Continuous Testing
How Log4j Becomes a Serious DevOps Problem
The recent discovery of the Apache Log4j vulnerability has wide-ranging implications for anyone who develops software, especially for those in the DevOps realm. What’s most troubling about the vulnerability (CVE-2021-44228) is how ...
Bridging the AppSec and DevOps Disconnect
Research estimates that cybercrime is going to cost the world $10.5 trillion annually by 2025, so it is no surprise that cybersecurity has become a top priority for business leaders. Today, security ...
Log4j: It’s All About the Supply Chain, Baby!
In 2021, the security story in DevOps and DevSecOps has been the supply chain. So, it’s only fitting that we are currently experiencing the mother of all supply chain issues with the ...
Speedscale Makes Free API Observability Tool Available
Speedscale today announced it is making a free edition of its observability tool for application programming interfaces (APIs) available to developers. Ken Ahrens, Speedscale CEO, said the goal is to expose more ...
Overcoming Challenges to Automating DevSecOps
In the last few years, DevSecOps has been widely adopted among organizations looking to get proactive with their security. Traditionally, development teams would continuously implement and deploy new applications into the enterprise ...
Vercel Acquires Turborepo to Gain Build System
Vercel today announced it has acquired Turborepo, a provider of a build system for JavaScript and TypeScript applications that provides developers with access to an easy-to-use monorepository for their code. In the ...
Securing the Software Supply Chain with Behavioral Analysis
Lately, software supply chains find themselves in a very interesting and uncomfortable position—the industry spotlight—and not in a good way. While significant and costly breaches such as SolarWinds or Kaseya make front-page ...
Iterative Adds Experiment Versioning to MLOps Platform
Iterative today added an experiment versioning capability to an open source platform for managing machine learning operations (MLOps) using GitOps workflows. Dmitry Petrov, Iterative CEO, said the latest version of the Data ...
CI/CD Is Still All About Open Source
One of the lessons I've learned in my years at the helm of DevOps.com is that the heart of DevOps is CI/CD. And at the heart of CI/CD is open source. While ...
Is TypeScript the New JavaScript?
While JavaScript is frequently the language of choice for all sizes of frontend and backend applications, it’s not the only option; nor is it necessarily the most efficient or cost-effective. Increasingly, TypeScript ...
Why Trust and Integrity Are Critical to IoT
We hear a lot about how the IoT is transforming people’s work and daily lives, but for me, its impact goes deeper. As a Type I diabetic, I depend on data from ...
WhiteSource Report Finds NPM Vulnerabilities Fixed Fast
WhiteSource today published a report that found most of the vulnerabilities that affect node package managers (NPMs), widely employed to deploy JavaScript applications, are addressed long before they are assigned a Common ...

