I will build a secure devsecops ci cd pipeline with trivy, semgrep and cosign

Nigeria

I speak English

Platform Engineer and SRE, Kubernetes, GitOps, DevSecOps

Platform Engineer & SRE with 5+ years running fintech and core-banking infrastructure at 99.9%+ uptime. I build GitOps platforms that take a service from commit to prod safely: Tekton/ArgoCD pipelines...
About this Gig

Catch leaked secrets and vulnerable dependencies before they reach production.


I'll add a shift-left security gate to your GitHub Actions, GitLab CI, Azure DevOps or Tekton pipeline. It runs SAST (Semgrep), secret detection (Gitleaks), image and dependency scanning (Trivy, OWASP Dependency-Check), and signs your images with Cosign. Anything High or Critical blocks promotion automatically.


I run this exact setup in production today, gating every release.


What you get:

  • Pipeline YAML with security stages
  • Tuned rules to cut false positives
  • SBOM generation and signed, attested images
  • Centralized findings dashboard (Premium)
  • Docs for your team


Please message me before ordering with your CI tool, repo count and container registry.

Tools:

Docker

•

GitHub

Frameworks:

Terraform

•

Ansible

Cloud Provider:

Amazon Web Services

•

Microsoft Azure

Programming language:

Bash

•

Python

Expertise:

Installation

•

Development

•

Configuration

My Portfolio

Other DevOps Engineering Services I Offer