DevSecOps
Browse all articles, tutorials, and guides about DevSecOps
Guides
Security Gates
Implement automated security gates that block deployments on critical vulnerabilities, policy violations, and security failures. Shift security left in your CI/CD pipeline.
Cryptography Essentials
Master the cryptographic fundamentals every DevOps engineer needs: symmetric and asymmetric encryption, hashing algorithms, TLS/SSL certificates, and Public Key Infrastructure (PKI).
Static Application Security Testing (SAST)
Master Static Application Security Testing (SAST) with SonarQube, Semgrep, and CodeQL. Learn to detect vulnerabilities in source code before they reach production.
Threat Modeling
Master threat modeling methodologies including STRIDE, DREAD, and attack trees. Learn to identify, analyze, and prioritize security threats in your systems with practical exercises.
OWASP Top 10
Learn about the OWASP Top 10 web application security risks. Understand each vulnerability, see real-world examples, and learn how to prevent them in your applications.
Security Principles
Master the fundamental security principles every DevSecOps engineer needs to know. Learn CIA Triad, Defense in Depth, Least Privilege, and Zero Trust concepts with practical examples.
Posts
A Poisoned .git/config Runs Code on git status. We Tested Which Commands and Copies Carry It
On October 2 GitLab disclosed ConfigPoisoning: a repo that brings its own .git/config makes an AI coding tool run attacker commands when it shows a diff. We ran the same trick against plain git 2.39 and 2.55. A bare git status ran repo-supplied programs, the usual safe diff flags missed the clean filter, git 2.54 config hooks walked past core.hooksPath=/dev/null, a clone was clean but a cached workspace was not, and GitHub-hosted runners switch off the ownership check that would stop it.
GITHUB_TOKEN Is Now 377 Characters Long. We Tested Which Redaction Rules Still Catch It
GitHub finished moving App installation tokens, including the Actions GITHUB_TOKEN, to a new ghs_<app id>_<JWT> format on October 2. We ran 40 real tokens through the usual redaction regexes and one through gitleaks, trufflehog and detect-secrets. The latest gitleaks release found nothing, and the common patterns either missed the token or hid only its first 40 to 46 characters, which were the same in all 40 tokens.