Skip to content

Automated DevSecOps Pipeline for Vulnerability Detection and Remediation - #2990

Open
sangeetha-murugesan-sda9 wants to merge 12 commits into
KTH:2026from
sangeetha-murugesan-sda9:Secure-CI-Pipeline-for-Automated-Vulnerability-Detection-and-Remediation
Open

Automated DevSecOps Pipeline for Vulnerability Detection and Remediation#2990
sangeetha-murugesan-sda9 wants to merge 12 commits into
KTH:2026from
sangeetha-murugesan-sda9:Secure-CI-Pipeline-for-Automated-Vulnerability-Detection-and-Remediation

Conversation

@sangeetha-murugesan-sda9

@sangeetha-murugesan-sda9 sangeetha-murugesan-sda9 commented Sep 7, 2026

Copy link
Copy Markdown

Assignment Proposal

Title

Automated DevSecOps CI Pipeline for Vulnerability Detection and Remediation.

Names and KTH ID

Deadline

Week 6

Category

Demo

Description

Our demo investigates how automated security testing and remediation can prevent vulnerable code from being merged into a shared codebase, using a small room-booking application (React frontend, Express API, a separate audit microservice, Supabase/Postgres) as the system under test. We use GitHub Actions together with CodeQL and Dependabot to detect vulnerabilities and automatically create fixes, without requiring a developer to manually triage every alert.

We will introduce a controlled vulnerability and We demonstrate automatic detection and remediation for both, showing how tests, security checks, and a security gate validate a fix before a pull request is allowed to merge.

The core workflow is:

Detect → Remediate → Validate → Security Gate → Merge/Block

Our demo investigates how automated security testing and remediation can prevent vulnerable code from being merged into a shared codebase, using a small room-booking application (React frontend, Express API, a separate audit microservice, Supabase/Postgres) as the system under test. We use GitHub Actions together with CodeQL and Dependabot to detect vulnerabilities and automatically create fixes, without requiring a developer to manually triage every alert.

We introduce two controlled vulnerabilities and demonstrate their automatic detection and remediation, showing how tests, security checks, and a security gate validate a fix before a pull request is allowed to merge.

The core workflow is:
Detect → Remediate → Validate → Security Gate → Merge/Block

Critically, the two vulnerabilities are chosen to contrast a case where automation completes the fix end-to-end against a case where it structurally cannot. We showcase this limitation live either no automated fix is offered for that alert, or a suggested fix is generated but fails CI, correctly blocking the merge until a human completes the remaining step. This directly demonstrates incomplete automated remediation as an observed limitation, alongside the related risk of fix-induced regressions and the fact that passing security checks does not guarantee complete security.

Relevance
The demo demonstrates DevSecOps by integrating security into the CI workflow. Automation provides fast feedback, reduces manual work, and ensures that vulnerable changes are blocked before reaching the main branch.

@github-actions github-actions Bot added the demo One of the task categories listed in README.md label Sep 7, 2026
@sangeetha-murugesan-sda9 sangeetha-murugesan-sda9 changed the title Automated DevSecOps for Vulnerability Detection and Remediation Automated DevSecOps Pipeline for Vulnerability Detection and Remediation Sep 7, 2026
@algomaster99

Copy link
Copy Markdown
Collaborator

Readme is not correctly formatted
Need exactly: ['Assignment Proposal', 'Title', 'Names and KTH ID', 'Deadline', 'Category', 'Description']

Got: ['Assignment Proposal', 'Title', 'Names and KTH ID', 'Deadline', 'Category', 'Description', 'Relevance']

@ericcornelissen ericcornelissen self-assigned this Sep 8, 2026

@ericcornelissen ericcornelissen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The demo seems a bit minimal. While gating pull requests should definitely be part of the demo, it's a concept already covered by earlier weeks. While demonstrating automated remediation of Dependabot and CodeQL-identified problems is a great proposal, I think it's too short and simple.

I would like you to add something (relevant) to the demo. One suggestion I have is to showcase one of the limitations you already plan to talk about, for example incomplete automated remediation.

@ericcornelissen ericcornelissen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The proposal looks good, please fix the duplication and then I will accept and merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

demo One of the task categories listed in README.md

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants