DEVSECOPS PIPELINE FOR PROVIDING SECURITY OF IOT CLIENT INTERFACES

Artem Antonenko, Oleh Bondarenko, Oleksandr Golubenko, Nataliia Lashchevska, Olga Morozova

Abstract


This article examines the processes for ensuring the information security of client interfaces (Front-end) in Internet of Things (IoT) systems. This study aims to develop and implement an automated DevSecOps pipeline integrated into the Gulp build environment to detect and block code vulnerabilities at the earliest stages of development (the Shift Left concept). The tasks are as follows: 1) analyze technological opportunities and challenges of implementing DevSecOps for IoT web interfaces; 2) analyze possible threats and vulnerabilities inherent in client-side code; 3) analyze existing approaches to integrating SAST tools into automated workflows; 4) analyze options for using standard automation tools (such as Gulp) to solve security tasks; 5) propose a DevSecOps pipeline architecture for the security of client interfaces; 6) propose a sequence of critical components and experimentally verify the effectiveness of the proposed solution. Based on the set tasks, the following results were obtained. An analysis of security problems in modern JavaScript-based IoT interfaces was conducted, and the need for automated code control was substantiated. An architecture for a DevSecOps pipeline is proposed using Gulp.js as an automation tool and a configured ESLint as a SAST scanner. A Gulp plugin ("wrapper") has been developed and implemented, providing continuous code monitoring during development. The system successfully identifies dangerous patterns (e.g., the use of eval functions or vulnerable setTimeout constructions) and blocks such code from entering the final release (Artifact). The proposed approach does not create significant overhead on the development process but guarantees compliance with security policies. Conclusions. The main contribution and scientific novelty of the results lie in creating an adaptive, easily integrated protection mechanism for the IoT ecosystem by integrating Static Application Security Testing (SAST) tools directly into the Gulp task runner architecture. Applying DevSecOps practices at the build level minimizes human-factor risks and increases overall trust in smart device management systems. The proposed solution is scalable and can serve as a foundational element of a cybersecurity strategy for Internet of Things projects

Keywords


DevSecOps; Internet of Things (IoT); Gulp; Static Application Security Testing (SAST); pipeline; JavaScript; Cybersecurity Shift Left; CI/CD; Supply Chain Security

References


Hoe, S. L. Digital transformation and the future of work: closing the digital skills gap. Development and Learning in Organizations: An International Journal, 2024, vol. 39, issue 3, pp. 14-17. DOI: 10.1108/DLO-06-2024-0167.

Moslehi, M. M. Exploring coverage and security challenges in wireless sensor networks: A survey. Computer Networks, 2025, vol. 260, article no. 111096. DOI: 10.1016/j.comnet.2025.111096.

Drane, L., McDonnell, M., Petras, R., Stiner, C., Ruckman, A. J., et al. Integrating scientific sin-gle-page applications with DevSecOps. Future Generation Computer Systems, 2025, vol. 166, article no. 107695. DOI: 10.1016/j.future.2024.107695.

Cope, R. Strong security starts with software development. Network Security, 2020, vol. 2020, issue 7, pp. 6-9. DOI: 10.1016/S1353-4858(20)30078-7.

Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. Challenges and solutions when adopt-ing DevSecOps: A systematic review. Information and Software Technology, 2022, vol. 141, article no. 106700. DOI: 10.1016/j.infsof.2021.106700.

Brojabasi, S., Paul, S., & Mitra, A. Cloud na-tive engineering: A comprehensive review of principles, practices, and challenges. Advances in Computers, 2026, vol. 141, pp. 331-353. DOI: 10.1016/bs.adcom.2025.06.013.

Shin, D., Kim, J., Pawana, I. W. A. J., & You, I. Enhancing cloud-native DevSecOps: A Zero Trust approach for the financial sector. Com-puter Standards & Interfaces, 2025, vol. 93, article no. 103975. DOI: 10.1016/j.csi.2025.103975.

Sroor, M., Mohanani, R., Colomo-Palacios, R., Dasanayake, S., & Mikkonen, T. Managing security issues in software containers: From practitioners’ perspective. Journal of Systems and Software, 2026, vol. 231, article no. 112616. DOI: 10.1016/j.jss.2025.112616.

