Weekly DevSecOps Updates - Issue #7Andreas TiefenthalerDec 13, 2018ShareLinksA report from the security firm Detectify said that they analyzed public GitHub repositories and found more than 1,500 unique “access tokens”. 😱Two articles guiding you through the process of sitting up a security focused CI/CD pipeline. Not only making sure your code is secure, but also your pipeline.A compiled list of 23 Node.js security best practices (+40 other generic security practices) from all top-ranked articles around the globe.Named vulnerabilities and their practical impact. A quick reality check on the severity and exploitability of the big fuss names.WatchThe shift towards an API landscape indicates a significant evolution in the way we build applications.Tools and TechA perfect playground to learn more about application security. Great for training your co-workers or organising a capture the flag.HackEDU offers comprehensive online Secure Development Training for developers and engineers.A great free resource to get your