DevSecOps is a curated roadmap and resource collection for integrating security throughout the software development lifecycle. It explains the relationship between development, security, and operations before organizing resources around practical lifecycle stages. Sections cover design, development, build, testing, deployment, operation, and monitoring. The repository links to guidance on threat modeling, secure coding, SAST, DAST, penetration testing, hardening, runtime protection, and security analysis. A separate tool catalog helps users discover software for implementing these practices. Dedicated CI/CD security material covers systems such as GitHub Actions and Jenkins. The project is community-driven and can be used either sequentially as a learning roadmap or selectively as a reference for specific DevSecOps challenges.
Features
- Structured DevSecOps learning roadmap
- Secure development lifecycle resources
- Threat modeling and secure coding guidance
- SAST, DAST, and penetration-testing references
- CI/CD pipeline security material
- Curated DevSecOps tool directory