This repo is used for testing DevSecOps practices and toolsets, and is used for demonstration purposes only.
This repo contains code that is purposefully vulnerable and insecure. Use at your own risk!
The following YAML-based Azure DevOps (ADO) pipelines have been created and tested:
- APP
- DATA
- PENDING
- INFRA
- SEC
The following YAML-based GitHub Actions (GHA) Workflows have been created and tested:
- APP
- DATA
- PENDING
- INFRA
- SEC
- Add examples for:
- Dockle
- Docker Bench for Security
- DockerDive
- DockerSlim