DevSecOps workshop v0.1.2 - Codespaces primary
Pre-releaseCodespaces-first workshop: v0.1.2 prerelease
The setup guide now follows the primary flow:
Original Pets template -> your repository -> open its codespace -> fetch the companion and run the existing setup script -> normal VS Code/Git edits.
Codespaces has already cloned the learner repository. No second clone, mandatory devcontainer, rebuild, application install, or extra core workflow is added. Local VS Code/Git and GitHub file editing are documented fallbacks after the primary path.
All live and take-home instructions now use the Codespaces editor and integrated terminal for file changes, commits, and pushes. GitHub.com remains the place for PRs, settings, Actions results, and approvals. Builds, tests, code scans, releases, and the optional token proof still execute in Actions.
The guide covers one reusable codespace, a persistent sibling kit under /workspaces, save versus commit/push, explicit stopping, storage usage, and safe recovery. It keeps Codespaces developer credentials separate from Actions job tokens. The companion fetch captures and verifies a commit before archiving that SHA, so a later editor auto-fetch cannot replace the archive source through FETCH_HEAD.
The original application template, two-core-workflow installer contract, 75-minute core plus startup/closing, and individual secret exercise remain unchanged.
Version and integrity
The annotated v0.1.2 tag resolves to companion commit:
ea050921bb902668d3e4fad5556548981c16cb91
Compare it with the commit printed by Step 0 before extracting. The ZIP contains all 52 kit files. SHA-256 of devsecops-workshop-kit-0.1.2.zip:
c9ef772ad516623dc55b62e073ad4cadad9869b522dc3a91418d62f7428c2c34
The checksum sidecar is attached. Versions v0.1.0 and v0.1.1 remain immutable.
Validation and limits
All 50 local tests passed, including a fetch regression that replaces FETCH_HEAD after verification and still extracts the correct saved commit without changing learner history. The route validator checked 25 Markdown files, 214 local links, 49 command/config snippets, and the primary/fallback boundaries. Four unchanged inert starters passed actionlint. Two kit builds produced identical bytes. Humanizer v3.0.0 File mode was applied from its pinned source to all 23 changed source Markdown files; the installed loader remains unavailable.
Actual Codespaces rehearsal was blocked before creation. The authoring CLI lacked the required codespace OAuth scope, and an authenticated browser control path was unavailable. No credentials or billing settings were changed, no additional auth consent was initiated, and no rehearsal repository or codespace was created to force the test. No Codespace ID, payer, machine, workflow-push result, secret-repair result, or stop/resume result is claimed.
The readiness register records that limitation separately from earlier local-terminal and Actions evidence. This remains a prerelease pending actual Codespaces and independent human walkthroughs, browser fallback checks, and measured learner timing.
Start with the overview or resume take-home work.