DevSecOps Tutorial for Beginners | CI Pipeline with GitHub Actions and Docker Scout

  Рет қаралды 82,112

TechWorld with Nana

TechWorld with Nana

Күн бұрын

DevSecOps Project | DevSecOps Pipeline for Python project with GitHub Actions - SAST Scan & Container Image Scanning | Discover security vulnerabilities of Python application in CI pipeline
💜 4-month DevSecOps Bootcamp: bit.ly/3RaK8KP
💙 6-month DevOps Bootcamp: bit.ly/483Iott
#devsecops #githubactions #techworldwithnana
🙌 Thanks Progress for supporting this video!
🙌 Automate and Enforce Compliance with Chef: prgress.co/chef-compliance
DevSecOps is a set of practices, concepts and tools that combines software development (Dev), security (Sec), and IT operations (Ops) into a single, integrated process. The goal of DevSecOps is to incorporate security into every stage of the software development lifecycle, from design and development to testing and deployment, rather than treating security as a separate and isolated concern.
▬▬▬▬▬▬ L I N K S 🔗▬▬▬▬▬▬
► OWASP vulnerable Python app: owasp.org/www-project-pygoat
► Forked project: github.com/nanuchi/devsecops-...
► Docker Scout Links:
- Docker Scout: docs.docker.com/scout/
- Docker Scout CLI: docs.docker.com/engine/refere...
- Docker Scout GitHub Action: github.com/docker/scout-action
▬▬▬▬▬▬ Course Pre-Requisites ▬▬▬▬▬▬
💡 DevOps, GitHub Actions, CI/CD Basics
👉 GitHub Actions Tutorial: • GitHub Actions Tutoria...
👉 What is DevSecOps in 8 minutes: • What is DevSecOps? Dev...
▬▬▬▬▬▬ What you’ll learn in this DevSecOps crash course ✅ ▬▬▬▬▬▬
► Understanding why DevSecOps concept emerged
► What is DevSecOps
► How DevSecOps works in practice
► DevSecOps Concepts and tools
► Understand what SAST, SCA, DAST, Secret Scanning, Container Image Scanning is
► DevSecOps Concepts and tools
► DevSecOps Demo: Build DevSecOps Pipeline with GitHub Actions
► How to configure SAST Scan with Bandit
► How to configure Container Image Scanning with Docker Scout
► How to generate scan reports
► How to analyze scan reports
► Next Steps to continue your DevSecOps Learning
▬▬▬▬▬▬ T I M E S T A M P S ⏰ ▬▬▬▬▬▬
00:00 - Intro and Course Overview
01:06 - Importance of Security
06:43 - Before DevSecOps: Security as Afterthought
07:36 - What is DevSecOps
09:40 - How DevSecOps works in Practice: DevSecOps Tools
15:51 - Shifting Security Left
19:19 - DevSecOps DEMO
19:26 - Demo Overview
21:05 - Workflow Templates
22:55 - Configure SAST Scan
31:25 - Analyze scan results
35:18 - Ignore Low Severity Issues
37:40 - Generate Scan Report
44:00 - Configure Image Scanning with Docker Scout
57:27 - Analyze scan results
01:04:12 - Reuse existing GitHub Action for Docker Scout
01:12:57 - Where to go from here
01:16:45 - Next Steps - Cloud and Kubernetes Security
▬▬▬▬▬▬ Connect with me 👋 ▬▬▬▬▬▬
INSTAGRAM ► bit.ly/2F3LXYJ
TWITTER ► bit.ly/3i54PUB
LINKEDIN ► bit.ly/3hWOLVT
Facebook group ► bit.ly/32UVSZP

Пікірлер: 67
Azure DevOps Tutorial for Beginners | CI/CD with Azure Pipelines
36:29
TechWorld with Nana
Рет қаралды 1,1 МЛН
Docker Crash Course for Absolute Beginners [NEW]
1:07:39
TechWorld with Nana
Рет қаралды 1,4 МЛН
КАКОЙ ВАШ ЛЮБИМЫЙ ЦВЕТ?😍 #game #shorts
00:17
The most impenetrable game in the world🐶?
00:13
LOL
Рет қаралды 31 МЛН
WHY DOES SHE HAVE A REWARD? #youtubecreatorawards
00:41
Levsob
Рет қаралды 31 МЛН
Como ela fez isso? 😲
00:12
Los Wagners
Рет қаралды 25 МЛН
Life of a DevSecOps Engineer (w/ Aras "Russ" Memisyazici)
1:06:45
Cyberspatial
Рет қаралды 47 М.
GitLab CI CD Tutorial for Beginners [Crash Course]
1:09:00
TechWorld with Nana
Рет қаралды 1,1 МЛН
What is Platform Engineering and how it fits into DevOps and Cloud world
42:41
TechWorld with Nana
Рет қаралды 137 М.
Kubernetes Crash Course for Absolute Beginners [NEW]
1:12:04
TechWorld with Nana
Рет қаралды 2,5 МЛН
How To Become A DevOps Engineer in 2023? | Skills To Learn
20:34
Travis Media
Рет қаралды 531 М.
ArgoCD Tutorial for Beginners | GitOps CD for Kubernetes
47:53
TechWorld with Nana
Рет қаралды 582 М.
КАКОЙ ВАШ ЛЮБИМЫЙ ЦВЕТ?😍 #game #shorts
00:17