OWASP DevSecOps Guideline

The OWASP DevSecOps Guideline explains how to build and operate a secure software delivery pipeline using best practices and a curated, vendor-neutral set of tools. The aim is to help organizations of any size that run a DevOps pipeline introduce security controls without slowing delivery, and to promote a shift-left (and increasingly shift-everywhere) security culture across the whole development lifecycle.

The ideal goal of this guideline is simple:

Detect security issues — whether design flaws or application vulnerabilities — as early and as cheaply as possible, and keep detecting them continuously.

About OWASP DevSecOps Guideline

Project Leaders

Ali Yazdani

Project Leader

Email

Project Information

Incubator Project
Classification
Other
Language
Python
Contributors
32
GitHub Stars
1124
Downloads
0
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP DevSecOps Guideline | OWASP Foundation