The AppGenie Blog

Controlled AI-assisted delivery, DevSecOps and compliance engineering, written from inside environments where somebody eventually has to answer for the outcome. 6 posts and counting.

Who Watches the Watcher? The DevSecOps Dirty Little Secret

Plenty of firms will audit your pipelines and tell you your release process is a liability, while running build pipelines of their own that would not survive the same review. So here are ours with the actual numbers: 21 deployments averaging 82 lines, 29 shared templates, 14 gates that fail the build, and the one that sat written but unwired for weeks.

DevSecOps, Azure DevOps, Engineering Governance · Q3 2026

DevSecOps and IRAP

DevSecOps and IRAP. Recent cyber events have focused attention on what many organisations are doing wrong. Here's a checklist to make sure you are aligning your DevSecOps with IRAP requirements and protecting your business.

DevSecOps · Q3 2025

JSON Web Tokens & SF CLI

Authenticating with your SF CLI is fine when you can use a screen and keyboard, but what about your Pipeline? Read the step-by-step How to use JWT to access your Salesforce Instance.

DevSecOps · Q4 2023

Git Merging

Are you living in fear of your next merge conflict, learn how GIT can save you or cause you more pain!

DevSecOps · Q1 2023

Static Analysis fails

Static Analysis is only half the answer. Good patterns and practices need to be supported in your dev team.

DevSecOps · Q2 2022
Follow along. New posts are published to RSS, Atom and JSON Feed, so you can read them in whatever you already use rather than remembering to come back here.