PROPELOO

DEVSECOPS / SECURITY IN THE PIPELINE

Find security issues in the CI pipeline, not in the production incident.

PROPELOO implements DevSecOps pipelines — integrating SAST, DAST, dependency scanning, container scanning, secrets detection and IaC security checks into CI/CD so security issues are caught before code reaches production. Security shifted left is security that is 10x cheaper to fix.

A security vulnerability found in code review costs hours to fix. The same vulnerability found in production costs weeks and potentially headlines.

The cost of fixing a security vulnerability scales exponentially with how late it is found. A SQL injection found by a developer during code review: 30 minutes to fix. The same issue found by a penetration tester before launch: 2 days (fix + retest). The same issue exploited in production: weeks of incident response, forensic analysis, customer notification, regulatory reporting and reputational damage. DevSecOps shifts security left — automated security checks in the CI pipeline catch vulnerabilities when the cost of fixing them is lowest. PROPELOO implements the full DevSecOps toolkit: SAST for code vulnerabilities, dependency scanning for known CVEs, secrets scanning for accidental credential commits, container scanning for vulnerable base images and IaC scanning for cloud misconfigurations.

The DevSecOps pipeline.

System Layers

  • Commit Layer: Pre-commit hooks: secrets scanning, linting, basic SAST
  • CI Layer: Full SAST, dependency scanning, license compliance, test coverage enforcement
  • Build Layer: Container image scanning, base image validation, signed image attestation
  • Deploy Layer: IaC security scanning, Kubernetes admission policies, environment config validation
  • Runtime Layer: DAST against staging, runtime container security (Falco), security monitoring

Core Technical Capabilities

  • SAST (Static Application Security Testing)

    Semgrep with custom rules for language-specific vulnerabilities, CodeQL for complex dataflow analysis, ESLint security plugins (eslint-plugin-security), Bandit for Python. Runs on every PR, blocks merge on critical findings.

  • Dependency Scanning

    Dependabot or Renovate for automated dependency updates, Snyk or OWASP Dependency-Check for CVE scanning, license compliance checking (GPL contamination detection) and outdated dependency alerts.

  • Secrets Detection

    Gitleaks or TruffleHog in pre-commit hooks and CI pipeline — detect accidentally committed API keys, passwords, tokens and private keys before they reach the repository or are distributed in builds.

  • Container Security

    Trivy for container image vulnerability scanning, base image validation (only approved base images), Dockerfile linting with hadolint, non-root user enforcement and minimal base image policy.

  • IaC Security Scanning

    Checkov or tfsec for Terraform security checks — identify S3 buckets without encryption, security groups open to 0.0.0.0/0, unencrypted databases, missing VPC Flow Logs. Blocks infrastructure PRs with critical findings.

  • DAST (Dynamic Testing)

    OWASP ZAP or Nuclei automated scans against staging environment on every deployment — active testing for injection, XSS, authentication issues and misconfigurations in the running application.

How we think about DevSecOps.

Security in the pipeline is only valuable if it does not slow down the developer. Every security gate must be fast enough (under 5 minutes) and accurate enough (low false positive rate) that developers treat it as signal, not noise.

  • Pipeline speed is security effectiveness

    A security scan that takes 20 minutes will be bypassed or ignored. Developers push code, the scan runs, they have moved on. The result is reviewed by nobody. A scan that runs in 3 minutes and blocks the PR immediately creates a loop that developers actually respond to.

    Axiom:

  • False positives destroy security culture

    A SAST tool that generates 200 findings per PR, 180 of which are false positives, trains developers to ignore the tool. Security findings that are routinely dismissed become security issues that are routinely missed. Tune tools, write suppression rules and configure thresholds so only actionable findings are surfaced.

    Axiom:

  • Secrets in git are permanent

    A credential committed to git and pushed — even briefly, even to a private repository — should be rotated immediately. It may already be in a CI log, a developer's local clone, an IDE history or a git mirror service. Secrets detection in pre-commit hooks catches the mistake before the push. Secrets detection in CI is the last line of defence.

