<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DevSecOps &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/devsecops/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Mon, 21 Jul 2025 23:13:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Beyond IAM access keys: Modern authentication approaches for AWS</title>
		<link>https://noise.getoto.net/2025/07/22/beyond-iam-access-keys-modern-authentication-approaches-for-aws/</link>
		
		<dc:creator><![CDATA[Mitch Beaumont]]></dc:creator>
		<pubDate>Mon, 21 Jul 2025 23:13:43 +0000</pubDate>
				<category><![CDATA[AWS IAM]]></category>
		<category><![CDATA[AWS Identity and Access Management]]></category>
		<category><![CDATA[AWS Identity and Access Management (IAM)]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[IAM policies]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e4ee7dfa2608bf03d7bf24667b2d8ec4</guid>

					<description><![CDATA[When it comes to AWS authentication, relying on long-term credentials, such as AWS Identity and Access Management (IAM) access keys, introduces unnecessary risks; including potential credential exposure, unauthorized sharing, or theft. In this post, I present five common use cases where AWS customers traditionally use IAM access keys and present more secure alternatives that you […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Combining Snyk’s Insight with Amazon Q Developer’s Assistance to Streamline Secure Development</title>
		<link>https://noise.getoto.net/2025/04/28/combining-snyks-insight-with-amazon-q-developers-assistance-to-streamline-secure-development/</link>
		
		<dc:creator><![CDATA[Omar Faruk]]></dc:creator>
		<pubDate>Mon, 28 Apr 2025 18:40:32 +0000</pubDate>
				<category><![CDATA[Amazon Q Developer]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[CI/CD]]></category>
		<category><![CDATA[codewhisperer]]></category>
		<category><![CDATA[Developer Tools]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[New stuff]]></category>
		<category><![CDATA[Partner solutions]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=0623a5ccfd4e45c65b2a5f7bf45c0c00</guid>

					<description><![CDATA[Developers today face a constant balancing act – building new features and functionality while also ensuring the security and reliability of their codebase. Two powerful tools, Snyk and Amazon Q Developer, can work in tandem to help developers navigate this challenge with greater efficiency and efficacy. Snyk is a leading developer security platform that empowers […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>How GitHub uses CodeQL to secure GitHub</title>
		<link>https://noise.getoto.net/2025/02/12/how-github-uses-codeql-to-secure-github/</link>
		
		<dc:creator><![CDATA[Brandon Stewart]]></dc:creator>
		<pubDate>Wed, 12 Feb 2025 17:00:04 +0000</pubDate>
				<category><![CDATA[CI/CD]]></category>
		<category><![CDATA[CodeQL]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Engineering]]></category>
		<category><![CDATA[GHAS]]></category>
		<category><![CDATA[Product Security]]></category>
		<category><![CDATA[sast]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://github.blog/?p=82533</guid>

					<description><![CDATA[<p>How GitHub’s Product Security Engineering team manages our CodeQL implementation at scale and how you can, too.</p>
<p>The post <a href="https://github.blog/engineering/how-github-uses-codeql-to-secure-github/">How GitHub uses CodeQL to secure GitHub</a> appeared first on <a href="https://github.blog/">The GitHub Blog</a>.</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Code security scanning with Amazon Q Developer</title>
		<link>https://noise.getoto.net/2024/10/16/code-security-scanning-with-amazon-q-developer/</link>
		
		<dc:creator><![CDATA[Surabhi Tandon]]></dc:creator>
		<pubDate>Wed, 16 Oct 2024 11:32:27 +0000</pubDate>
				<category><![CDATA[Amazon Q]]></category>
		<category><![CDATA[developer]]></category>
		<category><![CDATA[Developer Tools]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[generative AI]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=73b5171653658ecf8995928ae3df2e3c</guid>

