The OWASP DevSecOps Guideline explains how to build and operate a secure software delivery pipeline using best practices and a curated, vendor-neutral set of tools. The aim is to help organizations of any size that run a DevOps pipeline introduce security controls without slowing delivery, and to promote a shift-left (and increasingly shift-everywhere) security culture across the whole development lifecycle.
The ideal goal of this guideline is simple:
Detect security issues — whether design flaws or application vulnerabilities — as early and as cheaply as possible, and keep detecting them continuously.
Contributing to this project is so simple. Please go to the project’s GitHub repo and send a new pull request. Please do not hesitate to create an issue if you have any ideas or recommendations.Share your opinion or recommandation