DevSecOps
Chainguard Adds Private Edition of Code Signing Platform
Chainguard today added a private preview of a Chainguard Enforce Signing service, enabled by the open source Sigstore project, that allows developers to generate digital signatures for software artifacts using identities and ...
How Devs Can Improve Open Source Security in the Enterprise
Modern applications are dynamic. They’re distributed and they’re often born in the cloud. These applications can be developed on the fly, spun up and scaled quickly to meet evolving user and market ...
Report: Impact of Bad Software on US Economy Reaches $2.41 Trillion
A report published this week by Synopsys in collaboration with the Consortium for Information & Software Quality (CISQ) estimated that software quality issues might adversely impact the U.S. economy to the tune ...
Survey Surfaces Raft of DevSecOps Cultural and Technical Challenges
A global survey of 606 IT, security, application development and DevOps decision-makers found that the biggest barrier to adoption of DevSecOps best practices is cultural rather than technical. However, the survey, which ...
Implementing Shift Left Security in the Cloud
While ransomware has been the leading concern for enterprise security teams over the few past years, software vulnerabilities are nipping at its heels. The boom in cloud-based apps and services and increased ...
4 Best Practices for Entertainment App Testing
Entertainment apps represent a broad category of software, ranging from mobile games, to social media platforms, to streaming video apps and beyond. However, all entertainment apps share a few key traits in ...
Rezilion Adds Windows Support to Dynamic SBOM Tool
Rezilion has added support for Windows applications to its tool for dynamically generating software bills of materials (SBOMs). Rezilion CEO Liran Tancman said in addition to existing support for Linux applications, it’s ...
Culture a Stumbling Block to DevOps, DevSecOps
Organizations are struggling to improve DevSecOps practices as they confront a lack of cultural alignment and investment, according to a global Progress survey of more than 600 IT, security, application development and ...
Palo Alto Networks Buys Cider Security to Lock Down Pipelines
Palo Alto Networks this week extended its efforts to secure application environments by agreeing to acquire Cider Security, a provider of a platform for securing continuous integration/continuous delivery (CI/CD) platforms, for approximately ...
Data Centers IN SPAAACE | Discord GDPR Fine | AWS Fires Dead Wood
In this week’s The Long View: The EU wants to put servers in orbit, a GDPR penalty for Discord, and Amazon has the hatchet out ...
5 Tips for Securing DevOps: What You Wish You Knew Sooner
Foundations and frameworks, concrete and steel—not exciting. But that’s the foundation and framing of pretty much every modern building. Everything else that is part of a building–flooring, wiring, lighting, room placement and ...
Critical Vulnerability Discovered in Open Source Backstage Platform
Oxeye today disclosed that it has discovered a critical vulnerability in the open source Backstage software used to build developer portals. Backstage was originally created by Spotify. A 1.5.1 update to the ...

