Ardotech
All articles

DevSecOps: 5 checks to add from the very first sprint

Security added at the end is expensive and comes too late. Here are five simple checks to plug into your pipeline from day one.

By L'équipe ArdoTech1 min read

In many projects, security shows up just before go-live, as an audit that uncovers dozens of issues. Fixing them at that stage is expensive and delays delivery. DevSecOps does the opposite: lightweight, automated checks that run on every code change.

1. Scan your dependencies

Most of an application's code comes from open-source libraries. Tools such as Trivy, Dependabot or npm audit flag vulnerable versions on every build.

  • Only fail the build on critical vulnerabilities at first, so the team isn't discouraged.
  • Schedule regular dependency updates, for example monthly.

2. Never commit a secret

An API key pushed to a repository must be treated as compromised, even if it is deleted afterwards. Add a secret scanner (gitleaks, GitHub secret scanning) as a pre-commit hook and in CI, and keep secrets in a vault (Vault or your cloud provider's secret manager).

3. Run static analysis

A SAST tool (SonarQube, Semgrep) spots injections, weak input validation and dead code. Start with a small rule set and handle findings in code review, like any other defect.

4. Scan container images

A Docker image ships a whole operating system. Use minimal base images, keep them up to date and scan them before pushing to the registry.

5. Test the running application

A DAST scan (OWASP ZAP) against the staging environment checks security headers, cookies and common web flaws. Run nightly, it never slows developers down.

Where to start?

There is no need to do everything at once. Start with dependency scanning and secret detection: they give the best return. Add the others sprint by sprint, and track the number of open vulnerabilities to measure progress.

  • DevSecOps
  • CI/CD
  • Sécurité

A topic worth exploring for your company?

Let's discuss it in concrete terms, in your context.