community

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Why Your AWS GuardDuty Data Isn't Showing Up in Microsoft Sentinel (And How to Fix It)

Why Your AWS GuardDuty Data Isn't Showing Up in Microsoft Sentinel (And How to Fix It)

Comments
4 min read
Por Qué el 87% de Sistemas MLOps Fallan el Checklist de Seguridad 2025

Por Qué el 87% de Sistemas MLOps Fallan el Checklist de Seguridad 2025

Comments
6 min read
DevSecOps Explained for Beginners (What It Really Means in Practice)

DevSecOps Explained for Beginners (What It Really Means in Practice)

1
Comments
1 min read
dgoss: Testing the Container, Not Just the Image

dgoss: Testing the Container, Not Just the Image

Comments
6 min read
My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

Comments
4 min read
Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Comments
7 min read
My Perspective on SBOM: The Glue for DevSecOps

My Perspective on SBOM: The Glue for DevSecOps

Comments
2 min read
The Missing Piece for AI-Assisted Infrastructure Management

The Missing Piece for AI-Assisted Infrastructure Management

Comments
7 min read
Building a Secure CI/CD Pipeline: Or How I Learned to Stop Worrying and Love DevSecOps

Building a Secure CI/CD Pipeline: Or How I Learned to Stop Worrying and Love DevSecOps

Comments
9 min read
Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026

Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026

Comments
4 min read
Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security

Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security

1
Comments
10 min read
𝗪𝗵𝘆 𝗔𝗜-𝗚𝗲𝗻𝗲𝗿𝗮𝘁𝗲𝗱 𝗖𝗼𝗱𝗲 𝗢𝗳𝘁𝗲𝗻 𝗟𝗼𝗼𝗸𝘀 “𝗖𝗼𝗺𝗽𝗹𝗲𝘁𝗲” — 𝗯𝘂𝘁 𝗜𝘀𝗻’𝘁—𝗮𝗻𝗱 𝘄𝗵𝘆 𝗜 𝗯𝘂𝗶𝗹𝘁 𝗔𝗜-𝗦𝗟𝗢𝗣 𝗗𝗲𝘁𝗲𝗰𝘁𝗼𝗿

𝗪𝗵𝘆 𝗔𝗜-𝗚𝗲𝗻𝗲𝗿𝗮𝘁𝗲𝗱 𝗖𝗼𝗱𝗲 𝗢𝗳𝘁𝗲𝗻 𝗟𝗼𝗼𝗸𝘀 “𝗖𝗼𝗺𝗽𝗹𝗲𝘁𝗲” — 𝗯𝘂𝘁 𝗜𝘀𝗻’𝘁—𝗮𝗻𝗱 𝘄𝗵𝘆 𝗜 𝗯𝘂𝗶𝗹𝘁 𝗔𝗜-𝗦𝗟𝗢𝗣 𝗗𝗲𝘁𝗲𝗰𝘁𝗼𝗿

Comments 3
2 min read
Why 87% of Security Findings Never Get Fixed (And How We Solved It)

Why 87% of Security Findings Never Get Fixed (And How We Solved It)

Comments
3 min read
🔧Jenkins: The Heart of Continuous Integration in DevSecOps

🔧Jenkins: The Heart of Continuous Integration in DevSecOps

5
Comments 1
3 min read
DevSecOps Periodic Table-Tekton (TK)

DevSecOps Periodic Table-Tekton (TK)

Comments
1 min read
Atlassian Bamboo in the DevSecOps Periodic Table

Atlassian Bamboo in the DevSecOps Periodic Table

Comments
1 min read
How to Enforce Allowed Kubernetes Image Registries with Kyverno

How to Enforce Allowed Kubernetes Image Registries with Kyverno

Comments
4 min read
Building a DevSecOps Terraform Review Loop with Checkov, Infracost, and AI

Building a DevSecOps Terraform Review Loop with Checkov, Infracost, and AI

Comments
3 min read
Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Comments
7 min read
# Defending the Cloud-Native Frontier: Security as Code with Terraform & OPA

# Defending the Cloud-Native Frontier: Security as Code with Terraform & OPA

Comments
1 min read
🔧 Puppet: Automating Infrastructure as Code in DevSecOps

🔧 Puppet: Automating Infrastructure as Code in DevSecOps

Comments 1
3 min read
My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

Comments 1
4 min read
The 30-Minute Security Audit: Onboarding a New Codebase

The 30-Minute Security Audit: Onboarding a New Codebase

10
Comments 6
2 min read
Idempotent Dockerfiles: Desirable Ideal or Misplaced Objective?

Idempotent Dockerfiles: Desirable Ideal or Misplaced Objective?

Comments
5 min read
Commit Signing - GnuPG

Commit Signing - GnuPG

Comments
3 min read
loading...