Skip to content

Instantly share code, notes, and snippets.

@slamb2k
Created September 17, 2020 16:25
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save slamb2k/68e445ad4b93e745dd42e2f43d8e3d1a to your computer and use it in GitHub Desktop.
Save slamb2k/68e445ad4b93e745dd42e2f43d8e3d1a to your computer and use it in GitHub Desktop.
Links

DevSecOps Links

What is DevSecOps? Best Practices & How it Works

Secure DevOps @ Microsoft


DevSecOps on Azure

DevSecOps in Azure - Azure Solution Ideas | Microsoft Docs

DevSecOps in GitHub - Azure Solution Ideas | Microsoft Docs

Enable DevSecOps with Azure and GitHub - DevSecOps | Microsoft Docs

Secure DevOps Kit for Azure (AzSK) | AzSK website


Github Resources

The enterprise architect’s guide to DevSecOps

The complete guide to developer-first application security

Achieving DevSecOps maturity with a developer first, community driven approach

How leading software teams build securely on GitHub

Three AppSec pitfalls every security leader can avoid


Github Resources (Government)

DevSecOps for government agencies, the GitHub way

The government agency’s guide to DevSecOps

The complete guide to developer-first application security for government agencies


Videos

Implement DevSecOps in Azure - Victoria Almazova

DevSecOps for Azure | Build 2020

DevSecOps: Policy-as-code with Azure Pipelines | by Vishal Jain | Microsoft Azure | Medium


Pipelines

Add Continuous Security Validation to your CICD Pipeline - Azure DevOps | Microsoft Docs

Manage your open source usage and security as reported by your CI/CD pipeline | Microsoft Docs

DevSecOps and Continuous Assurance Tips and Tricks Rugged DevOps


Tools

devsecops/awesome-devsecops: An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

9 Great DevSecOps Tools to Integrate Throughout the DevOps Pipeline

microsoft/binskim: A binary static analysis tool that provides security and correctness results for Windows Portable Executable and *nix ELF binary formats

Microsoft Threat Modeling Tool overview - Azure | Microsoft Docs

Code analysis using sonarcloud in Azure DevOps - Azure DevOps Pro

Microsoft/CredScan: A static analysis tool to scan for credential leaks

Microsoft/Roslyn Analyzers: A static analysis tool to scan C# for security vulnerabilities

Microsoft Security Code Analysis documentation overview | Microsoft Docs

OWASP ZAP Scanner: Integrating to Azure DevOps Release Pipeline | by Anish Srivastava | Medium


Testing

Vulnerability Scanning vs Penetration Testing: How Do The Differ?


Permissions

Setting default repository permissions on your Azure DevOps Organization

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment