DEV Community

#devsecops

Integrating security practices into the DevOps lifecycle.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Artifactory Token Chain: Why Build Repositories Are a Credential Store

The Artifactory Token Chain: Why Build Repositories Are a Credential Store

Comments
4 min read
AI Agent Threat Response: Why Pre-Runtime Controls Matter More Than Runtime Detection

AI Agent Threat Response: Why Pre-Runtime Controls Matter More Than Runtime Detection

Comments
10 min read
Security Telemetry on a Budget: Building a Practical Elastic Baseline for a Growing Product Team

Security Telemetry on a Budget: Building a Practical Elastic Baseline for a Growing Product Team

Comments
8 min read
Architecting a Resilient DevSecOps Pipeline for Enterprise AI Agents

Treating prompt files as actual code

Architecting a Resilient DevSecOps Pipeline for Enterprise AI Agents

19
Picked as gem Comments 6
7 min read
Building a DevSecOps Pipeline on Alibaba Cloud

Building a DevSecOps Pipeline on Alibaba Cloud

Comments
4 min read
Why Secrets Slip Through Every Layer of Your Security Stack

Why Secrets Slip Through Every Layer of Your Security Stack

Comments
5 min read
`gh attestation verify` said yes to an image we never released

`gh attestation verify` said yes to an image we never released

Comments
15 min read
AI Security Patches Fail 74% of the Time: 6,080 Tested

AI Security Patches Fail 74% of the Time: 6,080 Tested

Comments
7 min read
CyberShield AI — Catch Vulnerabilities Before They Ship

CyberShield AI — Catch Vulnerabilities Before They Ship

Comments
1 min read
De Full Stack pra DevSecOps: documentando a virada em pĂşblico

De Full Stack pra DevSecOps: documentando a virada em pĂşblico

Comments
1 min read
Vault Coverage Is the Missing Metric in NHI Programs

Vault Coverage Is the Missing Metric in NHI Programs

Comments 1
8 min read
What Happens When You pip install a Malicious Python Package?

What Happens When You pip install a Malicious Python Package?

Comments
5 min read
Harden & Lockdown RKE2 Cluster with a 4-Layer DevSecOps Stack

Harden & Lockdown RKE2 Cluster with a 4-Layer DevSecOps Stack

Comments 1
20 min read
Building a "Fail-Closed" Zero-Trust CI/CD Protocol: A Personal Open-Source Experiment

Building a "Fail-Closed" Zero-Trust CI/CD Protocol: A Personal Open-Source Experiment

Comments
2 min read
GitSpawn: Claude Code Runs Untrusted Repo Code Before You Type

GitSpawn: Claude Code Runs Untrusted Repo Code Before You Type

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.