Skip to content
EgyKode

DevSecOps

Security throughout delivery: put the gates in the pipeline, not in a document nobody reads.

What this path covers

8 phases19 chapterscovered

4 topics planned

These belong in this path but have no chapter yet. A phase is only created once there is material behind it — so the count above is what the platform actually teaches, not a target.

  • Threat modelling and the secure SDLC as an opening chapter
  • Dependency scanning (SCA), secret scanning and SBOM generation
  • Image signing and provenance (Sigstore / cosign)
  • Security logging, audit trails and incident response as detection rather than general observability
Write one of these

Your progress

0 of 19 · 0%

  1. Ends with

    A pipeline that can say no

    Trivy blocks the push on a fixable CRITICAL, SonarQube gates the merge, and Checkov, Gitleaks and hadolint run before either. In the cluster: the restricted Pod Security Standard, default-deny NetworkPolicies, RBAC per service and secrets that never reach the image.

Progress is stored in this browser only. Sign-in sync is coming with accounts.