About
DevSecOps Practice Hub is a reference and practice portal for DevSecOps engineers, developers, system administrators, cloud engineers and security professionals. It is a catalog, not a marketing site: every practice page states what the control is, where it sits in the delivery lifecycle, which tools implement it, and what the common implementation mistakes are.
Code examples are illustrative starting points. They are not production-ready configuration — thresholds, exclusions and failure modes must be calibrated to your own environment before enforcement.
- Practices
- 48
- Security Tools
- 29
- Patterns
- 11
- Hands-On Labs
- 10
- Pipelines
- 10
- Technologies
- 30
How the content is structured
Content is stored as typed data separate from the UI, in src/data/: practices, tools, labs, patterns and pipelines. Adding a new practice means adding one data entry — no new page or component is required, and every catalog, filter, search result and detail page picks it up automatically.
Contribute
Contributions are welcome for new practices, tool entries, hands-on labs, pipeline examples and security patterns. Keep descriptions factual, avoid vendor claims, and include a working example where the practice allows one.
License & AI Disclosure
Created by Wang Yuen — wangyuen.linkedin@gmail.com
This project contains code and model weights released under the Apache License 2.0.
- Code: Licensed under Apache 2.0.
- Model Weights: Licensed under Apache 2.0.
- Generated Assets: All images and text outputs in the
/samplesdirectory were generated or modified using generative AI and are dedicated to the public domain under CC0 1.0.