Skip to main content
In this section
๐Ÿ’ป App Developer

Ship to production safely. Security is already handled.

SmoothGlue runs every security scan automatically on every build. Your job is the app โ€” the platform handles compliance.

Console role:OrgPrivilegedยทOrgUser

Getting startedโ€‹


Security on every buildโ€‹

Pillars of Creation โ€” zero-config security scanning
SBOM ยท SAST ยท Container scanning ยท Dependency scanning โ€” automatic on every pipeline

Every app onboarded through the Console gets the full Pillars of Creation pipeline: Syft generates a CycloneDX SBOM, Semgrep runs SAST, Grype cross-references the SBOM against known CVEs, and OWASP ZAP tests the running app. None of this requires developer configuration. Builds with critical findings fail automatically โ€” they never reach a namespace that could affect production.


How-to guides โ€‹

Step-by-step operational guides for licensed customers.