Snyk Learn
Unknown
Free interactive lessons from security vendor Snyk covering common vulnerabilities such as injection, cross-site scripting, and insecure dependencies, each shown in real code with its fix. Learners come away able to recognize and remediate OWASP Top 10 flaws in their own applications.
More resources on DevSecOps
OWASP Foundation
Nonprofit foundation publishing open web application security standards and guides, including the OWASP Top Ten, the Application Security Verification Standard, the Web Security Testing Guide and the Cheat Sheet Series, used to identify, test for and prevent common web vulnerabilities.
DevSecOps.org
Community site behind the DevSecOps Manifesto, which set out the movement's founding principles of security as code, shared responsibility, and data-driven risk decisions. Mostly dated essays; useful for understanding where DevSecOps came from and the cultural shift it asks of security teams.
OWASP DevSecOps Guideline
OWASP's open guide to building security checks into a CI/CD pipeline, stage by stage: secrets scanning, static and dynamic analysis, software composition analysis, infrastructure-as-code and container scanning. Readers can map which automated security tool belongs at each point in their delivery pipeline.
Securing DevOps
Mozilla security engineer Julien Vehent builds a sample web service on AWS and secures it end to end: pipeline controls, TLS, authentication, logging and intrusion detection, incident response, and risk assessment. Readers learn to embed security practices into continuous delivery.
Practical DevSecOps
Hands-on guide to automating security testing with open-source tools such as OWASP ZAP, sqlmap, and dependency checkers, then wiring those scans into CI/CD pipelines. Readers learn to build a security automation framework that tests web applications, APIs, and infrastructure without manual intervention.