DEV Community

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026

Is 'Shift Left' Just Another Buzzword? Rethinking Enterprise Security in 2026

Comments
4 min read
Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security

Building an Intentionally Vulnerable AWS Lab to Teach Cloud Security

1
Comments
10 min read
HashiCorp Vault: A Core Security Tool in DevSecOps

HashiCorp Vault: A Core Security Tool in DevSecOps

Comments
2 min read
Why 87% of Security Findings Never Get Fixed (And How We Solved It)

Why 87% of Security Findings Never Get Fixed (And How We Solved It)

Comments
3 min read
🔧Jenkins: The Heart of Continuous Integration in DevSecOps

🔧Jenkins: The Heart of Continuous Integration in DevSecOps

5
Comments 1
3 min read
DevSecOps Periodic Table-Tekton (TK)

DevSecOps Periodic Table-Tekton (TK)

Comments
1 min read
Atlassian Bamboo in the DevSecOps Periodic Table

Atlassian Bamboo in the DevSecOps Periodic Table

Comments
1 min read
How to Enforce Allowed Kubernetes Image Registries with Kyverno

How to Enforce Allowed Kubernetes Image Registries with Kyverno

Comments
4 min read
Building a DevSecOps Terraform Review Loop with Checkov, Infracost, and AI

Building a DevSecOps Terraform Review Loop with Checkov, Infracost, and AI

Comments
3 min read
# Defending the Cloud-Native Frontier: Security as Code with Terraform & OPA

# Defending the Cloud-Native Frontier: Security as Code with Terraform & OPA

Comments
1 min read
🔧 Puppet: Automating Infrastructure as Code in DevSecOps

🔧 Puppet: Automating Infrastructure as Code in DevSecOps

Comments 1
3 min read
Idempotent Dockerfiles: Desirable Ideal or Misplaced Objective?

Idempotent Dockerfiles: Desirable Ideal or Misplaced Objective?

Comments
5 min read
Commit Signing - GnuPG

Commit Signing - GnuPG

Comments
3 min read
Building a DevSecOps Pipeline on AWS: From Security Audit to Daily Deployments

Building a DevSecOps Pipeline on AWS: From Security Audit to Daily Deployments

Comments
15 min read
What is IDP and why we need it?

What is IDP and why we need it?

Comments
1 min read
Opsfolio - From Interview Task to Production: Building a Security-First DevSecOps Platform

Opsfolio - From Interview Task to Production: Building a Security-First DevSecOps Platform

Comments
5 min read
Ephemeral Vulnerability Scanner: Pure Client-Side JS for Windows/Linux/macOS Vuln Analysis

Ephemeral Vulnerability Scanner: Pure Client-Side JS for Windows/Linux/macOS Vuln Analysis

Comments
1 min read
Stop Using localhost:8080 - Why Your Dev Environment Needs Production-Grade Network Security

Stop Using localhost:8080 - Why Your Dev Environment Needs Production-Grade Network Security

24
Comments
15 min read
Automating Compliance Checks in CI/CD Pipelines with Rego

Automating Compliance Checks in CI/CD Pipelines with Rego

Comments
2 min read
How to Prevent Backup-related Throttling Without Losing Data (or Mind)

How to Prevent Backup-related Throttling Without Losing Data (or Mind)

Comments
6 min read
Why Your UEBA Isn’t Working (and how to fix it)

Why Your UEBA Isn’t Working (and how to fix it)

1
Comments
7 min read
Prevention-First Cloud Security: Escaping Alert Fatigue for Good using Turbot

Prevention-First Cloud Security: Escaping Alert Fatigue for Good using Turbot

5
Comments
2 min read
🚀 8 Software Trends Every Senior Developer Should Watch in 2026

🚀 8 Software Trends Every Senior Developer Should Watch in 2026

3
Comments
2 min read
Use AI to Speed Up Security Hardening (and Read This First)

Use AI to Speed Up Security Hardening (and Read This First)

Comments
1 min read
Pin It or Bin It

Pin It or Bin It

Comments
3 min read
loading...