{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T18:28:25Z","timestamp":1777487305928,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":31,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3493649.3493655","type":"proceedings-article","created":{"date-parts":[[2021,11,25]],"date-time":"2021-11-25T17:05:03Z","timestamp":1637859903000},"page":"13-18","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["tapiser\u00ed"],"prefix":"10.1145","author":[{"given":"Shripad","family":"Nadgowda","sequence":"first","affiliation":[{"name":"IBM TJ Watson Research Center, NY USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Laura","family":"Luan","sequence":"additional","affiliation":[{"name":"IBM TJ Watson Research Center, NY USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Cloud native security whitepaper. https:\/\/github.com\/cncf\/tag-security.  Cloud native security whitepaper. https:\/\/github.com\/cncf\/tag-security."},{"key":"e_1_3_2_1_2_1","unstructured":"Ite-6 attestation definition. https:\/\/github.com\/in-toto\/attestation.  Ite-6 attestation definition. https:\/\/github.com\/in-toto\/attestation."},{"key":"e_1_3_2_1_3_1","unstructured":"The spiffe runtime environment. https:\/\/github.com\/spiffe\/spire.  The spiffe runtime environment. https:\/\/github.com\/spiffe\/spire."},{"key":"e_1_3_2_1_4_1","unstructured":"Static analysis for kubernetes. https:\/\/github.com\/spiffe\/spire.  Static analysis for kubernetes. https:\/\/github.com\/spiffe\/spire."},{"key":"e_1_3_2_1_5_1","unstructured":"Vulnerability scanner for containers. https:\/\/github.com\/aquasecurity\/trivy.  Vulnerability scanner for containers. https:\/\/github.com\/aquasecurity\/trivy."},{"key":"e_1_3_2_1_6_1","volume-title":"Briefing Rootm, https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/","year":"2021"},{"key":"e_1_3_2_1_7_1","unstructured":"Amazon. Build and test code with continuous scaling. https:\/\/aws.amazon.com\/codebuild\/.  Amazon. Build and test code with continuous scaling. https:\/\/aws.amazon.com\/codebuild\/."},{"key":"e_1_3_2_1_8_1","unstructured":"artifacthub. Find install and publish kubernetes packages. https:\/\/artifacthub.io.  artifacthub. Find install and publish kubernetes packages. https:\/\/artifacthub.io."},{"key":"e_1_3_2_1_9_1","unstructured":"A. CD. Declarative gitops cd for kubernetes. https:\/\/argoproj.github.io\/argo-cd\/.  A. CD. Declarative gitops cd for kubernetes. https:\/\/argoproj.github.io\/argo-cd\/."},{"key":"e_1_3_2_1_10_1","volume-title":"CARNEGIE-MELLON UNIV PITTSBURGH PA","author":"Chick T. A.","year":"2021"},{"key":"e_1_3_2_1_11_1","volume-title":"CARNEGIE-MELLON UNIV PITTSBURGH PA","author":"Chick T. A.","year":"2021"},{"key":"e_1_3_2_1_12_1","volume-title":"Provisioning pipelines: a managed devsecops approach to pipeline creation. Technical report","author":"Ficorilli S. T.","year":"2020"},{"key":"e_1_3_2_1_13_1","unstructured":"GitHub. Automate workflows from idea to production. https:\/\/github.com\/features\/actions.  GitHub. Automate workflows from idea to production. https:\/\/github.com\/features\/actions."},{"key":"e_1_3_2_1_14_1","unstructured":"GitHub. Supply chain security in tekton pipelines. https:\/\/github.com\/tektoncd\/chains\/.  GitHub. Supply chain security in tekton pipelines. https:\/\/github.com\/tektoncd\/chains\/."},{"key":"e_1_3_2_1_15_1","volume-title":"Code securely and faster with open source. https:\/\/github.com\/dependabot","year":"2020"},{"key":"e_1_3_2_1_16_1","volume-title":"https:\/\/www.ibm.com\/cloud\/blog\/announcements\/find-source-code-vulnerabilities-with-code-risk-analyzer","author":"BM.","year":"2020"},{"key":"e_1_3_2_1_17_1","unstructured":"T. Insider. What is the solarwinds hack and why is it a big deal? https:\/\/www.businessinsider.com\/solarwinds-hack-explained-government-agencies-cyber-security-2020-12.  