Home
International Journal of Science and Research Archive
International, Peer reviewed, Open access Journal ISSN Approved Journal No. 2582-8185

Main navigation

  • Home
    • Journal Information
    • Abstracting and Indexing
    • Editorial Board Members
    • Reviewer Panel
    • Journal Policies
    • IJSRA CrossMark Policy
    • Publication Ethics
    • Issue in Progress
    • Current Issue
    • Past Issues
    • Instructions for Authors
    • Article processing fee
    • Track Manuscript Status
    • Get Publication Certificate
    • Become a Reviewer panel member
    • Join as Editorial Board Member
  • Contact us
  • Downloads

ISSN Approved Journal || eISSN: 2582-8185 || CODEN: IJSRO2 || Impact Factor 8.2 || Google Scholar and CrossRef Indexed

Peer Reviewed and Referred Journal || Free Certificate of Publication

Research and review articles are invited for publication in March 2026 (Volume 18, Issue 3) Submit manuscript

Integrating Security into CI/CD Pipelines: A DevSecOps Approach with SAST, DAST, and SCA Tools

Breadcrumb

  • Home
  • Integrating Security into CI/CD Pipelines: A DevSecOps Approach with SAST, DAST, and SCA Tools

Naga Murali Krishna Koneru *

Accenture Solutions Pvt. LTD, INDIA.

Review Article
 
International Journal of Science and Research Archive, 2021, 03(01), 250-265.
Article DOI: 10.30574/ijsra.2021.3.1.0080
DOI url: https://doi.org/10.30574/ijsra.2021.3.1.0080

Received on 17 June 2021; revised on 22 August 2021; accepted on 26 August 2021

Continuous Integration and Continuous Deployment (CI/CD), which was rapidly adopted by the software development industry, turned into a fast-paced process, causing new insecurity to be generated. This paper explains how we support the implementation of such DevSecOps by SDI (merging security in SD) with CI/CD process by combining SDI instruments of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA) instruments. In this manner, security measures maintain equal development speed during development, while vulnerabilities are detected before their respective development stage ends. This research contributes scientific evidence with production use cases to demonstrate the usefulness of SAST, DAST, and SCA technologies in strengthening the effectiveness of CI/CD pipeline security. These tools are deployed so that the application can expose the security risks before the deployment dates, thereby ensuring that the application promotes security standards across the development teams. Security is embedded into core development procedures through DevSecOps, which performs security at each development stage rather than at the end. Risk reduction, trust levels, and compliance standards are augmented in the transition, and these are most critical in sectors that process sensitive information, such as retail and e-commerce. According to research data, security protection must be present before it comes to the market so that methods of protection can be implemented according to industry standards and meet the requirements of protecting digital systems from new cyber threats and vulnerabilities in a dynamically changing digital environment.

CI/CD Pipelines; DevSecOps; SAST Tools; DAST Tools; SCA Tools; Retail & E-Commerce Security

https://ijsra.net/sites/default/files/fulltext_pdf/IJSRA-2021-0080.pdf

Preview Article PDF

Naga Murali Krishna Koneru. Integrating Security into CI/CD Pipelines: A DevSecOps Approach with SAST, DAST, and SCA Tools. International Journal of Science and Research Archive, 2021, 03(01), 250-265. Article DOI: https://doi.org/10.30574/ijsra.2021.3.1.0080

Copyright © Author(s). All rights reserved. This article is published under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0), which permits use, sharing, adaptation, distribution, and reproduction in any medium or format, as long as appropriate credit is given to the original author(s) and source, a link to the license is provided, and any changes made are indicated.


All statements, opinions, and data contained in this publication are solely those of the individual author(s) and contributor(s). The journal, editors, reviewers, and publisher disclaim any responsibility or liability for the content, including accuracy, completeness, or any consequences arising from its use.

Get Certificates

Get Publication Certificate

Download LoA

Check Corssref DOI details

Issue details

Issue Cover Page

Editorial Board

Table of content

          

   

Copyright © 2026 International Journal of Science and Research Archive - All rights reserved

Developed & Designed by VS Infosolution