    Axiom:

  • Container scanning at build time prevents runtime surprises

    A container image with a critical CVE that is scanned and blocked at build time costs 30 minutes to fix (update base image, rebuild). The same CVE discovered in a production container after a security audit costs days of emergency patching, change management processes and potential regulatory reporting.

    Axiom:

DevSecOps toolchain decisions.

  • SAST tool?

    Impact: Semgrep for most projects — fast, accurate, customisable, free. CodeQL for complex dataflow vulnerabilities in critical paths. Enterprise tools (Checkmarx) only if compliance requires their specific certifications.

    • Semgrep — fast, custom rules, multi-language, free tier
    • CodeQL — deep dataflow analysis, GitHub-native, slower
    • Checkmarx / Veracode — enterprise, comprehensive, expensive
    • SonarQube — code quality + security, good for Java/.NET shops
  • Dependency scanning?

    Impact: Dependabot for automated dependency updates (free, GitHub-native). Snyk for richer vulnerability context and developer-facing fixes. Both together for comprehensive coverage.

    • Dependabot (GitHub) — free, automated PRs, GitHub-native
    • Snyk — comprehensive, developer-friendly, cost at scale
    • OWASP Dependency-Check — open source, self-hosted
    • npm audit / pip audit — built-in, limited
  • Container scanning?

    Impact: Trivy as the default — open source, fast, covers OS packages and language package vulnerabilities. Integrate into GitHub Actions and ECR push events.

    • Trivy — fast, free, comprehensive (OS + language packages)
    • Snyk Container — developer-friendly output, cost at scale
    • AWS ECR scanning — native for ECR users, less comprehensive
    • Anchore — comprehensive, self-hosted, more complex
  • Secrets scanning placement?

    Impact: Both pre-commit (Gitleaks via Husky/pre-commit framework) and CI (Gitleaks in GitHub Actions). Pre-commit catches before push; CI is the safety net.

    • Pre-commit hook only — catches before push, can be bypassed
    • CI only — catches in pipeline, after push to repo
    • Both pre-commit + CI — defence in depth, recommended
    • None — the most common mistake in small teams
  • IaC scanning?

    Impact: Checkov for most IaC scanning — wide coverage, active development, integrates with Terraform Cloud and GitHub Actions.

    • Checkov — comprehensive, 1000+ checks, Terraform + K8s + CloudFormation
    • tfsec — Terraform-focused, fast, simpler rule set
    • Terrascan — multi-cloud, policy-as-code
    • KICS — Kubernetes + Terraform + others
  • DAST integration?

    Impact: Nuclei for most CI DAST — fast, templated scans of known vulnerability patterns. OWASP ZAP for more comprehensive passive and active scanning with longer CI windows (nightly).

    • OWASP ZAP — open source, comprehensive, slower
    • Nuclei — fast, template-based, modern
    • Burp Suite (CI mode) — professional, expensive
    • No DAST — missing runtime vulnerability class

What PROPELOO implements.

  • CI Security Pipeline

    Full DevSecOps pipeline: SAST, dependency scan, secrets detection, container scan, IaC scan — all running on every PR with configured severity thresholds.

  • GitHub Actions Security

    Security-hardened GitHub Actions workflows — pinned action versions, OIDC for cloud auth, minimal permissions, secret scanning and protected branch enforcement.

  • Container Security Programme

    Base image standardisation, Trivy scanning on build, distroless migration for production images, Kubernetes admission policies blocking non-compliant images.

  • IaC Security Gates

    Checkov in CI blocking Terraform PRs with critical security findings — public S3, unencrypted RDS, open security groups — before infrastructure is deployed.

  • Secrets Management Migration

    Audit existing repositories for committed secrets, rotate all found credentials, implement pre-commit + CI secrets scanning and migrate to Secrets Manager.

  • SOC2 Pipeline Evidence

    DevSecOps pipeline configured to produce evidence for SOC2 CC6-CC8 controls — code review documentation, vulnerability scanning records and access control audit logs.

The DevSecOps toolchain.

