One diagram, every module, in the order it actually runs.
The single strongest artifact to have ready — name the tool category and the threat it addresses at every stage.
1
Commitsecret scan
→
2
PRSAST+SCA+IaC
→
3
Buildephemeral, pinned
→
4
Image scan→
5
SBOM + sign→
6
DASTstaging only
→
7
Policy gate→
8
Deploy→
9
RuntimeFalco
IncidentYearWhat was compromisedWhich arrow
xz-utils2024A trusted maintainer identity, built over 2 yearsDev code → dep
event-stream2018Maintainer handed control to an unvetted volunteer3rd-party dep
Codecov2021Unpinned
curl | bash script, modifiedBuild systemDevSecOps is layered defense-in-depth — each stage catches what the ones before and after it structurally cannot.