Tom3306/devsecops-security-pipeline-lab ? reverse-engineered prompt
Reverse engineered prompt
Build me a small Node.js app that doubles as a DevSecOps security pipeline demo.
I want a simple Express service with a couple of endpoints like a health check and a search route, plus sensible security defaults like Helmet, request IDs, rate limiting, JSON body limits, and basic input validation. Add a few unit tests that prove it works and that the defensive headers are in place.
Then wire up GitHub Actions so the repo shows real application security coverage, including code scanning, secret scanning, dependency checks, container and filesystem scanning, a baseline web security scan, and supply chain checks. It should also work with Dependabot and include clear documentation that explains what each security control is catching and why it matters.
Please make it easy to run locally with npm install, npm test, and npm start, and include a Docker setup too. If you need current details for any of the security tools or GitHub Actions settings, look them up online first.
Are you gonna build this?
make sure you review the code using coderabbit