Four Common Security Acronyms Explained

Editor’s Note: This is the first in a series of posts about the 2020 DevSecOps Reference Architecture developed by DJ Schleen. In this series DJ explains various parts of the pipeline architecture.
I just released an updated version of the D… Continue reading Four Common Security Acronyms Explained

The DevSecOps Landscape is Maturing – We Want to Hear About Your Journey

Time is running out to take part in Sonatype’s annual DevSecOps Community Survey. Share your stories with others in the space. The race to out-innovate one’s competition has led to high-performing organizations chasing increased deployment veloc… Continue reading The DevSecOps Landscape is Maturing – We Want to Hear About Your Journey

Get the Latest DevSecOps Reference Architecture

Since releasing the DevSecOps Reference Architecture last year I’ve received a ton of feedback from the community. I took the feedback and spent some time over the past several months to update the architecture to roll in some of the suggestions. … Continue reading Get the Latest DevSecOps Reference Architecture

Security Should Stop Being a Drag

About a year ago during my talk at the Nexus User Conference, and during a Virtual Session for RSA Conference APJ, I mentioned that a pipeline shouldn’t fail just because a security vulnerability was detected by scanning tools. That statemen… Continue reading Security Should Stop Being a Drag

A Sort of a Homecoming – Why I Joined Sonatype

Switching employers is usually a difficult transition filled with complex emotions, fear, and anxiety. I haven’t had any of these feelings as I start my journey at Sonatype. The timing is right, the culture is right, the tools are right, and I hav… Continue reading A Sort of a Homecoming – Why I Joined Sonatype

Security Organizations Need to Start Thinking Like Developers

Many years ago when I was studying architecture a professor once told the class that, as architects, if we designed a space that a contractor couldn’t fit a hammer into, our best designs would never be built. We needed to understand how our … Continue reading Security Organizations Need to Start Thinking Like Developers