DEV Community

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
GitHub Organization Security Hardening: Exact Controls and Step-by-Step Setup Guide

GitHub Organization Security Hardening: Exact Controls and Step-by-Step Setup Guide

1
Comments
29 min read
We scanned 17,000 Claude Code skills. 39% run shell commands - only 4% say so up front.

We scanned 17,000 Claude Code skills. 39% run shell commands - only 4% say so up front.

Comments
3 min read
3 Broken Auth Patterns Cursor Keeps Writing Into Your API

3 Broken Auth Patterns Cursor Keeps Writing Into Your API

Comments
3 min read
組織向け GitHub セキュリティ・ハードニング完全ガイド

組織向け GitHub セキュリティ・ハードニング完全ガイド

Comments
29 min read
End-to-End GitHub Security Hardening Guide for Organizations

End-to-End GitHub Security Hardening Guide for Organizations

Comments
44 min read
When Chain Analysis Fails: Three Boundaries You Cannot Cross

When Chain Analysis Fails: Three Boundaries You Cannot Cross

Comments
4 min read
The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon

The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon

Comments
6 min read
Anyone with GitHub issue access can steal your CI/CD secrets. Here's why.

Anyone with GitHub issue access can steal your CI/CD secrets. Here's why.

Comments
6 min read
GitGuardian NHI Governance Now Gives More Comprehensive Visibility

GitGuardian NHI Governance Now Gives More Comprehensive Visibility

Comments
6 min read
2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk

2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk

1
Comments
5 min read
We benchmarked 24 SAST tools on ~700 real vulnerabilities. The 3 best known ones came last

We benchmarked 24 SAST tools on ~700 real vulnerabilities. The 3 best known ones came last

Comments
1 min read
Embracing Zero Trust Security Architecture: A DevOps and AI Engineer's Perspective

Embracing Zero Trust Security Architecture: A DevOps and AI Engineer's Perspective

Comments
2 min read
Trivy's March Supply Chain Attack Shows Where Secret Exposure Hurts Most

Trivy's March Supply Chain Attack Shows Where Secret Exposure Hurts Most

1
Comments 1
5 min read
Developers Are Now the Attack Surface

Developers Are Now the Attack Surface

Comments
10 min read
AI Security Scanning Tools in 2026: Snyk vs Semgrep vs OX Security — Real False-Positive Rates Tested

AI Security Scanning Tools in 2026: Snyk vs Semgrep vs OX Security — Real False-Positive Rates Tested

Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.