Tanque, M., & Foxwell, H. J. Cyber risks on IoT platforms and zero trust solutions. Advances in Computers, 2023, vol. 131, pp. 79-148. DOI: 10.1016/bs.adcom.2023.04.003.

Ranganath, S. Edge computing: Types and at-tributes. Advances in Computers, 2022, vol. 127, pp. 35-62. DOI: 10.1016/bs.adcom.2022.03.001.

Tawalbeh, L., Muheidat, F., Tawalbeh, M., Quwaider, M., & Abd El-Latif, A. A. Edge ena-bled IoT system model for secure healthcare. Measurement, 2022, vol. 191, article no. 110792. DOI: 10.1016/j.measurement.2022.110792.

Truong, H.-L., & Klein, P. DevOps Contract for Assuring Execution of IoT Microservices in the Edge. Internet of Things, 2020, vol. 9, article no. 100150. DOI: 10.1016/j.iot.2019.100150.

Rey Rodriguez, K. S., Avellaneda Galindo, J. D., Tárrega Juan, J., Bermejo Higuera, J. R., Bermejo Higuera, J., & Sicilia Montalvo, J. A. Secure Development Methodology for Full Stack Web Applications: Proof of the Methodology Applied to Vue.js, Spring Boot and MySQL. Computers, Materials and Continua, 2025, vol. 85, no. 1, pp. 1807-1858. DOI: 10.32604/cmc.2025.067127.

Nyarko-Boateng, O., Nti, I. K., Mensah, A. A., & Gyamfi, E. K. Controlling user access with scripting to mitigate cyber-attacks. Scientific African, 2024, vol. 26, article no. e02355. DOI: 10.1016/j.sciaf.2024.e02355.

Saeed, H., Shafi, I., Ahmad, J., Khan, A. A., Khurshaid, T., & Ashraf, I. Review of Tech-niques for Integrating Security in Software De-velopment Lifecycle. Computers, Materials and Continua, 2025, vol. 82, no. 1, pp. 139-172. DOI: 10.32604/cmc.2024.057587.

Sinan, M., Shahin, M., & Gondal, I. Imple-menting and integrating security controls: A practitioners’ perspective. Computers & Securi-ty, 2025, vol. 156, article no. 104516. DOI: 10.1016/j.cose.2025.104516.

Zhang, X., Zhao, P., & Jaskolka, J. Navigating the DevOps landscape. Journal of Systems and Software, 2025, vol. 223, article no. 112331. DOI: 10.1016/j.jss.2024.112331.

Zaitsev, I., Golubenko, O., Tkachenko, O., Pidmohylnyi, O., & Antonenko, A. Exploring advanced hypothesis generation in astronomy through the implementation of a mathematical model of linguistic neural networks. CEUR Workshop Proceedings, 2023, vol. 3687, pp. 121–128.

Casola, V., De Benedictis, A., Mazzocca, C., & Orbinato, V. Secure software development and testing: A model-based methodology. Computers & Security, 2024, vol. 137, article no. 103639. DOI: 10.1016/j.cose.2023.103639.

Liu, Y., Tiwari, D., Bogdan, C., & Baudry, B. Detecting and removing bloated dependencies in CommonJS packages. Journal of Systems and Software, 2025, vol. 230, article no. 112509. DOI: 10.1016/j.jss.2025.112509.

Kumar, R., & Goyal, R. Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over cloud (ADOC). Computers & Security, 2020, vol. 97, article no. 101967. DOI: 10.1016/j.cose.2020.101967.

Rezaei Nasab, A., Shahin, M., Hoseyni Raviz, S. A., Liang, P., Mashmool, A., & Lenarduzzi, V. An empirical study of security practices for microservices systems. Journal of Systems and Software, 2023, vol. 198, article no. 111563. DOI: 10.1016/j.jss.2022.111563.

Akbar, M. A., Smolander, K., Mahmood, S., & Alsanad, A. Toward successful DevSecOps in software development organizations: A deci-sion-making framework. Information and Software Technology, 2022, vol. 147, article no. 106894. DOI: 10.1016/j.infsof.2022.106894.

Ren, Y., Wang, Z., Sharma, P. K., Alqahtani, F., Tolba, A., & Wang, J. Zero Trust Networks: Evolution and Application from Concept to Practice. Computers, Materials and Continua, 2025, vol. 82, no. 2, pp. 1593-1613. DOI: 10.32604/cmc.2025.059170.

