---
name: devsecops-alm-devsecops-alm-overview
title: Overview of DevSecOps Application Lifecycle Management deployable architecture
description: The DevSecOps Application Lifecycle Management Deployable Architecture provides tools to securely deploy application code using DevSecOps pipelines. Out of the box, these pipelines use popular scanning tools such as SonarQube, Gosec, OWASP Zap (dynamic scan), any unit test framework, and GPG for image signing.
last-updated: 2025-03-27
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/devsecops-alm?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Overview of DevSecOps Application Lifecycle Management deployable architecture
{: #devsecops-alm-overview}

The DevSecOps Application Lifecycle Management Deployable Architecture provides tools to securely deploy application code using DevSecOps pipelines. Out of the box, these pipelines use popular scanning tools such as SonarQube, Gosec, OWASP Zap (dynamic scan), any unit test framework, and GPG for image signing. 

To learn more about integrating security practices through DevSecOps with Continuous Delivery, check out the [DevSecOps product guide](https://cloud.ibm.com/docs/devsecops?format=markdown).