Secure Software Development Pipeline
Security checks are built into the build and release pipeline. Secret and dependency scanning, cloud and container configuration checks, and access separation between development, testing, and production environments.
The task
Build security controls into the application build and release process. Connect the rules for handling code, secrets, dependencies and infrastructure with automated checks.
Rules and implementation
The system covers storage and rotation of secrets, keeping them out of the repository and checking that they do not reappear. Cloud and container configurations are described as code and validated before they are applied.
Dependency control is combined with access separation between the development, testing and production environments.
Rolling out the checks
Rules first run in observation mode. Warnings and build-blocking conditions are then tuned based on a review of the findings.
We tied security requirements to the technical release process, so the checks run regularly alongside every change to the application.