Robitzsch, S., Centenaro, M., di Pietro, N., Cordeiro, L., Gomes, A. S., Sanders, P., & Ishaq, A. Prospects on the adoption of a microservice-based architecture in 5G systems and beyond. Computer Networks, 2023, vol. 237, article no. 110058. DOI: 10.1016/j.comnet.2023.110058.

Casino, F., Lopez-Iturri, P., & Patsakis, C. Cloud continuum testbeds and next-generation ICTs: Trends, challenges, and perspectives. Computer Science Review, 2025, vol. 56, arti-cle no. 100696. DOI: 10.1016/j.cosrev.2024.100696.

Olotu, S. I., Oronti, A. O., & Alese, B. K. Mi-crosegmentation for containerized micro-services in edge computing. Intelligent Data-Centric Systems: Cybersecurity Defensive Walls in Edge Computing. Academic Press, 2026, pp. 85-104. DOI: 10.1016/B978-0-443-34109-0.00011-5.

Kadri, M. R., Abdelli, A., Ben Othman, J., & Mokdad, L. Survey and classification of Dos and DDos attack detection and validation ap-proaches for IoT environments. Internet of Things, 2024, vol. 25, article no. 101021. DOI: 10.1016/j.iot.2023.101021.

Khandebharad, A. Migration From DevOps to DevSecOps. International Journal of Cloud Applications and Computing, 2022, vol. 12, no. 1. DOI: 10.4018/IJCAC.2022010102.

Khadem, E. A., & Movaghar, A. From chal-lenges to metrics: An LLM-driven DevOps rec-ommendation system grounded in evidence-based mappings. Array, 2025, vol. 28, article no. 100547. DOI: 10.1016/j.array.2025.100547.

Oruma, S. O., Sánchez-Gordón, M., & Gkiou-los, V. Enhancing security, privacy, and usabil-ity in social robots: A software development framework. Computer Standards & Interfaces, 2026, vol. 96, article no. 104052. DOI: 10.1016/j.csi.2025.104052.

Schuh, G., Jarke, M., Gützlaff, A., Koren, I., Janke, T., & Neumann, H. Review of commer-cial and open technologies available for Indus-trial Internet of Things. Design and Operation of Production Networks for Mass Personalization in the Era of Cloud Technology, 2022, pp. 209-241. DOI: 10.1016/B978-0-12-823657-4.00005-1.

Silva, C., Felisberto, J., Barraca, J. P., & Salva-dor, P. ASAP 2.0: Autonomous & proactive de-tection of malicious applications for privacy quantification in 6G network services. Com-puter Communications, 2025, vol. 237, article no. 108145. DOI: 10.1016/j.comcom.2025.108145.

Ascenção, C., Teixeira, H., Gonçalves, J., & Almeida, F. Large-scale agile security practices in software engineering. Information and Computer Security, 2024, vol. 33, issue 3, pp. 344-361. DOI: 10.1108/ICS-07-2023-0136.

Caniglia, A., Dentamaro, V., Galantucci, S., & Impedovo, D. FOBICS: Assessing project secu-rity level through a metrics framework that evaluates DevSecOps performance. Information and Software Technology, 2025, vol. 178, article no. 107605. DOI: 10.1016/j.infsof.2024.107605.

Djebali, S., Guerard, G., & Taleb, I. Survey and insights on digital twins design and smart grid’s applications. Future Generation Computer Sys-tems, 2024, vol. 153, pp. 234-248. DOI: 10.1016/j.future.2023.11.033.

Makoveichuk, O., Golubenko, O., Kukhtyk, S., Antonenko, A., Bereznychenko, V., & Iatsyshyn, A. Temperature Forecasting with LSTM: A Case Study on Kyiv Weather Data. CEUR Workshop Proceedings, 2025, vol. 4133, pp. 201–211.

Zaitsev, I., Bondarenko, O., Golubenko, O., Antonenko, A., & Savchenko, A. Securing applied information systems with SAST integration into the Gulp pipeline. CEUR Workshop Proceedings, 2025, vol. 4133, pp. 181–189.




DOI: https://doi.org/10.32620/reks.2026.2.06

Refbacks

  • There are currently no refbacks.