
Launch a hands-on DevSecOps journey with GitLab, building an end-to-end secure continuous integration and delivery pipeline featuring SAST, SCA, and DAST, SonarCloud integration, and pipeline variables for secrets.
Introduce freshers and security engineers to the DevSecOps field, highlight the strong demand and salary potential, and show how upskilling in secure CI/CD with GitLab drives career growth.
Explore core security terms such as SAST, SCA, DEST, and IEC, including infrastructure as code testing, API security, and microservices concepts.
Explore how DevSecOps integrates development, security, and operations with a shift-left approach, implementing security early in the software development lifecycle, securing containers, and enforcing PCI DSS standards.
Explore enterprise devsecops tools, from git secrets and IDE security plugins to build pipelines, container and cloud security, and cloud security posture management with GitLab.
Import vulnerable code from GitHub into GitLab, create a .gitlab-ci.yml, and implement a DevSecOps pipeline with SAS, C and Das tools for logs and artifacts.
Create a GitLab free tier account and start a 30-day ultimate trial, choosing between SaaS and self-managed deployments, linking via Google or GitHub login, with the trial ending August 14.
Import an intentionally vulnerable Java application from GitHub into GitLab by authorizing GitLab to access GitHub, and create a new project under groups or subgroups to integrate security tools.
Create and set the master branch as the default for your GitLab repository, then delete the main branch, enabling sonar cloud analysis and streamlined DevSecOps workflows.
Define a .gitlab-ci.yml in your GitLab repo, add stages and a print text job using echo to display a message on the console, showcasing a devsecops pipeline on shared runners.
Explore SonarCloud, a cloud-based service that guards code quality and security. Set quality gates, track code coverage, and integrate checks via APIs.
Create a SonarCloud account using GitHub authentication, access the dashboard, and prepare your projects before implementing SAST in the DevSecOps pipeline.
Integrate SonarCloud in a GitLab DevSecOps pipeline to run static application security testing with Maven and OpenJDK, configuring organization, project key, and login token.
Create a custom quality gate in sonar cloud to block the GitLab DevSecOps pipeline when code coverage falls below 90% or security issues are detected.
Implement and validate quality gates in a DevSecOps pipeline with SonarCloud and GitLab CI. Observe the SonarCloud dashboard to evaluate coverage, quality gates, and pipeline outcomes.
Populate unit test code coverage on the sonar cloud dashboard by adding the g unit plugin, cocoa maven plugin, test folder tests, and enabling the maven verify goal in ci.
Explore how Snake security tools, a software as a service, identify security issues in source code, open source libraries, and cloud infrastructure templates, covering sast and software composition analysis.
Sign up for Snake to perform software composition analysis in a DevSecOps pipeline, using GitHub authentication and SCA to identify security issues in third-party libraries such as Log Forge.
Integrate Snyk software composition analysis into a GitLab devsecops pipeline by configuring the Maven plugin, setting a token as an environment variable, and running an SCA scan for vulnerabilities.
Learn about OWASP ZAP, an open source web application security scanner from the Open Web Application Security Project, and its ability to scan web apps and API specifications.
Integrate OWASP ZAP into a GitLab DevSecOps pipeline to perform DAST scans, generate ZAP reports, and publish artifacts for secure CI/CD.
Describe an end-to-end DevSecOps pipeline in GitLab that triggers on Java commits, runs SonarCloud sast, conducts software composition analysis, and uses owasp zap dast with Jira reporting.
Implement an end-to-end devsecops pipeline for a Java project using GitLab, integrating SAST, SCA, and DAST with SonarCloud, Snake, and ZAP.
Run an end-to-end devsecops pipeline for a Java project in GitLab, review logs across sast, sca, and dast stages, and inspect security findings.
Create a free Jira account with Atlassian using Google sign-in, then set up a custom security guru site and a DevSecOps project for reporting security issues to developers.
Report a high-severity SAST security issue (command injection) found by SonarCloud in a Java file as a JIRA bug, detailing file path, vulnerable function, and commit ID to guide developers.
Learn to report a security issue found during a C scan using Snake in Jira, including scan details, vulnerable path, and upgrading Morgan from 1.9.0 to 1.9.1 to fix injection.
Report a medium-severity dynamic application security testing issue on http example dot com using zap, x frame options header not set, documented in jira with description, mitigation, and references.
Integrate SonarCloud with Jira to create tickets with one click from security findings. Configure the cube connector, align global and project settings, and map issues to Jira types.
Explore GitLab's SAST and DAST analyzers and learn why to use them in secure DevSecOps pipelines, including built-in integration, OWASP-based testing, cost savings, and language support.
Integrate GitLab's built-in SAST and DAST analyses in a devsecops pipeline using GitLab Ultimate, with templates and CI configurations to run these scans.
Run a DevSecOps pipeline with SAST and DAST analyses from GitLab, review scan reports and artifacts, and interpret vulnerabilities identified by SEM Grip and ZAP within the GitLab environment.
Explore various information security career paths, from devsecops and cloud penetration testing to continuous security, security architecture and design, web and mobile penetration testing, and cloud security and compliance.
Students can enroll themselves in our other courses at discounted rates. View Resources section for more information.
Course Updates:
v5.0 - May 2026
Updated course repo with latest code changes
v 4.0 - May 2024
Added DevSecOps Handbook document in Section 10
v 3.0 - Jan 2024
Updated GitHub Repos in all sections to install Java 17 runner and to use sonar.token instead of sonar.login
Updated course with OWASP ZAP 2.14.0 version
v 2.0 - Feb 2023
Updated course with newer videos on Quality Gates in DevSecOps pipelines using SonarCloud/SonarQube in Section 4
Updated course with newer videos on Integrate JIRA with SonarCloud/SonarQube
Added Assignments and Quizzes to the course
v 1.0 - Feb 2023
Updated course with newer videos on SAST and DAST Analyzers by GitLab
Who shall take this course?
This "DevSecOps with GitLab" course is designed for Security Engineers, DevOps Engineers, SRE, QA Professionals and Freshers looking to find a job in the field of security. This is a focused GitLab DevSecOps course with a special focus on integrating SAST/SCA/DAST tools in Build pipeline.
Learn and implement security in DevOps pipeline, get Hands On experience in using Security tools & technologies.
This course is for:
Developers
DevOps
Security Engineers
Aspiring professional in the Security domain
Quality Assurance Engineers
InfoSec/AppSec Professional
DevSecOps being the hot skill, will help you to secure a high-salaried job and stay informed on the latest market trends.
Why purchase this course?
This is only practical hands-on course available on the internet till now.
DevSecOps enables rapid application development with agility, at the same time it secures your application with automated security checks integrated within the pipeline. It helps to increase productivity and security by integrating security stages in the pipeline.
Also, we have included practical examples to implement security in the DevOps pipeline through various tools.
By the end of the course, you will be able to successfully implement DevOps or DevSecOps pipeline and lead initiatives to create, build and maintain security pipelines in your project.
No Action required before taking this course. For any question or concerns, Please post your comments on discussions tab
Disclaimer: English subtitles are auto-generated so please ignore any grammar mistakes