SDLC pack¶
Secure development, testing, and DevSecOps knowledge lives here. Pages are claims: must / should, with control maps.
Applicability
Hardening and language pages are filtered by tech_profile in org.yaml. A Kubernetes checklist must not appear as current guidance for a Python-only org that does not run Kubernetes — once the kernel is live. This v1 site shows the default profile.
Tree¶
| Path | Contents |
|---|---|
| Policy | Change, environment separation, secrets, production access |
| Design | Threat-model bar, secure architecture |
| Coding | Secure coding + language profiles |
| Testing | Verification requirements (ASVS-shaped) |
| DevSecOps | Pipeline gates, evidence pointers |
| Hardening | Platform/language checklists |
| Agents | What coding agents may and may not do |
Default gates are listed under Pipeline gates.