devsecops
Safeguard articles tagged "devsecops" — guides, analysis, and best practices for software supply chain and application security.
100 articles
CI Secret Masking Matches the Exact String, and Almost Nothing Else
Encode it, uppercase it, split it across two log lines, and masking has nothing to match against. This is not a bug in any platform. It is the only mechanism possible without semantic analysis of every command a pipeline runs.
A Required Approval Proves a Button Was Clicked, Not That Anyone Read the Code
Branch protection requires review before merge. Your audit evidence shows one on every pull request for a year. It does not show whether any of them involved a person reading the diff, and for a meaningful share, they did not.
You Tested a Different Artefact Than the One You Shipped
Tests pass against a build with debug assertions, development dependencies and verbose errors. You then ship something compiled differently, with a different dependency set, that behaves differently when something goes wrong.
A Self-Hosted Runner Is a Machine on Your Network That Runs Strangers' Code
A hosted runner is destroyed after the job. A self-hosted one persists, on your network, executing code from your repository, and if that repository accepts contributions the code is not always yours.
Which Changes Should Trigger a Security Review
Asking developers to involve security when it seems relevant fails in both directions, because relevance requires exactly the expertise the person does not have. Give them observable properties instead.
A Feature Flag That Disables a Control Is a Control You Do Not Have
Added during an incident to skip a validation or bypass a limit, intended to be reverted that afternoon, and nothing reminds anyone. It lives in a system with weaker access control and no change record than your permission model.
Your ChatOps Bot Is an Admin API Nobody Reviewed
It deploys, restarts, queries production and rotates keys, and the authorization check is whether the person is in the channel. It became powerful one useful command at a time, and none of them got the review a new admin API would have.
When Automated Agents Share One Deploy Lock
Three agents, one lock, every one of them correct in isolation. The service restarts every few minutes for an hour and there is no bug to find, because the harmful behaviour only exists in aggregate.
Is It Working or Is It Stuck? Long-Running Jobs Need a Progress Signal
CPU, connection counts, process liveness and log volume are all proxies that decouple from reality in exactly the case you are trying to detect. One timestamp fixes it: when the last unit of work completed.
Your CI Job Is Not Hung, It Is Slower Than Your Timeout
A timeout kills a process and loses its buffered output, so a suite that needed eleven minutes looks exactly like a deadlock. How to tell them apart, the defaults that catch people, and why a killed scan must never count as a pass.
The Dockerfile in Your Repository Is Probably Not What Builds
An urgent fix gets made on the build host, the backport never happens, and the repository copy becomes a historical document. Absent files prompt questions; stale ones answer them wrongly.
Your Deploy Kills Long-Running Jobs. Drain Instead.
SIGKILL after a ten second grace period destroys a twenty minute job and leaves its row marked RUNNING forever. Three drain strategies, the four ways they get undermined, and what to tell the user when one is lost anyway.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.