Business of DevOps
Secrets Sprawl and Rotation: A Practical Vault Management Playbook
In 2025 alone, security firm GitGuardian detected 28.65 million new hardcoded secrets exposed in public GitHub commits — a 34% increase year over year and the largest single-year jump the company has ...
Coding Agents Broke Git’s Scaling Math. GitHub Is Rebuilding to Keep Up
GitHub is rebuilding its Git infrastructure as AI coding agents drive billions of commits, promising up to 35x faster writes while exposing new DevOps bottlenecks ...
HackerOne Report Surfaces Massive Increase in Vulnerability Backlogs
HackerOne research shows vulnerability remediation is getting faster, but AI-driven discovery is expanding exposure debt even more quickly, putting DevSecOps teams under growing pressure ...
Federated Query at Petabyte Scale: A Deployment Pattern for a Governed AI-Agent Data Layer
A federated query architecture can reduce data duplication and latency while creating a governed, auditable data layer that enterprise AI agents can safely access ...
DevOps Dozen 2026 Nominations Are Open: Recognizing the People and Technology Moving DevOps Forward
When we launched the DevOps Dozen in 2015, we wanted to recognize the people, projects and companies helping this community move forward. We saw the work happening across DevOps every day at ...
Introducing Futurum Media: Why Futurum, Why Now?
Techstrong, Tech Field Day and Visible Impact come together, backed by the research, intelligence and expertise of The Futurum Group ...
env zero Previews Control Plane for Agentic DevOps Workflows
env zero’s EZ Control introduces an agentic DevOps control plane that detects infrastructure drift, applies policy-driven remediation and keeps automated changes attributable, reversible and auditable ...
GitHub’s Security Autofix Agent Now Remembers What It Fixed
GitHub’s agentic autofix now uses Copilot Memory to reuse repository-specific security fix patterns, helping Copilot apply lessons from past vulnerabilities across future alerts, reviews and coding workflows ...
Dependency Mocking Approach That Gets More Accurate as Your Services Deploy More Often
Traffic-based dependency mocking turns frequent upstream deployments into opportunities to refresh mocks from real behavior and reduce integration test drift ...
Why Old Azure DevOps Releases Survive a Pipeline Cutover
Old Azure DevOps Classic releases can retain retired deployment tasks, Helm names, image paths and variables long after a pipeline cutover, leaving stale redeploy paths active ...
TeamPCP Supply Chain Attack Leads to CrowdSec Source Code Being Stolen
CrowdSec says attackers stole source code from about 170 private GitHub repositories after a TanStack npm supply chain attack exposed an OAuth token tied to a former employee ...
Cycode Extends DevSecOps Reach to Software Packages Developers Download
Cycode is adding workstation-level protection to stop developers and AI coding agents from downloading malicious or insufficiently vetted software packages ...

