Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

DevSecOps Tutorial - Building a Pipeline with GitHub Actions and Docker Scout

TechWorld with Nana via YouTube

Overview

Learn the fundamentals of DevSecOps in this comprehensive tutorial. Explore why DevSecOps emerged, its core concepts, and practical implementation. Discover essential tools and techniques including SAST, SCA, DAST, secret scanning, and container image scanning. Follow along with a hands-on demo to build a DevSecOps pipeline using GitHub Actions, configuring SAST scans with Bandit and container image scanning with Docker Scout. Analyze scan reports, generate comprehensive assessments, and gain insights into next steps for advancing your DevSecOps knowledge, including cloud and Kubernetes security.

Syllabus

- Intro and Course Overview
- Importance of Security
- Before DevSecOps: Security as Afterthought
- What is DevSecOps
- How DevSecOps works in Practice: DevSecOps Tools
- Shifting Security Left
- DevSecOps DEMO
- Demo Overview
- Workflow Templates
- Configure SAST Scan
- Analyze scan results
- Ignore Low Severity Issues
- Generate Scan Report
- Configure Image Scanning with Docker Scout
- Analyze scan results
- Reuse existing GitHub Action for Docker Scout
- Where to go from here
- Next Steps - Cloud and Kubernetes Security

Taught by

TechWorld with Nana

Reviews

Start your review of DevSecOps Tutorial - Building a Pipeline with GitHub Actions and Docker Scout

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.