DevSecOps
This Has Been a Test
For nearly the entire history of application development—certainly since application development became available to a larger market with the adoption of the personal computer for expansive business use—testing has taken a back ...
Wipro Fires 2-Job Staff | Python Bug from 2007 | Lite Layoffs
In this week’s The Long View: Wipro fires 300 for moonlighting at competitors, Python has a nasty 15-year-old bug, and companies are finding new ways to lay people off without calling it ...
The Real Pipeline
I’ve made no secret of the fact that DevOps was a game-changing advance in how the business of IT was done. But people tend to get religious about the methodology and forget ...
GitBOM Tool Automatically Identifies Software Artifact Components
An open source GitBOM tool, discussed at the Open Source Summit Europe conference this week, can automatically track every source code file incorporated into each built artifact. Nell Shamrell-Harrington, a principal software ...
Heat Cooks Twitter DC | AI Will Kill All Humans | Patreon Layoffs, CSAM Claim
In this week’s The Long View: Twitter is in a “non-redundant state” thanks to a hot summer, AI is likely to eliminate us, and Patreon fires 80 staff amid nasty allegations ...
Survey Surfaces Massive Number of Application Vulnerabilities
A survey of 16,510 IT and IT security practitioners published today by Rezilion, a provider of a platform for automating the remediation of software vulnerabilities, found nearly half of respondents (47%) worked ...
Database Observability: How to Circumvent your Weakest Link
Today, IT pros field an increasing number of assets they need to monitor to secure systems and understand what’s happening in their database and applications. This is further complicated as organizations adopt ...
DevOps World 2022: Developer and Security Links Protect Your Supply Chain
Ever since the SolarWinds attack back in December 2020, software supply chain attacks have been top-of-mind for any company that builds software. The idea of endangering not just your organization by being ...
Playwright: A Modern, Open Source Approach to End-To-End Testing
I was excited when I started writing my first end-to-end tests years ago. The idea was promising; create an automated test suite that spins up a browser and mimics your user's behavior ...
Federal Agencies Share DevSecOps Guidelines
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the Office of the Director of National Intelligence (ODNI) have published a set of DevSecOps best practices based on the Enduring ...
Supply Chain Security: Has the Next SolarWinds Already Happened?
More than two years after the now-infamous hack of the firm SolarWinds, the incident is very much in the foreground of conversations about cybersecurity defense, threat detection and incident response. As evidence ...
The Missing Link in DevOps Cloud Security
We’ve all seen the data from the latest Verizon Data Breach Incident Report that shows half of security breaches stem from credential abuse. It's clear that credential compromise is an epidemic in ...

