0.4 Map of Volume 1
This course is Volume 1 only. The book title is The Magical Code Library: DevSecOps, Volume 1. Nothing after the recap is a later volume hiding on this site.
- How to read. You are here. Library rules, map, safety.
- The tale of the code city. Waterfall, Agile, DevOps, and DevSecOps as four ways to build. A teaching table for the cost of bugs. Catch the bug on the left.
- Three pillars and DORA. Dev wants features. Sec wants risk down. Ops wants uptime. Four delivery goals, plus one security check that is not a DORA metric.
- Threat modeling on paper. STRIDE in six sentences. PASTA in seven steps. One payment picture. One worked threat and three fixes.
- Recap. What you can say out loud. What this volume refuses to teach.
A later book, not written here, is where names like OWASP Top 10 fixes, SAST with SonarQube and Semgrep, and SCA and SBOM with CycloneDX and SPDX belong. This volume only tells you those names are coming. It does not teach them.
Practice task
Open the chapter list. Mark the one chapter you will read tonight. Write the question that chapter should answer, in one line, before you start.