The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use in this matter. Also, the project is trying to help us promote the shift-left security culture in our development process.
ZAP should probably be removed from the guidelines: https://owasp.org/www-project-devsecops-guideline/latest/02b-Dynamic-Application-Security-Testing
https://github.com/OWASP/www-project-developer-guide/issues/282