Combine application-security understanding with automated checks and secure delivery design. Begin in training labs, then apply what you learn to a sample repository you control.
Use beginner Web Security Academy topics to understand what a vulnerability looks like.
Enable CodeQL in the training repository and investigate a finding.
Study the Secure DevOps module to place checks, identities and threat modeling into a delivery lifecycle.
The sequence, role fit and project exercises are editorial recommendations. Provider requirements and certificate conditions are shown separately.
These resources offer free learning access. Some are guided tutorials rather than full courses. A free course does not necessarily include a certificate, hosted compute, private-repository features or a professional exam.
1. PortSwigger · Course
Web Security Academy
A useful way to understand the issues pipeline scanners report. The Academy provides intentionally vulnerable training labs.
Level
Mixed
Before you start
Basic HTTP and web-application concepts; start with introductory labs.
Time commitment
Self-paced; no fixed total stated
What is free?
Learning material and Academy labs are free; an account enables progress tracking. Use the provided lab targets.
Certificate
No · Academy learning is separate from the provider's professional certification
Turn it into project evidence
Complete an introductory lab and write a short explanation of the root cause and a defensive fix.