DevSecOps notes and differnce btween devops vs devdecops.pptx

trivedicropconnect 3 views 20 slides Oct 17, 2025
Slide 1
Slide 1 of 20
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20

About This Presentation

DevSecOps notes and difference between devops vs devdecops.pptx


Slide Content

Continuous Delivery Continuous delivery is a practice where code changes are automatically prepared for a release to production

Continuous Delivery

Continuous Delivery

Continuous Delivery

Traditional Builds

Traditional Builds

Continuous Integration CI is a practice that helps to frequently integrate code changes into a central repository and then automate Builds

Continuous Integration

Production Grade DevSecOps Build Pipeline

Production Grade DevSecOps Build Pipeline Stage 1: Build & Unit Test Generate Artifacts Unit test Tools: Maven

Production Grade DevSecOps Build Pipeline Stage 2: Code Coverage How Many lines of code you tested? Unused code Tools: Jacoco

Production Grade DevSecOps Build Pipeline Stage 3: Software composition analysis Identify Vulnerabilities introduced by open-source or 3rd party libraries used in code Tools: OWASP Dependency-check

Production Grade DevSecOps Build Pipeline Stage 4: Static Application Security Testing Identify Vulnerabilities in proprietary code Insecure coding practice Tools: Sonarqube

Production Grade DevSecOps Build Pipeline Stage 5: Quality Gates Check if application meets the quality standards Tools: Sonarqube Quality profile

Production Grade DevSecOps Build Pipeline Stage 6: Build Docker Image Generate Deployable Artifact Tools: Dockerfile

Production Grade DevSecOps Build Pipeline Stage 7: Scan Docker Image Identify Vulnerabilities in Image layers Tools: Trivy

Production Grade DevSecOps Build Pipeline Stage 8: Smoke Test Verify if the Image is built properly Determine if Image/Application is ready for testing Tools: Docker Container

Production Grade DevSecOps Build Pipeline Stage 8: Smoke Test Verify if the Image is built properly Determine if Image/Application is ready for testing Tools: Docker Container

Continuous Integration CI is a practice that helps to frequently integrate code changes into a central repository and then automate Builds
Tags