← 🛡️ Security in the Pipeline
Core
Checkmarx release gates: scan identity, engine completion and finding triage
Build a Checkmarx One release decision from source identity, required scan engines, result filters and reviewed exceptions. Diagnose incomplete scans and misleading green pipeline jobs.
a free account opens the core tier · no card
RELATED CONCEPTS
PRACTICE THIS IN REAL QUESTIONS
DevSecOps & Supply Chain SecurityWhere do SAST, SCA, secret scanning and image scanning belong in a pipeline, and what does each actually catch?→DevSecOps & Supply Chain SecuritySAST, DAST, SCA and IAST: where does each belong in a pipeline, and what can none of them see?→CI/CD, Release Engineering & GitOpsYour pipeline takes 45 minutes and developers have stopped trusting it. How do you fix it?→CI/CD, Release Engineering & GitOpsShip a schema change to a live service with no downtime. Walk me through the sequence.→CI/CD, Release Engineering & GitOpsMonorepo or many repos for forty microservices? Argue it from the operational side.→CI/CD, Release Engineering & GitOpsDesign the test strategy for a pipeline that must stay under ten minutes. What runs where?→