Chapter 10 · Part 2

Security Scan, Compliance, and Quality Gate

A focused chapter on security scan, compliance, and quality gate, with practical delivery concerns, trade-offs, and the operational questions behind CI/CD work.

10-1

Why Your Pipeline Should Check Security and Compliance

When your team first sets up a CI/CD pipeline, the checks you add are usually the obvious technical ones: does the code compile, do the unit tests pass

5 min
10-2

What Your Pipeline Can Actually Check (Beyond Just Security Scanning)

When most teams start adding checks to their deployment pipeline, the first thing that comes to mind is security scanning of the application code. Run a

5 min
10-3

When to Fail a Pipeline and When to Just Warn

You just added a security scanner to your CI pipeline. The first scan runs, and it finds 47 issues. Three are marked critical, twelve are high, and the

5 min
10-4

When Your Security Pipeline Blocks Everything: Handling Exceptions Without Creating Loopholes

You have a security scan running in your CI pipeline. It finds a vulnerability in a library your team depends on. The severity is medium, but there is no

5 min
10-5

When Security Rules Live in Documents, They Get Ignored

A security team spends weeks drafting a container image scanning policy. They send it via email, announce it in the all-hands meeting, and store it in the

5 min
10-6

Where to Put Quality Gates in Your Pipeline Matters More Than What You Scan

You push a commit. The pipeline starts. You wait. And wait. After fifteen minutes, the pipeline fails because of a low-severity vulnerability in a library

6 min
10-7

When Security Scan Results Get Ignored (And How to Fix It)

Your pipeline has security scanning. The tools are configured. The gates are in place. Everything looks good on paper.

5 min
10-8

When Your Security Guardrail Stops Working: Measuring and Fixing Pipeline Effectiveness

You set up security scanning, compliance checks, and quality gates in your pipeline. Everything looked solid. Six months later, developers are submitting

6 min