Tracks / Secure the Pipeline
Secure the Pipeline
Every gate, shift-left, against the same three broken artifacts. Secrets to DAST, then the whole thing wired together.
0%
0 of 31 complete
Secrets
Stop a credential before it is ever committed, and find the ones already in history.
SAST
Find the bug in your own code, in the pull request, before anyone runs it.
SCA
Your dependencies are most of your attack surface and none of your code.
- 09Catch Vulnerable Dependencies for Free (OWASP Dependency-Check)read
- 10One Scanner for Dependencies, Secrets and Config (Trivy fs)read
- 11Grype and Syft — SBOM-Driven Scanningread
- 12Snyk versus Dependabot versus Trivyread
- 13Automate Dependency Fixes with Pull Requestsread
- 14Enterprise SCA and licence complianceoutline
IaC
The Terraform that builds the broken AWS account is the artifact under test here.
Container
Root users, unpinned tags, and a secret baked three layers down.
DAST
Everything above reads your code. This chapter attacks it while it runs.
Capstone
Every gate, one repo, one pull request.