Cyberlium

Secure › Module 10 › Lesson 3

BeginnerModule 10Lesson 3/5

Pipeline Sketch

Draw secure SDLC pipeline — SAST, gitleaks, deps, DAST on YOUR $REPO CI.

15 min+40 XP3 quiz
Module progress3 of 5

Visual · t17_pipeline_sketch

Pipeline sketch = shift-left controls on code you ship. Original Cyberlium.

Opening

One diagram beats ten slides if it shows where security actually runs in YOUR workflow.

Sketch CI/CD pipeline for $REPO: commit → lint/unit → SAST → gitleaks → dependency audit → build → deploy to $LAB_URL → optional DAST baseline against lab deploy. Mark manual gates: code review, triage, rotation on leak. Note what runs on PR vs main vs nightly. Paper or Mermaid in private notes — no copying employer pipeline internals without permission. Gap paragraph: what fails open if you skip gitleaks or deps.

1. Stages

PR: fast SAST + gitleaks + tests. Main: build + deploy lab. Nightly: DAST baseline + deep audit.

Block merge on critical SAST/leak per policy from Module 7.

Command guide

Try these commands — Stages

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

DevSecOps — https://owasp.org/www-project-developer-guide/ NIST SSDF — https://csrc.nist.gov/publications/detail/sp/800-218/final

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install curl

macOS: Built-in

Windows: Built-in (PowerShell: Invoke-WebRequest)

═══ LINUX / macOS ═══

Command — copy this

grep -E 'lint|SAST|DAST' "$HOME/cyberlium-lab/t17-sdlc-notes.txt" 2>/dev/null || echo 'Pipeline: lint -> SAST -> test -> DAST(127.0.0.1) -> deploy'
curl -sS https://owasp.org/www-project-developer-guide/ | head -5

Primary tools to practice this lesson: grep, curl. Reference sites: DevSecOps (https://owasp.org/www-project-developer-guide/); NIST SSDF (https://csrc.nist.gov/publications/detail/sp/800-218/final). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Human gates

Review for auth/session changes; triage new SAST rules; rotation drill quarterly.

OAuth app registrations listed with revoke on teardown.

3. Gap honesty

Mark N/A stages honestly — gap plan on YOUR bench, not stranger targets.

No filler with unauthorized scans.

4. What you ship: pipeline sketch

Diagram with SAST/gitleaks/deps/DAST stages + gap paragraph.

5. What you record before the next lesson

Pipeline sketch path.

6. Wrong vs right: stranger apps vs YOUR repo

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Sketch includes 'DAST prod stranger nightly.'

  • Right

    Pipeline sketch done. Next: capstone lab.

Mission: pipeline sketch

1) Draw stages from commit to lab deploy. 2) Mark PR vs nightly jobs. 3) One paragraph gaps if steps skipped.

Stuck? Ask Cyberlium AI Mentor

Ask Mentor: “DAST pre-prod vs lab URL?”

Knowledge Check

1

APPLY: Pipeline sketch shows:

Multiple choice

Knowledge Check

2

APPLY: True or False: Stranger prod DAST in sketch is OK.

True or False

Knowledge Check

3

APPLY: Gap paragraph names:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)