π Security & DevSecOps
Ship safer software: shut down the OWASP Top 10, get authn/authz right, manage secrets, harden your supply chain and cloud, and bake security into the SDLC.
0/8
1Free2π3πβ
π Standard4π5π6πβ
π Standardππ Professional
Web app vulns & the OWASP Top 10
Shut down the web's most-exploited bugs β SQLi, XSS, broken access control, and SSRF β with the durable fixes attackers can't sidestep.
AuthN/AuthZ done right
Sessions vs tokens, OAuth2/OIDC without the pitfalls, airtight JWT validation, and least-privilege authorization enforced on the server.
Secrets management
Keep credentials out of Git and build logs, centralize them in a vault with audit and rotation, and prefer short-lived, dynamically issued creds.
Chapter review
Chapter 1 review β AppSec, identity & secrets
Lab: Find & fix the access-control and secret-in-repo issues Β· 10-question check
Supply-chain security
Inventory dependencies with SBOMs, sign artifacts with cosign, attest builds with SLSA provenance, scan with SCA, and pin sources to defeat confusion attacks.
Cloud & container hardening
Close the gaps attackers hunt for β public buckets, wildcard IAM, IMDS credential theft β and lock down containers: non-root, read-only FS, network policy.
Secure SDLC & threat modeling
Shift security left: threat-model with STRIDE and trust boundaries, wire SAST/DAST/SCA security gates into CI, and know the incident-response basics.
Chapter review
Chapter 2 review β supply chain, cloud & secure SDLC
Lab: Harden an image, add signing/SBOM, and wire a CI security gate Β· 10-question check
Final exam
Security & DevSecOps β comprehensive capstone
Hands-on capstone + course-wide exam Β· scored to a role level