In DevSecOps, while SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), and SCA (Software Composition Analysis) are commonly used in the CI (Continuous Integration) pipeline, the CD (Continuous Delivery/Deployment) pipeline focuses on security controls for the post-build, deployment, and production stages.

Common DevSecOps Security Tools Used in the CD Pipeline

Example Flow

  1. CI Pipeline : SAST, DAST, SCA tools check code security.
  2. CD Pipeline:-