Forem

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

๐Ÿ‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
GuardDuty: Your AWS Watchdog
Cover image for GuardDuty: Your AWS Watchdog

GuardDuty: Your AWS Watchdog

Comments
5 min read
Why Your AWS GuardDuty Data Isn't Showing Up in Microsoft Sentinel (And How to Fix It)

Why Your AWS GuardDuty Data Isn't Showing Up in Microsoft Sentinel (And How to Fix It)

Comments
4 min read
Por Quรฉ el 87% de Sistemas MLOps Fallan el Checklist de Seguridad 2025
Cover image for Por Quรฉ el 87% de Sistemas MLOps Fallan el Checklist de Seguridad 2025

Por Quรฉ el 87% de Sistemas MLOps Fallan el Checklist de Seguridad 2025

Comments
6 min read
DevSecOps Explained for Beginners (What It Really Means in Practice)

DevSecOps Explained for Beginners (What It Really Means in Practice)

1
Comments
1 min read
dgoss: Testing the Container, Not Just the Image

dgoss: Testing the Container, Not Just the Image

Comments
6 min read
My Perspective on Amazon Inspector's 2025 Updates for DevSecOps
Cover image for My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

Comments
4 min read
Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS
Cover image for Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Comments
7 min read
My Perspective on SBOM: The Glue for DevSecOps
Cover image for My Perspective on SBOM: The Glue for DevSecOps

My Perspective on SBOM: The Glue for DevSecOps

Comments
2 min read
The Missing Piece for AI-Assisted Infrastructure Management
Cover image for The Missing Piece for AI-Assisted Infrastructure Management

The Missing Piece for AI-Assisted Infrastructure Management

Comments
7 min read
Building a Secure CI/CD Pipeline: Or How I Learned to Stop Worrying and Love DevSecOps

Building a Secure CI/CD Pipeline: Or How I Learned to Stop Worrying and Love DevSecOps

Comments
9 min read
Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026
Cover image for Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026

Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026

Comments
4 min read
Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security
Cover image for Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security

Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security

1
Comments
10 min read
Why 87% of Security Findings Never Get Fixed (And How We Solved It)

Why 87% of Security Findings Never Get Fixed (And How We Solved It)

Comments
3 min read
๐Ÿ”งJenkins: The Heart of Continuous Integration in DevSecOps
Cover image for ๐Ÿ”งJenkins: The Heart of Continuous Integration in DevSecOps

๐Ÿ”งJenkins: The Heart of Continuous Integration in DevSecOps

5
Comments 1
3 min read
DevSecOps Periodic Table-Tekton (TK)

DevSecOps Periodic Table-Tekton (TK)

Comments
1 min read
Atlassian Bamboo in the DevSecOps Periodic Table

Atlassian Bamboo in the DevSecOps Periodic Table

Comments
1 min read
How to Enforce Allowed Kubernetes Image Registries with Kyverno

How to Enforce Allowed Kubernetes Image Registries with Kyverno

Comments
4 min read
Building a DevSecOps Terraform Review Loop with Checkov, Infracost, and AI

Building a DevSecOps Terraform Review Loop with Checkov, Infracost, and AI

Comments
3 min read
Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS
Cover image for Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Implementing Container Signing in Your CI/CD Pipeline: A DevSecOps Approach with AWS

Comments
7 min read
# Defending the Cloud-Native Frontier: Security as Code with Terraform & OPA

# Defending the Cloud-Native Frontier: Security as Code with Terraform & OPA

Comments
1 min read
๐Ÿ”ง Puppet: Automating Infrastructure as Code in DevSecOps
Cover image for ๐Ÿ”ง Puppet: Automating Infrastructure as Code in DevSecOps

๐Ÿ”ง Puppet: Automating Infrastructure as Code in DevSecOps

Comments 1
3 min read
My Perspective on Amazon Inspector's 2025 Updates for DevSecOps
Cover image for My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

My Perspective on Amazon Inspector's 2025 Updates for DevSecOps

Comments 1
4 min read
๐—ช๐—ต๐˜† ๐—”๐—œ-๐—š๐—ฒ๐—ป๐—ฒ๐—ฟ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ข๐—ณ๐˜๐—ฒ๐—ป ๐—Ÿ๐—ผ๐—ผ๐—ธ๐˜€ โ€œ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ฒ๐˜๐—ฒโ€ โ€” ๐—ฏ๐˜‚๐˜ ๐—œ๐˜€๐—ปโ€™๐˜โ€”๐—ฎ๐—ป๐—ฑ ๐˜„๐—ต๐˜† ๐—œ ๐—ฏ๐˜‚๐—ถ๐—น๐˜ ๐—”๐—œ-๐—ฆ๐—Ÿ๐—ข๐—ฃ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ
Cover image for ๐—ช๐—ต๐˜† ๐—”๐—œ-๐—š๐—ฒ๐—ป๐—ฒ๐—ฟ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ข๐—ณ๐˜๐—ฒ๐—ป ๐—Ÿ๐—ผ๐—ผ๐—ธ๐˜€ โ€œ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ฒ๐˜๐—ฒโ€ โ€” ๐—ฏ๐˜‚๐˜ ๐—œ๐˜€๐—ปโ€™๐˜โ€”๐—ฎ๐—ป๐—ฑ ๐˜„๐—ต๐˜† ๐—œ ๐—ฏ๐˜‚๐—ถ๐—น๐˜ ๐—”๐—œ-๐—ฆ๐—Ÿ๐—ข๐—ฃ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ

๐—ช๐—ต๐˜† ๐—”๐—œ-๐—š๐—ฒ๐—ป๐—ฒ๐—ฟ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ข๐—ณ๐˜๐—ฒ๐—ป ๐—Ÿ๐—ผ๐—ผ๐—ธ๐˜€ โ€œ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ฒ๐˜๐—ฒโ€ โ€” ๐—ฏ๐˜‚๐˜ ๐—œ๐˜€๐—ปโ€™๐˜โ€”๐—ฎ๐—ป๐—ฑ ๐˜„๐—ต๐˜† ๐—œ ๐—ฏ๐˜‚๐—ถ๐—น๐˜ ๐—”๐—œ-๐—ฆ๐—Ÿ๐—ข๐—ฃ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ

Comments 3
2 min read
The 30-Minute Security Audit: Onboarding a New Codebase
Cover image for The 30-Minute Security Audit: Onboarding a New Codebase

The 30-Minute Security Audit: Onboarding a New Codebase

11
Comments 6
2 min read
Idempotent Dockerfiles: Desirable Ideal or Misplaced Objective?

Idempotent Dockerfiles: Desirable Ideal or Misplaced Objective?

Comments
5 min read
loading...