Skip to content
← Technical Diagram Library
Security

DevSecOps Software Supply Chain

Follow a change from developer commit through verification, artifact creation, deployment and runtime controls.

GitHub ActionsSASTSCASBOMSigstoreContainer SecurityPolicy as Code

DevSecOps Software Supply Chain

A secure delivery pipeline creates evidence at every handoff. Source review, dependency analysis, build integrity, artifact provenance and runtime controls should reinforce each other.

01

Security gates should create auditable evidence.

02

Build output should be traceable back to reviewed source.

03

Runtime findings should feed back into engineering decisions.

DevSecOps Software Supply ChainFollow a change from developer commit through verification, artifact creation, deployment and runtime controls.01DeveloperCode change02GitReview + policy03CIBuild + tests04Security GatesSAST • SCA • secrets05Artifact + SBOMSigned output06RuntimePolicy + telemetry
How to read it

Follow the handoffs, then ask where evidence exists.

01

Developer

Code change

02

Git

Review + policy

03

CI

Build + tests

04

Security Gates

SAST • SCA • secrets

05

Artifact + SBOM

Signed output

06

Runtime

Policy + telemetry

Architecture questions
Security gates should create auditable evidence.
Build output should be traceable back to reviewed source.
Runtime findings should feed back into engineering decisions.
Technology context
GitHub ActionsSASTSCASBOMSigstoreContainer SecurityPolicy as Code

The diagram is intentionally architectural rather than vendor-specific. Use it as a mental model, then map the components to the actual environment.

Need the architecture applied?

Use the visual model as the starting point for a workshop or technical review.