Services / DevSecOps and CI/CD
Every change scanned before it ships
We set up pipelines that build, test, and scan every change, and we fix what the scanner finds, including in vendored third-party code.
Proof: findings fixed, rescanned clean
Static analysis stood up for a defense research program’s simulation plugins; findings fixed, including in third-party code; rescanned clean.
Related case study: One test coverage report for a whole product, on every build
Our own release pipeline
- Our application images cannot reach test or production with a critical or high CVE; each image is scanned before any database migration or deploy.
- Deploys are blue/green and drop zero requests.
- Every merge request runs end-to-end browser tests against the production build and a real database.
Release images with no critical or high CVEs, deployed blue/green
Tools we work with include GitLab CI, Fortify, SonarQube, Semgrep, Docker Scout, and Trivy, among others.
Can you work with the scanner our accreditation requires?
Yes. We have used open-source and commercial scanners, and we work with the one your program names.
Do you fix findings in third-party code?
Yes. We fix findings in vendored third-party code as well as your own; on one program, the fixes included a vendored binding library.
Can you work on site?
Yes, as needed and for as long as the work needs, including inside SCIFs. Our founder holds a TS/SCI clearance.
What does an estimate cost?
Estimates are free. Send the scope through the contact form; we reply within one business day and send a written quote within five business days.