International Journal of Science and Research (IJSR)

International Journal of Science and Research (IJSR)
Call for Papers | Fully Refereed | Open Access | Double Blind Peer Reviewed

ISSN: 2319-7064

DevSecOps Automation: SAST/DAST Integration in GitLab CI/CD with Semgrep, OWASP ZAP, and Dependency-Check

Sandhya Guduru

Abstract: As software development accelerates, integrating security into continuous integration and continuous deployment (CI/CD) pipelines is essential. This paper explores the automation of security testing in GitLab CI/CD by embedding Static Application Security Testing (SAST) with Semgrep, Dynamic Application Security Testing (DAST) with OWASP ZAP, and Software Bill of Materials (SBOM) generation with Dependency-Check. These tools enable early vulnerability detection, reducing security risks in production. The implementation of SLSA scorecards is also examined to assess software supply chain security and Kubernetes admission controllers to enforce security policies by blocking vulnerable builds. Automating these security measures can enhance application security without compromising development speed. This paper highlights best practices for securing DevSecOps pipelines effectively.

Keywords: DevSecOps Automation, CI/CD Security, GitLab CI/CD, SBOM analysis, SAST and DAST, OWASP ZAP, Dependency-Check, Kubernetes admission controllers

How to Cite?: Sandhya Guduru, "DevSecOps Automation: SAST/DAST Integration in GitLab CI/CD with Semgrep, OWASP ZAP, and Dependency-Check", Volume 9 Issue 12, December 2020, International Journal of Science and Research (IJSR), Pages: 1893-1898, https://www.ijsr.net/getabstract.php?paperid=SR20127082903, DOI: https://dx.doi.org/10.21275/SR20127082903

Download Citation: APA | MLA | BibTeX | EndNote | RefMan

Share This Research

Help this article reach readers, researchers and professionals.

Share activity is measured for research-engagement analytics. Only verified, unique public shares can support award tie-breaking.

Confirm Your Share

Enter your details so IJSR can confirm this sharing activity.

Your details are used to validate this share and protect the award process from duplicate or false activity.

Download Article PDF


Rate This Article!

Top

Confirm Your Share

Enter your details so IJSR can confirm this sharing activity.

Your details are used to validate this share and protect the award process from duplicate or false activity.