OWASP / OWASP/DevSecOpsGuideline
Pipeline Tampering Risks & Prevention
Open
Nobody has claimed this yet.
documentation
enhancement
idea
- Dominant language
- Python
- Stars
- 1.1k
- Forks
- 262
- PR merge metrics
- No merged PRs in 30d
Description
Hi folks,
As a DevSecOps practitioner for many sizes of development, there is a critical one for maintaining DevSecOps Pipeline to prevent integrity violation and DRY principle with the pipeline consuming
Abstraction Ideas:
- Pipeline definition store as separate repos
- Consuming pipeline as git sub-modules
- Pipeline call should be visible and measured
Benefits:
- Pipeline enforcement
- Pipeline integrity
- Pipeline scalability
I'm happy to help but not so sure which category should we put it on
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.