Skip to main content

Command Palette

Search for a command to run...

14 - Case Study - Implementazione End-to-End di DevSecOps Pipeline

Real startup: SAST + DAST + SCA + container scanning + secrets management + policy as code integrati in CI/CD. Timeline: 8 settimane, team di 2. Metri

Published
1 min readView as Markdown
F
Love coding and AI

Real startup: SAST + DAST + SCA + container scanning + secrets management + policy as code integrati in CI/CD. Timeline: 8 settimane, team di 2. Metriche: vulnerabilità rilevate, false positive rate, MTTR.

What you'll learn

  • How to plan a DevSecOps implementation from scratch
  • Complete technology stack with costs and alternatives
  • Detailed timeline of the 8-week implementation
  • Before and after metrics: vulnerabilities, MTTR, coverage
  • Real challenges and how they were resolved

This article is part of the DevSecOps series on federicocalo.dev.


Read the full article

The complete article (20 min read) with code examples, diagrams, and practical exercises is available here:

➡️ 14 - Case Study - Implementazione End-to-End di DevSecOps Pipeline

https://federicocalo.dev/en/blog/case-study-devsecops-pipeline-end-to-end


By Federico Calò — Software Developer & Technical Writer