Business of DevOps
Fast-Moving Shai-Hulud Attack Infects npm Packages with 2 Billion Monthly Downloads
Researchers at Aikido Security and Endor Labs are tracking a fast-spreading supply-chain attack that is compromising a wide range of npm software packages that combined have more than 2 billion installs a ...
AI is Coding Us Into a Corner
AI-powered patching and coding is putting us on a track towards a deepening dependency on future frontier models. The modern tools we use today to fix yesterday’s coding problems are quietly creating ...
Shift Left Security: 4 Automated Security Gates in GitHub Actions
Learn how to add four automated security gates to GitHub Actions using npm audit, Snyk, Trivy, CodeQL and OWASP ZAP—without an enterprise licence ...
Microsoft Confirms Copilot ‘Super App’ Is Coming This Year — and It’s About More Than Convenience
Microsoft is combining Copilot Chat, Code, Cowork and Autopilots into one super app, raising new questions about agent governance, identity, licensing and security ...
JetBrains Open-Sources KotlinLLM, a Research Prototype for Runtime Code Generation
JetBrains open-sources KotlinLLM, letting compiled Kotlin apps generate and persist LLM-written code at runtime instead of calling a model live ...
GitHub Brings Stacked Pull Requests Out of the Shadows
GitHub introduces native stacked pull requests, helping development teams break large changes into smaller, dependency-ordered PRs that are faster and easier to review ...
CISA’s 2026 SBOM Guidance Adds Hash Requirements and AI Coverage
CISA’s updated 2026 SBOM minimum elements expand software transparency requirements to AI, SaaS and open source while adding hashes, licenses and stronger validation ...
GitHub Gives Teams More Control Over Copilot’s Cloud Agent in Linear
GitHub’s Copilot cloud agent integration with Linear is now generally available, adding model, branch and team-level controls for delegated coding work ...
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
GitHub and PyPI are using time as a security control, delaying dependency updates and locking older releases against new file uploads ...
CodePen 2.0 Turns a Design Playground Into a Real Deployment Tool
CodePen 2.0 transforms the front-end playground into a file-based development platform with collaboration, version history and one-click deployment ...
The End of Manual Triage
Why SRE teams are replacing manual incident triage with AI-assisted correlation, stronger observability and controlled agentic workflows ...
AI Agents Are Writing Your Infrastructure Code. Is Anyone Governing It?
AI agents now generate infrastructure code at scale, but security pass rates are stuck at 55%. Here’s how teams can close the governance gap ...