					<description><![CDATA[A primary objective of software developers is to develop products that uphold the highest standards of data privacy and security, fostering trust and confidence among their users and customers. Developers seek to secure their software by identifying and mitigating security vulnerabilities in their codebase, thereby enhancing its resilience against cyber threats. Amazon Q Developer, a […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Terraform CI/CD and testing on AWS with the new Terraform Test Framework</title>
		<link>https://noise.getoto.net/2024/04/03/terraform-ci-cd-and-testing-on-aws-with-the-new-terraform-test-framework/</link>
		
		<dc:creator><![CDATA[Kevon Mayers]]></dc:creator>
		<pubDate>Tue, 02 Apr 2024 23:45:18 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[CI/CD]]></category>
		<category><![CDATA[Customer Solutions]]></category>
		<category><![CDATA[Developer Tools]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Infrastructure as Code]]></category>
		<category><![CDATA[Integration & Automation]]></category>
		<category><![CDATA[Pipelines]]></category>
		<category><![CDATA[Provisioning and orchestration]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<category><![CDATA[Terraform]]></category>
		<category><![CDATA[Test Automation]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[Top Posts*]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=104dcde212c04af33da75c4e54a350d1</guid>

					<description><![CDATA[In this blog post, we will show you how to validate Terraform modules and how to automate the process using a Continuous Integration/Continuous Deployment (CI/CD) pipeline.]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Strengthen the DevOps pipeline and protect data with AWS Secrets Manager, AWS KMS, and AWS Certificate Manager</title>
		<link>https://noise.getoto.net/2024/01/10/strengthen-the-devops-pipeline-and-protect-data-with-aws-secrets-manager-aws-kms-and-aws-certificate-manager/</link>
		
		<dc:creator><![CDATA[Magesh Dhanasekaran]]></dc:creator>
		<pubDate>Wed, 10 Jan 2024 19:59:11 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[AWS Certificate Manager]]></category>
		<category><![CDATA[AWS CodePipeline]]></category>
		<category><![CDATA[AWS Key Management Service*]]></category>
		<category><![CDATA[AWS KMS]]></category>
		<category><![CDATA[AWS Secrets Manager]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[Data protection]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e6945fbfa728839a1dfdd0afec4aa6e7</guid>

					<description><![CDATA[In this blog post, we delve into using Amazon Web Services (AWS) data protection services such as Amazon Secrets Manager, AWS Key Management Service (AWS KMS), and AWS Certificate Manager (ACM) to help fortify both the security of the pipeline and security in the pipeline. We explore how these services contribute to the overall security […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Automate Cedar policy validation with AWS developer tools</title>
		<link>https://noise.getoto.net/2024/01/10/automate-cedar-policy-validation-with-aws-developer-tools/</link>
		
		<dc:creator><![CDATA[Pontus Palmenäs]]></dc:creator>
		<pubDate>Wed, 10 Jan 2024 17:08:18 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon Verified Permissions]]></category>
		<category><![CDATA[AWS CodeBuild]]></category>
		<category><![CDATA[AWS CodePipeline]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=cf39ffbfc6140ea0c30aa7ff7451beb6</guid>

					<description><![CDATA[Cedar is an open-source language that you can use to authorize policies and make authorization decisions based on those policies. AWS security services including AWS Verified Access and Amazon Verified Permissions use Cedar to define policies. Cedar supports schema declaration for the structure of entity types in those policies and policy validation with that schema. […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Introducing IAM Access Analyzer custom policy checks</title>
		<link>https://noise.getoto.net/2023/11/27/introducing-iam-access-analyzer-custom-policy-checks/</link>
		
		<dc:creator><![CDATA[Mitch Beaumont]]></dc:creator>
		<pubDate>Mon, 27 Nov 2023 14:00:04 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[announcements]]></category>
		<category><![CDATA[Automated reasoning]]></category>
		<category><![CDATA[AWS IAM]]></category>
		<category><![CDATA[AWS Identity and Access Management]]></category>
		<category><![CDATA[AWS Identity and Access Management (IAM)]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[IAM Access Analyzer]]></category>
		<category><![CDATA[IAM policies]]></category>
		<category><![CDATA[Identity and Access Management]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=54c32ffaf84455d5492a7febba6ffcf3</guid>

