GitHub: DevSecOps: Part 12/12: How to build a DevSecOps pipeline with GitHub: Our Recommendations

Опубликовано: 20 Март 2026
на канале: Romano Roth
20,182
241

How to build a DevSecOps pipeline with GitHub: Our Recommendations
Session 12: In this video, Padi and I will present you our recommendations for setting up a DevSecOps Pipeline with GitHub.

▬▬▬▬▬▬ T I M E S T A M P S ⏰ ▬▬▬▬▬▬
00:00 Welcome
00:15 Intro
00:21 Recommendations an summary
00:34 DevSecOps with GitHub
01:40 Our Recommendations
01:50 Create top level workflows and re-use workflows
02:41 Define on what branches to run pipelines.
02:56 Use scheduled pipelines
03:51 Use Pull Request
04:14 Protect your branch
05:06 Review the tools you source from the marketplace
05:52 Store your secrets in a secret management
06:36 Evaluate the Security tool
07:01 DAST: Customise the scanner configuration
07:26 Considering including a Secure Expert
07:32 Use a external Vulnarability Management
09:00 Summary
09:43 Outro

▬▬▬▬▬▬ L I N K S 🔗▬▬▬▬▬▬
Source Code
https://github.com/romanoroth/GitHubD...
Blog-Post
https://www.romanoroth.com/post/gitla...
GitHub
https://github.com/
Patrick Steger
  / patrick-steger-ch  

▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
GitHub: DevSecOps: Part 1/12: What is GitHub? The fundamental concepts of a DevSecOps pipeline.
   • GitHub: DevSecOps: Part 1/12: What is GitH...  
GitHub: DevSecOps: Part 2/12: Introduction to GitHub
   • GitHub: DevSecOps: Part 2/12: Introduction...  
GitHub: DevSecOps: Part 3/12: Learn How to Use SCA (Software Composition Analysis)
   • GitHub: DevSecOps: Part 3/12: Learn How to...  
GitHub: DevSecOps: Part 4/12: How to ensure License Compliance?
   • GitHub: DevSecOps: Part 4/12: How to ensur...  
GitHub: DevSecOps: Part 5/12: Protect your Apps with Static Application Security Testing (SAST)
   • GitHub: DevSecOps: Part 5/12: Protect your...  
GitHub: DevSecOps: Part 6/12: How to use Container Scanning
   • GitHub: DevSecOps: Part 6/12: How to use C...  
GitHub: DevSecOps: Part 7/12: How to find secrets in your own code with Secret Scanning
   • GitHub: DevSecOps: Part 7/12: How to find ...  
GitHub: DevSecOps: Part 8/12: How to use Dynamic Application Security Testing (DAST)
   • GitHub: DevSecOps: Part 8/12: How to use D...  
GitHub: DevSecOps: Part 9/12: Vulnerability Management
   • Video  
GitHub: DevSecOps: Part 10/12: Branch Protection and Pull Requests
   • GitHub: DevSecOps: Part 10/12: Branch Prot...  
GitHub: DevSecOps: Part 11/12: How to do Schedule pipeline in GitHub
   • GitHub: DevSecOps: Part 11/12: How to do S...  

▬▬▬▬▬▬ S U B S C R I B E 🔔 ▬▬▬▬▬▬
╔═╦╗╔╦╗╔═╦═╦╦╦╦╗╔═╗
║╚╣║║║╚╣╚╣╔╣╔╣║╚╣═╣
╠╗║╚╝║║╠╗║╚╣║║║║║═╣
╚═╩══╩═╩═╩═╩╝╚╩═╩═╝
   / @romanoroth  

▬▬▬▬▬▬ Connect with me 👋 ▬▬▬▬▬▬
LINKEDIN ►   / romanoroth  
TWITTER ►   / romanoroth  
INSTAGRAM ►   / romanoroth  
FACEBOOK ►  / romanoroth  
MEETUP ► https://www.meetup.com/de-DE/DevOps-M...
CONFERNCE ►https://www.devopsdays.ch/
HOMEPAGE ► https://www.romanoroth.com/

▬▬▬▬▬▬ P L A Y L I S T S ▶️ ▬▬▬▬▬▬
Modern Software Engineering
   • Modern Software Engineering  
DevOps
   • DevOps  
GitLab: Build a DevSecOps Pipeline
   • GitLab: Build a DevSecOps Pipeline  

#devsecops #devops #github #romanoroth