Learn
Safe code, through safe pipelines
Practical guides for developers, security engineers and the people who run the build servers. Each topic shows the unsafe way beside a safer one, in real languages and real pipeline files, and points to the primary sources: OWASP, NIST, SLSA, OpenSSF and Sigstore.
The guides
Four pages, each readable on its own. Free, no sign up, written for 2026 tooling.
Secure coding guide for developers
Validation and encoding, injection, access checks, secrets, dependencies, errors, crypto and review, each with an unsafe and a safer example.
Read the guideCI/CD pipeline security
Jenkins, GitHub Actions, GitLab CI, Azure DevOps, CircleCI, TeamCity and Bamboo, hardened, and mapped to the OWASP CI/CD risks.
Read the guideUnsafe vs safe, side by side
A visual gallery of common mistakes beside the safer way: code, dependencies, pipelines, secrets, containers and infrastructure.
Read the guideSecurity and development, working as one team
Shared goals, champions, paved roads, ownership, triage SLAs, exceptions that expire, a maturity model and a 30/60/90 day plan.
Read the guideLearning paths
Short routes through the guides for the role you have. Each step is one section, about five minutes.
Developers
Write code that holds up, and keep what you pull in honest.
Security teams
Put guidance where developers already work, and make findings worth fixing.
Platform and DevOps
The build system is production. Treat it that way.
Leads and managers
Make the safe way the easy way, and measure it.
The frameworks behind the guides
These are the primary sources. When a guide says "OWASP recommends" or "SLSA Build L2", this is where it comes from.
- OWASP Top 10:2025
The ten most critical web application risks, 2025 edition. Supply chain failures are now A03. The OWASP Top 10:2021 edition is still widely referenced. - OWASP ASVS 5.0
The Application Security Verification Standard: testable requirements to design against and verify, at three levels. - OWASP Top 10 CI/CD Security Risks
CICD-SEC-1 to CICD-SEC-10: flow control, identity, dependency chain abuse, poisoned pipelines, credentials and more. - SLSA build levels
Supply chain Levels for Software Artifacts. Build L1 to L3: provenance exists, is signed by a hosted platform, then comes from a hardened one. - NIST SSDF, SP 800-218
The Secure Software Development Framework, version 1.1. A version 1.2 draft (SP 800-218 Rev. 1) was published for comment in December 2025. - OpenSSF Scorecard
Automated checks for open source projects: pinned dependencies, token permissions, branch protection, dangerous workflows, signed releases. - Sigstore
Free signing and verification for software artifacts, keyless through OIDC identities, with a public transparency log. - OWASP Cheat Sheet Series
Short, specific guidance per topic. The guides here link to the relevant sheet for each section.
Where ForgeRepo™ fits
The guides are tool neutral. Two parts of them are where ForgeRepo™ does the work: every dependency your code and your pipelines pull goes through one gate, and you can answer "who pulled this?" in seconds when a package turns out to be malicious. It is free and self hosted.
For the code itself, reading it for injection, leaked secrets and risky patterns, the same author wrote Git Code Review, a free SAST and code review tool.
Put a gate in front of every dependency
The guides tell you to stop pulling straight from public registries. ForgeRepo™ is one container that does it for npm, PyPI, Docker, NuGet, Maven and more. Free, MIT licensed.