T. Insider. What is the solarwinds hack and why is it a big deal? https:\/\/www.businessinsider.com\/solarwinds-hack-explained-government-agencies-cyber-security-2020-12."},{"key":"e_1_3_2_1_18_1","volume-title":"Dod enterprise devsecops reference design. Department of Defence","author":"Lam T.","year":"2019"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E.2017.14"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3098958"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"e_1_3_2_1_22_1","unstructured":"Pekato. Paketo buildpacks. https:\/\/paketo.io.  Pekato. Paketo buildpacks. https:\/\/paketo.io."},{"key":"e_1_3_2_1_23_1","volume-title":"Using blockchain and smart contracts for secure data provenance management. arXiv preprint arXiv:1709.10000","author":"Ramachandran A.","year":"2017"},{"key":"e_1_3_2_1_24_1","volume-title":"Code securely and faster with open source. https:\/\/developers.redhat.com\/blog\/2020\/08\/28\/vulnerability-analysis-with-red-hat-codeready-dependency-analytics-and-snyk","year":"2020"},{"key":"e_1_3_2_1_25_1","unstructured":". Research. Devsecops: Application security tool use between development and information security nears parity. https:\/\/451research.com\/trending-topics\/read-the-451-take\/devsecops\/.  . Research. Devsecops: Application security tool use between development and information security nears parity. https:\/\/451research.com\/trending-topics\/read-the-451-take\/devsecops\/."},{"key":"e_1_3_2_1_26_1","unstructured":"sigstore. software signing and transparency service. https:\/\/sigstore.dev.  sigstore. software signing and transparency service. https:\/\/sigstore.dev."},{"key":"e_1_3_2_1_27_1","unstructured":"Snyk. Developer-first cloud native application security. https:\/\/snyk.io.  Snyk. Developer-first cloud native application security. https:\/\/snyk.io."},{"key":"e_1_3_2_1_28_1","unstructured":"tekton. Catalog of shared tasks and pipelines. https:\/\/github.com\/tektoncd\/catalog.  tekton. Catalog of shared tasks and pipelines. https:\/\/github.com\/tektoncd\/catalog."},{"key":"e_1_3_2_1_29_1","unstructured":"WhiteSource. Automated dependency updates. https:\/\/www.whitesourcesoftware.com\/free-developer-tools\/renovate\/.  WhiteSource. Automated dependency updates. https:\/\/www.whitesourcesoftware.com\/free-developer-tools\/renovate\/."},{"key":"e_1_3_2_1_30_1","unstructured":"WhiteSource. Code securely and faster with open source. https:\/\/www.whitesourcesoftware.com.  WhiteSource. Code securely and faster with open source. https:\/\/www.whitesourcesoftware.com."},{"key":"e_1_3_2_1_31_1","volume-title":"CARNEGIE-MELLON UNIV PITTSBURGH PA PITTSBURGH United States","author":"Woody C.","year":"2020"}],"event":{"name":"Middleware '21: 22nd International Middleware Conference","location":"Virtual Event Canada","acronym":"Middleware '21","sponsor":["ACM Association for Computing Machinery","IFIP"]},"container-title":["Proceedings of the Seventh International Workshop on Container Technologies and Container Clouds"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3493649.3493655","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3493649.3493655","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:11:51Z","timestamp":1750191111000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3493649.3493655"}},"subtitle":["Blueprint to modernize DevSecOps for real world"],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":31,"alternative-id":["10.1145\/3493649.3493655","10.1145\/3493649"],"URL":"https:\/\/doi.org\/10.1145\/3493649.3493655","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}