DevSecOps
Orca Security Adds CLI to Improve Cloud Security
Orca Security has extended its cloud security platform via a command-line interface (CLI) that makes it simpler to integrate with a wide range of DevOps tools. Rather than relying on agents, the ...
5 Testing Strategies For Deploying Microservices
With rigorous development and pre-production testing, your microservices will perform as they should. However, microservices need to be continuously tested against actual end-user activity to adapt the application to changing preferences and ...
The APIs You Really Don’t Know About
A few years ago, we were rightly warned about the amount of exposure our APIs created. A massive attack surface that often used “security by obscurity” as its primary method of protection ...
The Risks of Shadow Code
As the economy struggles to recover after the last two years of the COVID-19 pandemic, we have all learned a thing or two about supply chains—and what happens when they break down ...
Architecting an Auth System for Applications
Applications today use many login and authentication methods and workflows. Here, I’ll share the most relevant and proven authentication workflows, which you can use as a basis for architecting and designing an ...
Why DevSecOps Should Be Top Priority
DevOps culture and process are integral to maintaining the pace of cloud-native software development for organizations, especially when code deployments might take place many times a day. The ability to instantly create, ...
Go Language is Popular? | VMware Sells to Broadcom? | Unlimited PTO?
In this week’s The Long View: Golang goes from zero to hero, Broadcom buys VMware, and limitless vacation is still a Thing ...
WhiteSource Becomes Mend, Launches Automated Remediation Platform
WhiteSource rechristened itself Mend today and launched a remediation platform that automatically resolves security issues for application developers. Rami Sass, co-founder and CEO of Mend, said now the company is going beyond ...
Survey Surfaces Challenges Ahead on National DevOps Day
A survey published today for National DevOps Day found nearly two-thirds (63%) have seen an increase in the frequency of service incidents that have affected their customers over the course of the ...
Competing Priorities Prevent Devs From Creating Secure Code
The recently released Secure Code Warrior State of Developer-Driven Security Survey revealed that developers continue to wrestle with secure coding practices in a working environment that has long prioritized features and functionality ...
DevSecOps Deluge: Choosing the Right Tools
In the last few years, DevSecOps has become the security process of choice for many forward-thinking enterprises. These organizations have come to understand that fixing bugs in the latter stages of product ...
Managing Hardcoded Secrets to Shrink Your Attack SurfaceÂ
The practice of hardcoding secrets—such as authentication credentials, passwords, API tokens and SSH Keys—as non-encrypted plain text into source code or scripts has been common in software development for many years. It ...

