Microsoft Defender for DevOps is a new capability in Defender for Cloud that provides visibility across multiple DevOps environments that you can use to centrally manage DevOps security, strengthen your infrastructure as code and help you prioritize critical issues in code across your pipeline and multiple cloud environments.
In this video, I’m going to show you how you can set up Defender for DevOps, connect your GitHub account to Defender for DevOps, setting up your GitHub Actions workflow to run the scan and then publish the results of the scan to GitHub so you can remediate issues.
Any questions? Pop them in the comment section below 👇
Twitter: / willvelida
RESOURCES
Blog post: https://www.willvelida.com/posts/conf...
GitHub Repo: https://github.com/willvelida/defende...
Defender for DevOps: https://learn.microsoft.com/en-us/azu...
Microsoft Security DevOps for GitHub Actions: https://github.com/microsoft/security...
Microsoft Security DevOps for GitHub Actions YAML file: https://github.com/microsoft/security...