SBOM & SCA Automation
Azure DevOps extension — org-wide SBOM + supply-chain security.
A custom Azure DevOps extension automating SBOM generation (CycloneDX) and Software Composition Analysis, feeding centralized vulnerability tracking via OWASP Dependency-Track. Drove org-wide adoption of software-supply-chain security while cutting licensing cost.
Alongside it, rolled out automated secrets detection across engineering repositories — surfacing 3,500+ exposed credentials, API keys, and tokens — then established preventive controls so new secrets are caught before they enter source control. SonarQube static analysis and AI-assisted pull-request review went into the same standardized pipelines, making secure-by-default the path of least resistance rather than an opt-in step.
- org
- Bajaj Finserv Health
- impact
- Org-wide supply-chain security; 3,500+ exposed secrets surfaced; reduced licensing cost.
- stack
- Azure DevOps ExtensionsCycloneDXDependency-TrackSonarQubedetect-secrets