					<description><![CDATA[AWS Identity and Access Management (IAM) Access Analyzer was launched in late 2019. Access Analyzer guides customers toward least-privilege permissions across Amazon Web Services (AWS) by using analysis techniques, such as automated reasoning, to make it simpler for customers to set, verify, and refine IAM permissions. Today, we are excited to announce the general availability […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Validate IAM policies by using IAM Policy Validator for AWS CloudFormation and GitHub Actions</title>
		<link>https://noise.getoto.net/2023/08/30/validate-iam-policies-by-using-iam-policy-validator-for-aws-cloudformation-and-github-actions/</link>
		
		<dc:creator><![CDATA[Mitch Beaumont]]></dc:creator>
		<pubDate>Wed, 30 Aug 2023 13:04:28 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[AWS IAM]]></category>
		<category><![CDATA[AWS Identity and Access Management]]></category>
		<category><![CDATA[AWS Identity and Access Management (IAM)]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[IAM Access Analyzer]]></category>
		<category><![CDATA[Identity and Access Management]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<category><![CDATA[Web Identity Federation]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6044f3e89440f257872d1dad2a6ea31d</guid>

					<description><![CDATA[In this blog post, I’ll show you how to automate the validation of AWS Identity and Access Management (IAM) policies by using a combination of the IAM Policy Validator for AWS CloudFormation (cfn-policy-validator) and GitHub Actions. Policy validation is an approach that is designed to minimize the deployment of unwanted IAM identity-based and resource-based policies […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Integrating with GitHub Actions – Amazon CodeGuru in your DevSecOps Pipeline</title>
		<link>https://noise.getoto.net/2023/03/22/integrating-with-github-actions-amazon-codeguru-in-your-devsecops-pipeline/</link>
		
		<dc:creator><![CDATA[Mahesh Biradar]]></dc:creator>
		<pubDate>Wed, 22 Mar 2023 16:25:11 +0000</pubDate>
				<category><![CDATA[Amazon CodeGuru]]></category>
		<category><![CDATA[AWS CloudFormation]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[Customer Solutions]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Github]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=005fd07e3089ab8cbeb4a94830ae287c</guid>

					<description><![CDATA[Many organizations have adopted DevOps practices to streamline and automate software delivery and IT operations. A DevOps model can be adopted without sacrificing security by using automated compliance policies, fine-grained controls, and configuration management techniques. However, one of the key challenges customers face is analyzing code and detecting any vulnerabilities in the code pipeline due […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Use Amazon Inspector to manage your build and deploy pipelines for containerized applications</title>
		<link>https://noise.getoto.net/2022/11/03/use-amazon-inspector-to-manage-your-build-and-deploy-pipelines-for-containerized-applications/</link>
		
		<dc:creator><![CDATA[Scott Ward]]></dc:creator>
		<pubDate>Thu, 03 Nov 2022 16:50:23 +0000</pubDate>
				<category><![CDATA[Amazon Inspector]]></category>
		<category><![CDATA[Containers]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=faf5af3e675126eced077c3c51631934</guid>

					<description><![CDATA[Amazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities and unintended network exposure. Amazon Inspector currently supports vulnerability reporting for Amazon Elastic Compute Cloud (Amazon EC2) instances and container images stored in Amazon Elastic Container Registry (Amazon ECR). With the emergence of Docker in 2013, […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Integrating Cloud Security With DevOps and CI/CD Tools</title>
		<link>https://noise.getoto.net/2022/09/09/integrating-cloud-security-with-devops-and-ci-cd-tools/</link>
		
		<dc:creator><![CDATA[Clint Merrill]]></dc:creator>
		<pubDate>Fri, 09 Sep 2022 14:33:06 +0000</pubDate>
				<category><![CDATA[cloud security]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=24ec6493e6ea5a58fd9e2749c0f77157</guid>

