Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

The Developer’s Edge | DevSecOps in Bitbucket Cloud

Developer's Edge Atlassian Community Banner.png

Welcome to the Developer's Edge video series. This series examines Atlassian products and partner integrations through a developer’s lens, showing how an integrated toolchain can improve the developer experience while increasing productivity.

 

A better developer experience is a few steps away.

This video demonstrates a variety of Bitbucket features while deploying a Node.js webapp to AWS ECS. The video has a particular focus on Bitbucket pipelines and pull requests. You’ll learn how to run Bitbucket pipelines on your own hardware with self-hosted runners, and how platform teams can enforce standards via Dynamic pipelines and Custom merge checks. Dynamic pipelines greatly reduce the amount of CI/CD YAML that developers need to write while making sure all pipelines in the org run necessary static analysis and security scans.

 

This demo features three security pipes

First, atlassian/git-secrets-scanwhich uses gitleaks secret pattern registry to provide industry-leading Security Secrets Scanning

Second, atlassian/bitbucket-dependency-scanner, which leverages OWASP Dependency-Check scanning tool to provide dependency scanning capabilities.

 
Finally, atlassian/bitbucket-iac-scan, which uses KICS scanning tool to provide IaC Scanning capabilities.

 

Please take a look and leave any questions in the comments below.

 

 

Resources to get you going 

Check out the entire Developer's Edge video series here: The Developer's Edge 

Learn more about Bitbucket here: Bitbucket 

Bitbucket pipes here: Bitbucket pipes 

Dynamic pipelines here: Dynamic pipelines 

 

About the author

Warren is a former developer turned technical evangelist who joined Atlassian in 2021. He has worked on everything from COBOL telecoms software running on mainframes to modern cloud infrastructure at AWS. He has a passion for technology and a research background in machine learning. As a technical evangelist, Warren builds awareness of the capabilities of Atlassian products demos, writings, and videos. You can often find him at conferences like Team and re:Invent. Warren also curates the Developer’s Edge video series here. In his spare time, you can find him practicing his passion for Brazilian Jiu-Jitsu.

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events