Skip to content

SDLC pack

Secure development, testing, and DevSecOps knowledge lives here. Pages are claims: must / should, with control maps.

Applicability

Hardening and language pages are filtered by tech_profile in org.yaml. A Kubernetes checklist must not appear as current guidance for a Python-only org that does not run Kubernetes — once the kernel is live. This v1 site shows the default profile.

Tree

Path Contents
Policy Change, environment separation, secrets, production access
Design Threat-model bar, secure architecture
Coding Secure coding + language profiles
Testing Verification requirements (ASVS-shaped)
DevSecOps Pipeline gates, evidence pointers
Hardening Platform/language checklists
Agents What coding agents may and may not do

Default gates are listed under Pipeline gates.