I will build a secure devsecops ci cd pipeline with trivy, semgrep and cosign
Platform Engineer and SRE, Kubernetes, GitOps, DevSecOps
About this Gig
Catch leaked secrets and vulnerable dependencies before they reach production.
I'll add a shift-left security gate to your GitHub Actions, GitLab CI, Azure DevOps or Tekton pipeline. It runs SAST (Semgrep), secret detection (Gitleaks), image and dependency scanning (Trivy, OWASP Dependency-Check), and signs your images with Cosign. Anything High or Critical blocks promotion automatically.
I run this exact setup in production today, gating every release.
What you get:
- Pipeline YAML with security stages
- Tuned rules to cut false positives
- SBOM generation and signed, attested images
- Centralized findings dashboard (Premium)
- Docs for your team
Please message me before ordering with your CI tool, repo count and container registry.
Tools:
Docker
•
GitHub
Frameworks:
Terraform
•
Ansible
Cloud Provider:
Amazon Web Services
•
Microsoft Azure
Programming language:
Bash
•
Python
Expertise:
Installation
•
Development
•
Configuration
My Portfolio
Other DevOps Engineering Services I Offer
FAQ
Which CI/CD tools do you support?
GitHub Actions, GitLab CI, Azure DevOps and Tekton. Others on request, just message me first.
Will the scans slow down my builds?
Scans run in parallel where possible and use caching, so most pipelines add only a few minutes.
