DevSecOps
Report: The State of Cloud-Native Application Security
The cloud brings tremendous capabilities in terms of increased deployment fluidity and automation. Along with cloud adoption has come the use of cloud-native tools built specifically for developing applications for this domain ...
Google Proposes SLSA Framework to Secure Software Supply Chains
Google is proposing organizations adopt a framework for securing the integrity of software artifacts across a software supply chain. Kim Lewandowski, a product manager for open source software security at Google, said ...
No More Hot Potato: How Collaboration is Key in Application Security
Technology is accelerating at an unprecedented rate and companies with little digital footprint or experience in application security are struggling to keep up. With more and more breaches and vulnerabilities being detected ...
Learning ‘The Third Way’ of DevOps – Continuous Improvement
I refer to the third way of DevOps–continuous experimentation and learning, as simply continuous improvement. In some sense, there is no way to learn the third way of DevOps because it is, ...
How to Analyze Your Code for Security Vulnerabilities
Shifting Left 2.0 is a two-day virtual conference taking place from 9 a.m. to 2 p.m. PDT on June 22nd-23rd that dives deep into application security in the modern tech space. Security ...
Accurics Aligns DevSecOps Platform With GitLab
Accurics today announced it has integrated its tool for discovering violations of security policies that occur when developers provision infrastructure as code with both the continuous integration and continuous delivery (CI/CD) platform ...
Majority of Orgs Lack Visibility Into Container Vulnerabilities
Today’s blend of third-party application dependencies and polyglot software development often makes assessing risk difficult. With many new cloud-native deployment models, it can be tricky to discover potential vulnerabilities. These threats take ...
Learning ‘The Second Way’ of DevOps – Continuous Feedback
As indicated in my prior blog Learning the 'First Way' of DevOps–Continuous Flow, many organizations are struggling to realize well-engineered DevOps, even the 'first way' of DevOps – continuous flow. The first ...
Why API Quality Is Top Priority for Developers
It is no secret that web APIs have become increasingly important to the operation of modern businesses. According to RapidAPI's Developer Survey and Insights report, 61% of developers used more APIs in ...
HashiCorp Increases Terraform’s Enterprise Appeal
During the online HashiConf Europe conference today, HashiCorp debuted the general availability of a 1.0 release of HashiCorp Terraform along with updates to HashiCorp Terraform Cloud service. Meghan Liese, senior director of ...
What Biden’s Cybersecurity EO Means for DevOps Teams
On May 12, 2021 President Biden issued Executive Order 14028, also known as the Executive Order on Improving the Nation’s Cybersecurity. This EO covers a lot of ground, and like all executive ...
Fixing Risk Sharing With Observability
Incentives are mismatched among SREs, SecOps, and application developers. These mismatches create challenges around how and what information is shared across siloed teams. This asymmetrical information creates a moral hazard where one ...

