Tracks / Secure the Pipeline

Secure the Pipeline

Every gate, shift-left, against the same three broken artifacts. Secrets to DAST, then the whole thing wired together.

0 of 31 complete

Secrets

Stop a credential before it is ever committed, and find the ones already in history.

  1. 01Block a Secret Before It Is Ever Committed (Gitleaks Pre-Commit)read
  2. 02Dig Secrets Out of Git History (TruffleHog)read
  3. 03Secrets Scanning Across a Whole Organisationread

SAST

Find the bug in your own code, in the pull request, before anyone runs it.

  1. 04Find Security Bugs in Your Code in Seconds (Semgrep)read
  2. 05Wire SonarQube into Your PR Checksread
  3. 06Snyk Code versus the Free Toolsread
  4. 07CodeQL — GitHub-Native SASTread
  5. 08What Enterprise SAST Does Differentlyread

SCA

Your dependencies are most of your attack surface and none of your code.

  1. 09Catch Vulnerable Dependencies for Free (OWASP Dependency-Check)read
  2. 10One Scanner for Dependencies, Secrets and Config (Trivy fs)read
  3. 11Grype and Syft — SBOM-Driven Scanningread
  4. 12Snyk versus Dependabot versus Trivyread
  5. 13Automate Dependency Fixes with Pull Requestsread
  6. 14Enterprise SCA and licence complianceoutline

IaC

The Terraform that builds the broken AWS account is the artifact under test here.

  1. 15Catch AWS Misconfigurations Before Apply (Checkov)read
  2. 16Migrate Off tfsec to trivy configread
  3. 17The Two Native Checks Every Terraform Pipeline Needsread
  4. 18Snyk IaC on the Same Terraformread
  5. 19tfsec Is Dead — Here Is the Migrationread

Container

Root users, unpinned tags, and a secret baked three layers down.

  1. 20Lint Your Dockerfile Before You Build (Hadolint)read
  2. 21Is Your Image CIS-Compliant? A Sixty-Second Check (Dockle)read
  3. 22Scan a Container Image for CVEs, Live (Trivy)read
  4. 23Grype versus Trivy on the Same Imageread
  5. 24Docker's Built-in Image Scanner (Scout)read

DAST

Everything above reads your code. This chapter attacks it while it runs.

  1. 25Attack Your Own Running App with ZAPread
  2. 26Burp Suite Basics for Pipeline Testingread
  3. 27Nuclei — Templated DAST in CIread

Capstone

Every gate, one repo, one pull request.

  1. 28The Best SAST, SCA, IaC and Container Scanner in 2026read
  2. 29I Built a Full DevSecOps Pipeline — Every Gate, One Reporead
  3. 30A Reusable IaC Security Workflowread
  4. 31A Reusable Container Security Workflowread