Features
Tooling
SHIP-HATS contains a tool suite to cater to each stage of the CI/CD pipeline. Learn more here.
Compliance Framework
The SHIP-HATS Compliance Framework enables developers to automate DevSecOps practices based on industry pipeline security practices as well as the ICT&SS Management standards. Learn more here.
Pipeline Templates
SHIP-HATS templates are reusable pipeline configuration files that developers can use instead of building from scratch. These templates enable developers to build CI/CD pipelines efficiently by providing building blocks to include in their pipelines. This is based on the “write once, use anywhere” concept and encourages InnerSourcing. Learn more here.
Pipeline COE
Pipeline COE is a GitLab innersource project that aims to build and store sample images & pipelines that all users on SHIP-HATS’ GitLab can use. This feature is based on the GitLab DevSecOps Governance Framework (DGF) and helps development teams get started quickly through the available resources. Learn more here.
Dashboards
SHIP-HATS leverages GitLab dashboards within the GitLab Ultimate Tier to showcase key metrics for GitLab native tools (e.g., DevOps Adoption, DORA Metrics, Security dashboard, and Value Stream Analytics). The DevSecOps maturity report lets users review compliance with ICT&SS Management and DevSecOps policies. It also provides insights on alignments with best practices such as the Cloud Native Computing Foundation (CNCF), Supply Chain Levels for Software Artifacts (SLSA), and Open Web Application Security Project (OWASP). Learn more here.
Supply-chain Levels for Software Artifacts (SLSA)
SLSA is an add-on component to SHIP-HATS that protects against supply chain attacks. Learn more here.
InnerSource
The InnerSource Group in SHIP-HATS provides government officers with a community for learning, sharing of knowledge, and discussion. It is open for all public officers to contribute, view and adopt common code. Learn more here.
Thanks for letting us know that this page is useful for you!
If you've got a moment, please tell us what we did right so that we can do more of it.
Did this page help you? - No
Thanks for letting us know that this page still needs work to be done.
If you've got a moment, please tell us how we can make this page better.
A CI/CD Component That Speeds Up CI Setup, Testing and Delivery