<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DevSecOps on 黄文卓 | DevOps Engineer</title><link>https://socake.github.io/tags/devsecops/</link><description>Recent content in DevSecOps on 黄文卓 | DevOps Engineer</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor><webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster><copyright>© 2026 Wenzhuo Huang</copyright><lastBuildDate>Fri, 05 Dec 2025 10:00:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/devsecops/index.xml" rel="self" type="application/rss+xml"/><item><title>SLSA 软件供应链等级实施：从 L1 到 L3 的工程化路径</title><link>https://socake.github.io/posts/supply-chain-slsa-framework/</link><pubDate>Fri, 05 Dec 2025 10:00:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/supply-chain-slsa-framework/</guid><description>一份 SLSA v1.0 框架的实战落地笔记：讲清楚 Build Track 从 L1 到 L3 的具体要求、用 GitHub Actions 官方 generator 和 Tekton Chains 生成 provenance、用 slsa-verifier 和 Kyverno 做验证、以及和前面 Sigstore/Kyverno/Cosign 的整合。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/supply-chain-slsa-framework/featured.jpg"/></item><item><title>Sigstore/Cosign 镜像签名实战：从 keyless 签名到准入策略验证</title><link>https://socake.github.io/posts/sigstore-cosign-signing-workflow/</link><pubDate>Fri, 17 Oct 2025 10:00:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/sigstore-cosign-signing-workflow/</guid><description>一份 Sigstore 生产化落地笔记：讲清楚 Fulcio/Rekor/Cosign 三件套的工作原理，演示 GitHub Actions 和 GitLab CI 下的 keyless 签名流水线，对接 Kyverno/Policy Controller 做准入验证，并分享签名验证性能、Rekor 不可用降级、多签策略等真实运维经验。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/sigstore-cosign-signing-workflow/featured.jpg"/></item><item><title>DevSecOps 安全左移实践：从代码到生产的全链路安全</title><link>https://socake.github.io/posts/devsecops-practice/</link><pubDate>Wed, 20 Aug 2025 10:30:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/devsecops-practice/</guid><description>安全不是最后一道关卡，而是嵌入每个研发环节的连续过程。本文从代码静态分析、依赖漏洞扫描、镜像安全、K8s 运行时防护到供应链签名，逐层拆解 DevSecOps 的完整实施路径，并给出一个可落地的流水线设计。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/devsecops-practice/featured.jpg"/></item></channel></rss>