Skip to content
s1ns3nz0 | Known Unknowns
Go back

Securing Workflows in CI Pipelines - Secure Code Commits

2 min read

Considering DevSecOps principles such as Shift Left, code commits should be properly reviewed and tested

Table of contents

Open Table of contents

Overview

COMMIT-REQ-1

Activate Secret Scanning and Push Protection

Bypass Must be reviewed

Monitor and Alert Security Dashboard

Remediation Process

COMMIT-REQ-2


Share this post:

Previous Post
Securing Workflows in CD Pipelines
Next Post
Securing Workflows in CI Pipelines - Integrity of Evidence Generation During Software Updates