					<description><![CDATA[In this post, we dive into a key aspect of our approach: integrating cloud security with developer and DevOps tooling.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/09/cloud-devops-tools.jpg" length="0" type="" />

			</item>
		<item>
		<title>What It Takes to Securely Scale Cloud Environments at Tech Companies Today</title>
		<link>https://noise.getoto.net/2022/05/25/what-it-takes-to-securely-scale-cloud-environments-at-tech-companies-today/</link>
		
		<dc:creator><![CDATA[Ben Austin]]></dc:creator>
		<pubDate>Wed, 25 May 2022 14:20:10 +0000</pubDate>
				<category><![CDATA[cloud security]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=484f0c10950bc2f6eac862283975e344</guid>

					<description><![CDATA[Here are three ways to help empower your teams to take advantage of the many benefits of public cloud infrastructure without sacrificing security.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/05/securely-scale-cloud.jpg" length="0" type="" />

			</item>
		<item>
		<title>Continuous runtime security monitoring with AWS Security Hub and Falco</title>
		<link>https://noise.getoto.net/2021/12/17/continuous-runtime-security-monitoring-with-aws-security-hub-and-falco/</link>
		
		<dc:creator><![CDATA[Rajarshi Das]]></dc:creator>
		<pubDate>Fri, 17 Dec 2021 17:35:38 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon ECS]]></category>
		<category><![CDATA[Amazon EKS]]></category>
		<category><![CDATA[AWS Security Hub]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[Containers]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Falco]]></category>
		<category><![CDATA[integration]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Runtime Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=933be533d13950372c1e6ca4c71a3da1</guid>

					<description><![CDATA[Customers want a single and comprehensive view of the security posture of their workloads. Runtime security event monitoring is important to building secure, operationally excellent, and reliable workloads, especially in environments that run containers and container orchestration platforms. In this blog post, we show you how to use services such as AWS Security Hub and […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Forensic investigation environment strategies in the AWS Cloud</title>
		<link>https://noise.getoto.net/2021/10/28/forensic-investigation-environment-strategies-in-the-aws-cloud/</link>
		
		<dc:creator><![CDATA[Sol Kavanagh]]></dc:creator>
		<pubDate>Thu, 28 Oct 2021 15:57:41 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon EC2]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Digital forensics]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[security automation]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6a6fe4851fc4204925bbc84f53063b8c</guid>

					<description><![CDATA[When a deviation from your secure baseline occurs, it’s crucial to respond and resolve the issue quickly and follow up with a forensic investigation and root cause analysis. Having a preconfigured infrastructure and a practiced plan for using it when there’s a deviation from your baseline will help you to extract and analyze the information […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Use the Snyk CLI to scan Python packages using AWS CodeCommit, AWS CodePipeline, and AWS CodeBuild</title>
		<link>https://noise.getoto.net/2021/07/27/use-the-snyk-cli-to-scan-python-packages-using-aws-codecommit-aws-codepipeline-and-aws-codebuild/</link>
		
		<dc:creator><![CDATA[BK Das]]></dc:creator>
		<pubDate>Tue, 27 Jul 2021 00:34:52 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon CodePipeline]]></category>
		<category><![CDATA[AWS CDK]]></category>
		<category><![CDATA[AWS Cloud Development Kit]]></category>
		<category><![CDATA[AWS CodeBuild]]></category>
		<category><![CDATA[AWS CodeCommit]]></category>
		<category><![CDATA[AWS CodePipeline]]></category>
		<category><![CDATA[AWS Command Line Interface]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=bd1ef55ad60fbd9d0fa78fc576b3ec49</guid>

					<description><![CDATA[Learn how to scan Python packages for security vulnerabilities using AWS Developer tools and Snyk]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Building an end-to-end Kubernetes-based DevSecOps software factory on AWS</title>
		<link>https://noise.getoto.net/2021/06/26/building-an-end-to-end-kubernetes-based-devsecops-software-factory-on-aws/</link>
		
