We're using the normal MS recommended approach to using Pipelines for ALM, however we are looking into what approach would be used to be as 'secure dev ops' as is reasonable.
With Power Platform being PaaS/Saas what could be used in the Pipelines from a 'security' perspective? For custom code there is SonarCube, Verracode etc.
What are other people doing in their pipelines to be considered 'Secure Dev Ops'?

Report
All responses (
Answers (