05 — Modern Infrastructure & Operations
DevSecOps
Security, vulnerability scanning, and compliance built directly into the development lifecycle.
Security runs inside the build. Vulnerability scanning and the compliance steps that belong in the lifecycle sit in the pipeline beside the tests. Each release leaves a record of what was checked, who approved it, and what still needs a fix.
Start a projectWho it is for
Teams shipping software that holds customer, plant, or company data.
What this covers
- 01
Security in the lifecycle
Access, secrets, and review are part of how the software is built and released.
- 02
Vulnerability scanning
Dependencies and images are scanned in the pipeline, before a release goes out.
- 03
Compliance in the workflow
The checks a client or a regulator expects are attached to the change, with a record.
Technologies
GitHub Actions
Docker
Sentry