<?xml version="1.0"?>
<metadata xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/"><dc:title>Managing DevSecOps pipeline on Azure DevOps portal</dc:title><dc:creator>Bizjak,	Alen	(Avtor)
	</dc:creator><dc:creator>Lavbič,	Dejan	(Mentor)
	</dc:creator><dc:subject>Azure DevOps portal</dc:subject><dc:subject>software engineering</dc:subject><dc:subject>DevOps</dc:subject><dc:subject>DevSecOps</dc:subject><dc:description>DevSecOps (Development, Security and Operations) is an extension of DevOps (Development and Operations) that aims at adding security and security testing to the entire development process, which is traditionally neglected in DevOps practices that are more focused on rapid and agile development lifecycle. An important goal of DevSecOps is, therefore, to keep up with the speed of CI/CD pipelines while adding meaningful benefits in the form of increased security. In our work, we implemented a DevSecOps pipeline by starting with a baseline CI/CD pipeline that built our testing application from source code and deployed it to our virtual server. We then transformed this pipeline into the DevSecOps pipeline by including in it Static Application Security Testing (SAST) tools and Dynamic Application Security Testing (DAST) tools. The selection of tools used was inspired by existing studies. We expanded on related works by including other features in our pipeline, such as parsing the results of tools and using those results to develop configurable pipeline build breakers, using Azure caching to speed up the pipeline and more. The resulting pipeline is shown to be able to detect vulnerabilities in the deployed application and it adheres to one of the most important DevOps goals, which is fast execution time.</dc:description><dc:date>2023</dc:date><dc:date>2023-04-07 10:55:00</dc:date><dc:type>Magistrsko delo/naloga</dc:type><dc:identifier>145136</dc:identifier><dc:identifier>VisID: 35328</dc:identifier><dc:identifier>COBISS_ID: 149827075</dc:identifier><dc:language>sl</dc:language></metadata>
