Browsing Category
DevSecOps
116 posts
Open Source Security Best Practices
I love open source. Nearly everything I build leans on it heavily, and I genuinely couldn’t ship software…
Dependency Scanning Explained
I once inherited a project with over 400 dependencies, and when I ran a scan for the first…
How to Secure Open Source Dependencies
I think of open-source dependencies the way I think about hiring contractors — I’m bringing in outside work…
Prevent Software Supply Chain Attacks: A Practical Guide for Developers and Security Teams
A few years ago, “supply chain security” was a phrase you’d mostly hear from procurement teams talking about…
SCA vs SBOM: What’s the Difference (and Why You Need Both)
I get asked this question a lot, usually in the same breath: “We already have an SBOM, so…
Secure Package Management Best Practices Every Developer Should Follow
Every project I’ve worked on, no matter the language or stack, eventually comes down to the same reality:…
AWS DevSecOps Best Practices: Building Security Into Every Deployment
The first time I audited an AWS environment that had grown organically over a couple of years —…
Azure DevSecOps: A Complete Guide to Building Secure Pipelines
Azure DevOps and Azure’s broader security tooling give you almost everything you need to run a mature DevSecOps…
Google Cloud DevSecOps Best Practices: A Practical Playbook
Google Cloud has a reputation for being the “engineer’s cloud,” and that shows in its security tooling too…
Multi-Cloud Security Best Practices: Managing Risk Across AWS, Azure, and GCP
Multi-cloud rarely happens because a company sits down and deliberately architects for it. More often, it’s the result…