All roadmaps
Advanced7 projects

DevSecOps

Bake security into the pipeline instead of bolting it on after the fact.

18+

completed

~18.5h

total time

7

projects

Part 1·Beginner·2-3h·18+ learners

Shift-Left Security in CI/CD

Add pre-commit secret scanning, dependency vulnerability checks, and a fail-the-build security gate to a real GitHub Actions pipeline.

Start
Part 2·Intermediate·2-3h·16+ learners

Container Image Scanning

Scan a container image for OS and dependency vulnerabilities with Trivy, generate an SBOM, and sign the image with cosign.

Start
Part 3·Intermediate·3h·14+ learners

Secrets Management with Vault

Run HashiCorp Vault locally, store and retrieve static secrets, and generate short-lived dynamic database credentials.

Start
Part 4·Intermediate·2-3h·12+ learners

Infrastructure as Code Security Audits

Run tfsec and Checkov against a deliberately misconfigured Terraform module, triage the findings, and wire the scan into CI.

Start
Part 5·Intermediate·3h·9+ learners

SAST and DAST Pipeline Integration

Add static analysis (Semgrep) and dynamic analysis (OWASP ZAP) to a CI pipeline against a small intentionally-vulnerable web app.

Start
Part 6·Intermediate·2-3h·7+ learners

Policy as Code with OPA

Write Rego policies with Open Policy Agent, test them with the built-in unit test framework, and enforce one against raw Kubernetes manifests.

Start
Part 7·Beginner·2-3h·5+ learners

Writing an Incident Response Runbook

Write a real, usable incident response runbook for a specific scenario — a leaked cloud credential — then pressure-test it.

Start