		<dc:creator><![CDATA[Srinivas Manepalli]]></dc:creator>
		<pubDate>Fri, 25 Jun 2021 22:35:53 +0000</pubDate>
				<category><![CDATA[Architecture]]></category>
		<category><![CDATA[AWS CodeBuild]]></category>
		<category><![CDATA[AWS CodeDeploy]]></category>
		<category><![CDATA[AWS CodePipeline]]></category>
		<category><![CDATA[AWS Security Hub]]></category>
		<category><![CDATA[CI/CD]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Expert (400)]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Read More]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=246a953713ae9be29fb19636ef6cf3c5</guid>

					<description><![CDATA[DevSecOps software factory implementation can significantly vary depending on the application, infrastructure, architecture, and the services and tools used. In a previous post, I provided an end-to-end DevSecOps pipeline for a three-tier web application deployed with AWS Elastic Beanstalk. The pipeline used cloud-native services along with a few open-source security tools. This solution is similar, […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>GitLab Watchman – Audit Gitlab For Sensitive Data &#038; Credentials</title>
		<link>https://noise.getoto.net/2021/02/03/gitlab-watchman-audit-gitlab-for-sensitive-data-credentials/</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Wed, 03 Feb 2021 13:13:35 +0000</pubDate>
				<category><![CDATA[Без категория]]></category>
		<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<guid isPermaLink="false">https://www.darknet.org.uk/?p=5487</guid>

					<description><![CDATA[GitLab Watchman is an application that uses the GitLab API to audit GitLab for sensitive data and credentials exposed internally – this includes code, commits, wiki pages and more.

GitLab Watchman searches GitLab for internally shared projects and loo...]]></description>
		
		
		
			</item>
		<item>
		<title>Finding Results at the Intersection of Security and Engineering</title>
		<link>https://noise.getoto.net/2021/01/25/finding-results-at-the-intersection-of-security-and-engineering/</link>
		
		<dc:creator><![CDATA[Chaim Mazal]]></dc:creator>
		<pubDate>Mon, 25 Jan 2021 15:06:24 +0000</pubDate>
				<category><![CDATA[Customer Perspective]]></category>
		<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[InsightIDR]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9c12dbdc3caa0a7c67069c204a18eb08</guid>

					<description><![CDATA[In this blog, Chaim Mazal discusses the importance of collaborating with teams to build a comprehensive security culture within an organization.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/01/Finding-Results-at-the-Intersection-of-Security-and-Engineering2.jpg" length="0" type="" />

			</item>
		<item>
		<title>Building end-to-end AWS DevSecOps CI/CD pipeline with open source SCA, SAST and DAST tools</title>
		<link>https://noise.getoto.net/2021/01/22/building-end-to-end-aws-devsecops-ci-cd-pipeline-with-open-source-sca-sast-and-dast-tools/</link>
		
		<dc:creator><![CDATA[Srinivas Manepalli]]></dc:creator>
		<pubDate>Thu, 21 Jan 2021 23:16:59 +0000</pubDate>
				<category><![CDATA[Architecture]]></category>
		<category><![CDATA[AWS CodeBuild]]></category>
		<category><![CDATA[AWS CodeCommit]]></category>
		<category><![CDATA[AWS CodeDeploy]]></category>
		<category><![CDATA[AWS CodePipeline]]></category>
		<category><![CDATA[CICD Pipeline]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Expert (400)]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Read More]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=7335102aed98efbe3f58a77d9a450b54</guid>

					<description><![CDATA[DevOps is a combination of cultural philosophies, practices, and tools that combine software development with information technology operations. These combined practices enable companies to deliver new application features and improved services to customers at a higher velocity. DevSecOps takes this a step further, integrating security into DevOps. With DevSecOps, you can deliver secure and compliant […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 99/457 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-08 16:06:03 by W3 Total Cache
-->