Pipeline security, SBOM, supply chain management, secrets, container security, and environments.
CI/CD pipeline security covering hardening, scanning stages, secrets management, and protecting the build system as an attack surface.
Artifact integrity verification, SBOM generation, and software supply chain transparency using SLSA and in-toto frameworks.
Dependency and supply chain management including SCA, license compliance, vulnerability monitoring, and mitigating dependency confusion attacks.
Secrets management best practices covering vaults, rotation, detection, and preventing secret exposure in code and CI/CD pipelines.
Infrastructure hardening and container security covering IaC security, CIS Benchmarks, image scanning, and runtime protection.
Environment separation and deployment strategies ensuring security isolation between development, staging, and production environments.
Secure development environment configuration covering endpoint security, IDE hardening, and developer workstation standards.