FEATURES

Video Interviews

Autonomous Patching for Cloud-Native Workloads

Autonomous Patching for Cloud-Native Workloads

|
The cloud-native stack didn’t make security go away—it just spread it across more layers, more repos, more images, and more ...
KubeCon, cloud native, ai, cloud-native,

From Cloud First to Cloud Fit: Rethinking Where Workloads Belong

|
Induprakas “Indu” Keri explores why organizations are increasingly shifting from a cloud-first mindset to a cloud-fit strategy as containerized applications ...

LATEST FROM DEVOPS.COM

‘PackageGate’ Vulnerabilities Can Let Attackers Bypass Shai-Hulud Defenses

In the wake of the massive Shai-Hulud supply chain attack that ripped through npm late last year and compromised more than 700 packages and exposed 25,000 repositories, developers in the JavaScript world embraced a two-part defense strategy. The widely adopted playbook called for disabling lifecycle scripts and using lockfiles. “It became the standard advice everywhere […] [...]

Opsera Report Highlights DevOps Challenges Created by AI Coding Tools

An analysis published today by Opsera, a provider of a DevOps platform, finds that while adoption of artificial intelligence (AI) coding tools has increased developer productivity they also create more duplicate code, resulting in 15 to 18% more security vulnerabilities per line of code compared to code created by a human developer. Overall, the Opsera […] [...]

AWS CodeBuild Webhook Misconfiguration Exposed Admin Access Risk

AWS fixed webhook filter misconfigurations in CodeBuild that could have allowed unauthorized repository access. No customer impact or malicious code found. [...]