The move to DevOps, high-frequency deployments and containerization has introduced two new asset classes along with the opportunities to significantly improve the security posture of applications throughout the CI/CD pipeline. These new assets are templates in order to deploy infrastructure and applications, defined as code. The second of these asset classes are the container images which contain the packages, code, and binaries for a specific application. However, more often than not security is an afterthought, bolted on and addressed at runtime.