DevSecOps — the whole path
27 steps · 25 written
Build
Run
Prove
6 steps
Prevent known-bad from ever shipping.
11 steps
Detect the unknown in the live account, then respond automatically.
10 steps
Your pipeline output is the audit evidence. Show it.
Build
6 steps
Prevent known-bad from ever shipping.
Run
11 steps
Detect the unknown in the live account, then respond automatically.
Prove
10 steps
Your pipeline output is the audit evidence. Show it.
Every command copy-pasteable. Every lesson re-run before it ships.
Latest
All posts →The Best SAST, SCA, IaC and Container Scanner in 2026
Seventeen scanners against the same deliberately broken application. The headline result: no free tool found both the SQL injection and the XSS — and exactly one paid tool found both. Every number here comes from a run you can reproduce.
AWS SecurityBurp Suite Basics for Pipeline Testing
Burp Suite Community cannot run in a pipeline — the automation needs a project file, and project files are Professional only. That is not a limitation to work around. It is the boundary between the scanner you gate on and the tool you reach for when the scanner finds something. Verified against Burp Suite Community 2026.7.3.
AWS SecurityCatch AWS Misconfigurations Before Apply (Checkov)
26 failed checks against the Range's Terraform, in under a second, before a single resource exists. Here is how to read them, which to gate on, and the one class of finding Checkov structurally cannot see. Verified against Checkov 3.2.533.
Intentionally vulnerable — education only
The Range
Three shared broken artifacts every lesson scans: a vulnerable app, a vulnerable image, and the Terraform that builds the broken AWS account. Run it locally or in a throwaway account with billing alarms — never deployed publicly.
How the Range worksDifferent job? Read this instead
Responsible for CPS 234 at an APRA-regulated entity?
The control mapping, the evidence an auditor actually accepts, and where most AWS estates fail CPG 234 — without the four-year-stale tooling.
15+ years platform engineering · enterprise data security at MNC scale · AWS Security Specialty, AWS Solutions Architect & CKA certified
- AWS Certified Security – Specialty
- AWS Certified Solutions Architect – Associate
- CNCF Certified Kubernetes Administrator
The free Big Data tools — YARN calculator, HDFS planner, Spark sizer, queue designer — are still here. Use them →
Get the DevSecOps Pipeline Cheatsheet
One page: every gate, the tool that owns it, and what fails the build vs what just reports — plus a heads-up when a tool dies (like tfsec). Free, straight to your inbox.
No spam. Unsubscribe anytime. See our privacy policy.
Prefer to grab it now?Read the cheatsheet → Download PDF