
8/18/2021 · Pedro Fortuna
What this post added
This post introduces DevSecOps as a strategy to protect businesses from software supply chain attacks, highlighting the SolarWinds and Codecov incidents. It details how GitLab's platform, through security scanning (SAST, DAST, dependency scanning, etc.) and integration with Jscrambler, provides visibility and control over web supply chain risks. Jscrambler's capabilities include obfuscation, code locks, runtime protection, and real-time alerts for malicious behavior. The post emphasizes a defense-in-depth approach and a zero-trust model for website security.