Continuous Testing in DevSecOps Pipelines: Enhancing Software Quality Through Automated Security and Performance Validation
Abstract
ABSTRACT The rapid acceleration of software delivery cycles through Agile and DevOps methodologies has introduced severe challenges in maintaining robust security posture and optimal system performance. Traditional security evaluations and performance benchmarks—historically performed during late SDLC stages—create major bottlenecks, elevated remediation costs, and unmitigated production risks. DevSecOps addresses these limitations by shifting security and performance validation left, integrating automated testing tools directly into Continuous Integration and Continuous Deployment (CI/CD) pipelines. This review paper provides a comprehensive analysis of continuous testing mechanisms within modern DevSecOps architectures. We evaluate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and continuous performance profiling tools (e.g., automated load, stress, and latency testing). Furthermore, we synthesize empirical evidence regarding tool interoperability, false positive management, execution latency overheads, and feedback loop optimization. Our findings demonstrate that integrating lightweight security and performance gates reduces Mean Time to Remediate (MTTR) by up to 68% and decreases critical production vulnerabilities by 74%, while maintaining continuous delivery velocity.
KEYWORDS: DevSecOps, Continuous Testing, Automated Security Validation, Performance Profiling, Shift-Left Security, CI/CD Pipeline, SAST, DAST, SCA.
Full Text:
PDF 87-104Refbacks
- There are currently no refbacks.