SkillAgentSearch skills...

DevSecOps

♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎

Install / Use

/learn @hahwul/DevSecOps
About this skill

Quality Score

0/100

Category

Operations

Supported Platforms

Universal

README

<div align="center"> <picture> <source media="(prefers-color-scheme: dark)" srcset="assets/devsecops-dark.png" width="500px;"> <source media="(prefers-color-scheme: light)" srcset="assets/devsecops-light.png" width="500px;"> <img alt="DevSecOps Logo" src="assets/devsecops-dark.png" width="500px;"> </picture> <p>Roadmap for everyone who wants DevSecOps.</p> </div> <p align="center"> <a href="https://github.com/hahwul/DevSecOps/blob/main/CONTRIBUTING.md"> <img src="https://img.shields.io/badge/CONTRIBUTIONS-WELCOME-000000?style=for-the-badge&labelColor=black"></a> <a href="./README.md"> <img src="https://img.shields.io/badge/English-000000?style=for-the-badge&labelColor=black"></a> <a href="./README.ko.md"> <img src="https://img.shields.io/badge/ν•œκ΅­μ–΄-000000?style=for-the-badge&labelColor=black"></a> <a href="./README.jp.md"> <img src="https://img.shields.io/badge/ζ—₯本θͺž-000000?style=for-the-badge&labelColor=black"></a> </p>

What is DevSecOps and Why is it Important?

DevSecOps is a culture and practice that aims to integrate security into every phase of the software development lifecycle (SDLC). It emphasizes collaboration between Development, Security, and Operations teams. The goal is to build secure software from the ground up, reduce vulnerabilities, and ensure faster, safer deployments. This roadmap provides a curated list of resources and tools to help individuals and organizations implement DevSecOps practices.

πŸ“œ Table of Contents

πŸ“– How to Use This Roadmap

This roadmap is designed to be a comprehensive guide for individuals and organizations looking to adopt or improve their DevSecOps practices. Here's how you can make the most of it:

  1. Understand the Basics: If you're new to DevSecOps, start with the "What is DevSecOps and Why is it Important?" section to get a foundational understanding.
  2. View the Big Picture: The main Roadmap image provides a visual overview of the different stages and areas within DevSecOps. Use this to orient yourself.
  3. Explore Tools: The Tools section offers a curated list of software and services that can help you implement various DevSecOps capabilities.
  4. Dive into Resources: The Resources section is categorized by the DevSecOps lifecycle (Design, Develop, Build, Test, Deploy, Operate and Monitor). Each category contains links to articles, guides, and official documentation. You can explore these based on your specific needs or areas of interest.
  5. Focus on CI/CD Security: If your focus is on securing your pipelines, the Security of CICD section provides targeted resources.
  6. Contribute: This is a community-driven effort. If you have suggestions, find broken links, or want to add new resources, please see our CONTRIBUTING.md guide.

You don't have to go through it linearly. Feel free to jump to the sections that are most relevant to your current challenges or learning goals.

πŸ’­ Roadmap

Roadmap

πŸ”© Tools

This project includes a curated list of tools to help you implement DevSecOps practices. These tools cover various stages of the SDLC, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), secret management, threat modeling, component analysis, and more.

➑️ Explore the DevSecOps Tools List

This list is designed to help you quickly find and compare tools, reducing the time spent on searching and decision-making.

πŸ“¦ Resources

0. DevSecOps Overview

1. Design

2. Develop

3. Build

4. Test

5. Deploy

6. Operate and Monitor

Security of CICD

  • Github Actions
    1. [Security hardening for GitHu

Related Skills

View on GitHub
GitHub Stars2.1k
CategoryOperations
Updated1d ago
Forks422

Languages

Just

Security Score

100/100

Audited on Mar 25, 2026

No findings