---
title: "devsecops"
author: "Mohammad Abu Mattar"
canonical: https://mkabumattar.com/blog/categories/devsecops
---

[Home](/)›[All Posts](/blog)›[All Categories](/blog/categories)›[Devsecops](/blog/categories/devsecops)

Category

# devsecops

4Articles

[![What's the Deal with Shift-Left Security, and Why Should You Care?](/_astro/hero.xI_32nOg_3BHjK.webp)](/blog/post/shift-left-security-sast-dast-sca-cicd)

## [What's the Deal with Shift-Left Security, and Why Should You Care?](/blog/post/shift-left-security-sast-dast-sca-cicd)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [CI/CD](/blog/categories/cicd)
-   [DevSecOps](/blog/categories/devsecops)
-   [Security](/blog/categories/security)
-   [Automation](/blog/categories/automation)
-   [Application Security](/blog/categories/application-security)
-   Published: 24 Jan, 2026

Let's be honest: in today's software world, security can't be an afterthought. If you're still waiting until the end of your development cycle to think about vulnerabilities, you're doing it wrong. Th

[#Shift Left Security](/blog/tags/shift-left-security)[#SAST](/blog/tags/sast)[#DAST](/blog/tags/dast)+7 tags

[read more](/blog/post/shift-left-security-sast-dast-sca-cicd)

[![Container Image Signing with Cosign: A Hands-On Guide to Secure Your Supply Chain](/_astro/hero.eolo66hS_Z1Eh5SE.webp)](/blog/post/container-image-signing-cosign-guide)

## [Container Image Signing with Cosign: A Hands-On Guide to Secure Your Supply Chain](/blog/post/container-image-signing-cosign-guide)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [Security](/blog/categories/security)
-   [Supply Chain Security](/blog/categories/supply-chain-security)
-   [Containers](/blog/categories/containers)
-   [DevSecOps](/blog/categories/devsecops)
-   Published: 18 Jan, 2026

In today's fast-paced software world, we all rely on container images to package and run our apps. They're super consistent and efficient, which is great! But this ease also brings new security headac

[#Cosign](/blog/tags/cosign)[#Sigstore](/blog/tags/sigstore)[#Container Signing](/blog/tags/container-signing)+4 tags

[read more](/blog/post/container-image-signing-cosign-guide)

[![The Democratization of Container Security: Docker Hardened Images](/_astro/hero.CPmb6ixV_1X6DeU.webp)](/blog/post/democratization-docker-hardened-images-container-security)

## [The Democratization of Container Security: Docker Hardened Images](/blog/post/democratization-docker-hardened-images-container-security)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [Docker](/blog/categories/docker)
-   [Container Security](/blog/categories/container-security)
-   [DevSecOps](/blog/categories/devsecops)
-   [Supply Chain Security](/blog/categories/supply-chain-security)
-   Published: 19 Dec, 2025

On December 17, 2025, the world of container security changed in a big way. Docker decided to open up its entire catalog of over 1,000 Docker Hardened Images (DHI) to everyone under the Apache 2.0 lic

[#Docker Hardened Images](/blog/tags/docker-hardened-images)[#Distroless](/blog/tags/distroless)[#SBOM](/blog/tags/sbom)+5 tags

[read more](/blog/post/democratization-docker-hardened-images-container-security)

[![Compliance as Code: Making Security Easier with Terraform and InSpec](/_astro/hero.CuKP9d1A_ZJUUcq.webp)](/blog/post/compliance-as-code-nist-iso-27001-gdpr-terraform-inspec)

## [Compliance as Code: Making Security Easier with Terraform and InSpec](/blog/post/compliance-as-code-nist-iso-27001-gdpr-terraform-inspec)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [Compliance as Code](/blog/categories/compliance-as-code)
-   [Security](/blog/categories/security)
-   [DevSecOps](/blog/categories/devsecops)
-   [Terraform](/blog/categories/terraform)
-   [InSpec](/blog/categories/inspec)
-   [Cloud](/blog/categories/cloud)
-   [Governance](/blog/categories/governance)
-   Published: 03 Aug, 2025

Hey, so you know how keeping our tech stuff secure and following all the rules can be a real headache these days? With everything moving to the cloud and so many regulations popping up, it's tough to

[#Compliance](/blog/tags/compliance)[#NIST](/blog/tags/nist)[#ISO 27001](/blog/tags/iso-27001)+7 tags

[read more](/blog/post/compliance-as-code-nist-iso-27001-gdpr-terraform-inspec)
