skip to content
vaibhav.vanage
← all work
project

SBOM & SCA Automation

Azure DevOps extension — org-wide SBOM + supply-chain security.

DevSecOps

A custom Azure DevOps extension automating SBOM generation (CycloneDX) and Software Composition Analysis, feeding centralized vulnerability tracking via OWASP Dependency-Track. Drove org-wide adoption of software-supply-chain security while cutting licensing cost.

Alongside it, rolled out automated secrets detection across engineering repositories — surfacing 3,500+ exposed credentials, API keys, and tokens — then established preventive controls so new secrets are caught before they enter source control. SonarQube static analysis and AI-assisted pull-request review went into the same standardized pipelines, making secure-by-default the path of least resistance rather than an opt-in step.

org
Bajaj Finserv Health
impact
Org-wide supply-chain security; 3,500+ exposed secrets surfaced; reduced licensing cost.
stack
Azure DevOps ExtensionsCycloneDXDependency-TrackSonarQubedetect-secrets

// skills

CycloneDX SBOMDependency-TrackSecrets DetectionSecure CI/CD

// connections

see this in the graph