Security in Mobile Application Developme: An Integrated Pipeline Based on the DevSecOps Approach
security in applications mobile; DevSecOps; pipeline of security.
The use of mobile devices is becoming increasingly widespread and is also the primary means of accessing the internet. This is due to applications, which expand the functionalities of these devices and, in turn, store various types of information, whether personal, banking, or corporate. In this context, the security of these applications requires strong attention, especially in the development process, which is directly related to the origin of many vulnerabilities. This work proposes the development of an integrated pipeline focused on the security of mobile applications, adopting the DevSecOps methodology. The pipeline will contain a modular architecture with stages covering most phases of the development lifecycle and different types of vulnerabilities, with the aim of identifying and mitigating them in an automated way. It is expected that the proposed solution, composed of stages such as static analysis, dynamic analysis, compliance verification, and dependency checking, will significantly contribute to the reduction of security flaws in mobile applications.