
DevSecOps
Course Index
28 Lessons · 3 Sections
Master DevSecOps — shifting security left into every stage of the CI/CD pipeline. Covers SAST, DAST, SCA, container scanning, SBOM, Sigstore supply chain security, OPA/Gatekeeper, Falco runtime security & AI-powered security 2026. Includes 4 builds: SAST & SCA pipeline, Trivy scanning, OPA K8s policy & full DevSecOps pipeline.
28Lessons
3Sections
4Projects
FreeAccess
Section 1Shift-Left Security & ScanningLessons 1–10
Lesson 1
What is DevSecOps? Shift-Left Security
Lesson 2
DevSecOps vs DevOps: Adding Security
Lesson 3
Threat Modelling: STRIDE & PASTA
Lesson 4
SAST: Static Application Security Testing
Lesson 5
SCA: Software Composition Analysis
Lesson 6
DAST: Dynamic Application Security Testing
Lesson 7
Container Security Scanning: Trivy & Snyk
Lesson 8
Secret Scanning: Detecting Leaked Credentials
Lesson 9
SBOM: Software Bill of Materials
Lesson 10
Security in CI/CD: GitHub & GitLab Integration
Section 2Supply Chain, Runtime & ComplianceLessons 11–22
Lesson 11
Supply Chain Security: SLSA Framework
Lesson 12
Sigstore: Signing & Verifying Artifacts
Lesson 13
Infrastructure Security: Checkov & tfsec
Lesson 14
Kubernetes Security: Pod Security & RBAC
Lesson 15
Cloud Security Posture Management (CSPM)
Lesson 16
Runtime Security: Falco & eBPF
Lesson 17
Zero Trust Security Model
Lesson 18
Compliance as Code: OPA & Gatekeeper
Lesson 19
Penetration Testing Basics for DevSecOps
Lesson 20
Vulnerability Management & CVE Triage
Lesson 21
Security Metrics & KPIs for DevSecOps
Lesson 22
AI & DevSecOps 2026: AI-Powered Security
Section 3Anti-Patterns, Culture & ProjectsLessons 23–28