DevSecOps Tutorial - Building a Pipeline with GitHub Actions and Docker Scout
Offered By: TechWorld with Nana via YouTube
Course Description
Overview
Learn the fundamentals of DevSecOps in this comprehensive tutorial. Explore why DevSecOps emerged, its core concepts, and practical implementation. Discover essential tools and techniques including SAST, SCA, DAST, secret scanning, and container image scanning. Follow along with a hands-on demo to build a DevSecOps pipeline using GitHub Actions, configuring SAST scans with Bandit and container image scanning with Docker Scout. Analyze scan reports, generate comprehensive assessments, and gain insights into next steps for advancing your DevSecOps knowledge, including cloud and Kubernetes security.
Syllabus
- Intro and Course Overview
- Importance of Security
- Before DevSecOps: Security as Afterthought
- What is DevSecOps
- How DevSecOps works in Practice: DevSecOps Tools
- Shifting Security Left
- DevSecOps DEMO
- Demo Overview
- Workflow Templates
- Configure SAST Scan
- Analyze scan results
- Ignore Low Severity Issues
- Generate Scan Report
- Configure Image Scanning with Docker Scout
- Analyze scan results
- Reuse existing GitHub Action for Docker Scout
- Where to go from here
- Next Steps - Cloud and Kubernetes Security
Taught by
TechWorld with Nana
Related Courses
Managing Microsoft Azure SecurityPluralsight Implementing and Administering Azure Sentinel
LinkedIn Learning AWS Certified DevOps Engineer: Get 3 Certifications 2023
Udemy Automating Cisco ASA and Firepower Policies Using APIs
Pluralsight SC-200: Mitigate threats using Microsoft Defender for Endpoint
Microsoft via Microsoft Learn