DEV Community

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Bandit in a File Automation Script: Security Risks Hidden in Small Python Tools

Bandit in a File Automation Script: Security Risks Hidden in Small Python Tools

Comments
7 min read
Why Every CISO Needs an AIBOM in 2026 — And What Vendors Get Wrong

Why Every CISO Needs an AIBOM in 2026 — And What Vendors Get Wrong

Comments
9 min read
Why Cursor Keeps Installing Vulnerable npm Packages

Why Cursor Keeps Installing Vulnerable npm Packages

Comments
3 min read
SAST vs SCA: why your CI pipeline needs both

SAST vs SCA: why your CI pipeline needs both

Comments
4 min read
Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2

Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2

Comments
6 min read
Security triage shouldn't happen in another browser tab.

Security triage shouldn't happen in another browser tab.

Comments
4 min read
Applying Checkov SAST to Detect Security Issues in Terraform Infrastructure as Code

Applying Checkov SAST to Detect Security Issues in Terraform Infrastructure as Code

Comments
4 min read
Shifting Security Left for AI Agents: Enforcing AI-Generated Code Security with GitGuardian MCP

Shifting Security Left for AI Agents: Enforcing AI-Generated Code Security with GitGuardian MCP

Comments
6 min read
The security dashboard is where productivity goes to die

The security dashboard is where productivity goes to die

Comments
4 min read
78% False Negatives: Your AI Security Scanner Is Gaslighting You

78% False Negatives: Your AI Security Scanner Is Gaslighting You

Comments
5 min read
DevOps Security Best Practices Every Engineering Team Should Follow

DevOps Security Best Practices Every Engineering Team Should Follow

3
Comments
8 min read
Protecting Developers Means Protecting Their Secrets

Protecting Developers Means Protecting Their Secrets

Comments
10 min read
Nation-State Actors Are Now Targeting Your AI Agent's npm Packages

Nation-State Actors Are Now Targeting Your AI Agent's npm Packages

Comments
6 min read
DevSecOps Automation: A Deep Dive into SAST

DevSecOps Automation: A Deep Dive into SAST

Comments
4 min read
Why Cursor Keeps Hardcoding Secrets in AI-Generated Code (CWE-798)

Why Cursor Keeps Hardcoding Secrets in AI-Generated Code (CWE-798)

2
Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.