ResponseOne is a 14-day project to build and prove out an automated DevSecOps and incident response pipeline, using OWASP Juice Shop as the test application. The goal was simple: catch vulnerabilities the moment code is committed, stop insecure builds automatically, and route every finding straight into an automated response system rather than relying on manual review.
The team built and integrated four types of security scanning (static code analysis, dependency scanning, secrets detection, and live application testing) directly into the CI/CD pipeline. Each scan type was tested against a real, planted vulnerability to confirm the system works end to end, not just in theory. In every case, the pipeline correctly detected the issue, blocked the build, and sent a real-time alert to the team with accurate details, including a severity score and clear remediation steps. This ranged from a hardcoded cloud credential to a live SQL injection vulnerability found through active testing.
Those findings were then connected to a self-hosted incident response platform, which automatically enriches each alert with threat intelligence and routes it to the right response workflow, all without anyone needing to manually triage the finding first.
The project surfaced a number of real infrastructure and configuration issues along the way, from networking faults to a routing bug in the automation platform itself, all of which were diagnosed and resolved with evidence, not guesswork. Notably, one fix corrected a bug that had been silently causing real vulnerabilities in prior test runs to go undetected, a good example of why this kind of rigorous, end-to-end verification matters.
The entire solution was delivered using free, open-source tools, keeping the approach reproducible and cost-free to replicate elsewhere. The result is a working proof of concept: security scanning and incident response no longer need to be separate, manual processes. They can run automatically, in real time, as part of how software already gets shipped.
ResponseOne is a 14-day initiative to build and validate a working DevSecOps pipeline integrated with automated incident response, using OWASP Juice Shop as the test environment. The project addresses a common gap in software delivery: security scanning and incident response are often handled as separate, manual processes, which slows down detection and delays action on real vulnerabilities. This project closes that gap by embedding four categories of automated security scanning directly into the CI/CD pipeline, then routing every finding into a Security Orchestration, Automation and Response (SOAR) platform capable of enriching, triaging, and alerting on those findings without manual handling.
The work is carried out by a three-person team, each responsible for a distinct layer of the solution: pipeline and scanner integration, SOAR deployment and automation, and environment setup with final reporting. The entire solution is built using free and open-source tools, making the outcome fully reproducible without licensing cost. The sections below define the project's specific objectives and the boundaries of what this implementation covers.

The ResponseOne project aims to embed automated security testing directly into the software delivery pipeline and connect the resulting findings to an automated response capability. Specifically, the project seeks to: