Resources

This page gathers reference materials, tools, and technical resources related to CI/CD security and software supply chain protection.

Resources listed here are selected for their relevance, technical depth, and practical usefulness.


Standards and frameworks


CI/CD security tools


Policy and control enforcement


Secrets management


CI/CD platforms and ecosystems


Threat modeling and attacks


Comparison guides

In-depth comparisons to help you choose the right tools for your CI/CD security stack.


Cheat sheets and quick references

Concise, copy-paste-ready references for everyday CI/CD security tasks.


External references


Related ecosystem

For compliance, governance, and regulatory aspects of DevSecOps and CI/CD, see regulated-devsecops.com.

The two sites are designed to complement each other: