# Devsecops Shift Left

> Use when implementing DevSecOps and shift-left security.

- Skill: `loopyluci/devsecops-shift-left` (Agent Skill)
- Install (CLI): `npx skillmds@latest add loopyluci/devsecops-shift-left`
- Raw SKILL.md: https://api.skillmd.com/api/skills/loopyluci/devsecops-shift-left/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- License: MIT
- Author: LoopyLuci (https://skillmd.com/u/loopyluci)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/loopyluci/devsecops-shift-left

---


# DevSecOps and Shift-Left Security

Implementing DevSecOps practices — from SAST/DAST/SCA scanning in CI through threat modeling, secrets detection, and security champions program.

## When to Use

- Integrating security into development workflows
- Shifting security testing left (earlier in development)
- Automating vulnerability scanning in CI/CD
- Building security champions culture

## DevSecOps Tools

```python
DEVSECOPS_TOOLS = {
    'sast': 'Static Analysis — Semgrep, SonarQube, CodeQL — find vulnerabilities in source code',
    'dast': 'Dynamic Analysis — OWASP ZAP, Burp Suite — test running applications',
    'sca': 'Software Composition Analysis — Dependabot, Snyk, Trivy — dependency vulnerabilities',
    'secrets': 'Secret detection — GitGuardian, truffleHog, Gitleaks — prevent credential leaks',
    'container_scan': 'Image scanning — Trivy, Grype, Clair — vulnerabilities in container images',
}

class DevSecOpsPipeline:
    """Security gates in CI/CD pipeline."""
    def __init__(self):
        self.gates = []
    
    def add_gate(self, name: str, tool: str, fail_on: str = 'critical'):
        self.gates.append({'name': name, 'tool': tool, 'fail_on': fail_on})
    
    def run_gates(self):
        results = {}
        for gate in self.gates:
            results[gate['name']] = self._execute(gate['tool'], gate['fail_on'])
        return results
```

## Verification Checklist

- [ ] SAST scanning in PR pipeline (fail on critical findings)
- [ ] SCA/dependency scanning automated (alert on new CVEs)
- [ ] Secrets scanning in pre-commit hooks and CI
- [ ] DAST scheduled for deployed applications
- [ ] Container image scanning in CI
- [ ] Threat modeling for new features (STRIDE)
- [ ] Security champions program across development teams
- [ ] Security training for developers (OWASP Top 10)

