About This Architecture
Shift-left security pipeline integrating security scanning at every stage: SAST analysis with SonarQube on source code, SCA/dependency checking with Snyk after build, container image scanning with Trivy, and DAST scanning with OWASP ZAP. Security gates block promotion on critical vulnerabilities, with runtime protection and a centralized vulnerability dashboard.