  • SAST

    Stack: Semgrep, CodeQL, ESLint security, Bandit (Python), gosec (Go)

  • Dependency Scanning

    Stack: Dependabot, Snyk, OWASP Dependency-Check, npm audit, Trivy (language packages)

  • Secrets Detection

    Stack: Gitleaks, TruffleHog, detect-secrets, GitHub secret scanning

  • Container Security

    Stack: Trivy, Hadolint (Dockerfile lint), Dockle, Falco (runtime), OPA/Gatekeeper

  • IaC Security

    Stack: Checkov, tfsec, KICS, Terrascan, AWS Config

  • DAST

    Stack: OWASP ZAP, Nuclei, Nikto, Burp Suite CI

DevSecOps is the security programme, not a feature.

  • Supply chain security

    Pin GitHub Action versions to commit SHA, not floating tags. Verify action integrity with attestation. Minimal permissions (GITHUB_TOKEN scope). OIDC for cloud authentication instead of stored credentials.

  • Scanning accuracy

    Tune SAST rules to your codebase — reduce false positive rate below 20% so findings are investigated. Document suppressed findings with justification. Review suppression list quarterly.

  • Security finding SLAs

    Critical: blocked in CI, must be fixed before merge. High: 7-day remediation SLA. Medium: 30 days. Low: next sprint. SLAs create accountability and prevent security debt accumulation.

  • Branch protection

    Main branch protection: required status checks (security scans must pass), required code review, dismiss stale reviews, require signed commits. No direct pushes to main from any account.

  • Audit logging

    CI/CD system audit logs: who triggered builds, what was deployed, which approvals were given, when secrets were accessed. Required for SOC2, PCI DSS and HIPAA compliance evidence.

  • Vulnerability disclosure process

    Published security.txt with contact for responsible disclosure, defined triage process for externally reported vulnerabilities and response SLA commitments.

Implementing DevSecOps.

  1. 01. Current State Audit

    Assess existing pipeline, identify security gaps, prioritise by risk and effort.

  2. 02. Secrets Cleanup

    Scan all repositories for committed secrets, rotate found credentials, implement pre-commit hooks.

  3. 03. Dependency Scanning

    Dependabot + Snyk integration, existing vulnerability triage, remediation SLA definition.

  4. 04. SAST Integration

    Semgrep in CI, rule tuning to reduce false positives, severity thresholds, PR blocking configuration.

  5. 05. Container Security

    Trivy in CI build pipeline, base image standardisation, Hadolint Dockerfile linting.

  6. 06. IaC & Runtime

    Checkov for Terraform, Falco for runtime, OPA admission policies.

  7. 07. Training & Culture

    Developer security training, security champion programme, monthly vulnerability review.

Frequently Asked Questions

Won't security checks slow down our CI pipeline?

With proper tool selection and configuration: Semgrep runs in 30-90 seconds, Trivy in 30-60 seconds, Gitleaks in 5-10 seconds, tfsec in 10-20 seconds. Total security pipeline addition: 2-3 minutes. The key is selecting fast tools (Semgrep over slower tools) and running checks in parallel. A 3-minute security gate that catches critical vulnerabilities is a good trade.

How do we handle false positives?

False positives are managed via suppression rules with justification comments in code, configuration of rule severity thresholds, and regular review of suppressed findings. The goal is a false positive rate below 20% — meaning 80%+ of findings are genuine issues. Higher false positive rates train developers to ignore the tool.

What is SAST vs DAST?

SAST (Static Application Security Testing) analyses source code without running it — finds SQL injection patterns, hardcoded secrets, dangerous function calls. Fast, runs in CI on every commit. DAST (Dynamic Application Security Testing) tests the running application — sends malicious requests, checks for XSS, injection, authentication issues. Slower, runs against staging. Both find different vulnerability classes and are complementary.

What compliance frameworks does DevSecOps support?

SOC2: CC6 (logical access), CC7 (change management), CC8 (risk assessment) all have evidence requirements that DevSecOps pipeline logs satisfy. PCI DSS: Requirement 6 (secure development) requires vulnerability scanning. ISO 27001: A.14 (system acquisition, development, maintenance) requires security in SDLC. HIPAA Security Rule: technical safeguards for systems processing PHI.