Further reading
The following readings offer further insights and best practices regarding DevSecOps in AWS:
- Building end-to-end AWS DevSecOps CI/CD pipeline with open source SCA, SAST and DAST tools by Srinivas Manepalli (2021): https://aws.amazon.com/blogs/devops/building-end-to-end-aws-devsecops-ci-cd-pipeline-with-open-source-sca-sast-and-dast-tools
- Use the Snyk CLI to scan Python packages using AWS CodeCommit, AWS CodePipeline, and AWS CodeBuild by BK Das (2021): https://aws.amazon.com/blogs/devops/snyk-cli-scan-python-codecommit-codepipeline-codebuild
- Integrating and automating security into a DevSecOps model by Deloitte: https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-integrating-and-automating-security-into-a-devsecops-model.pdf
- Introduction to DevSecOps with AWS: How to Integrate Security into DevOps by Apriorit (2022): https://www.apriorit.com/dev-blog/530-delivering-devsecops-aws