DevSecOps
Software Compliance Teams Can Learn a Lot from DevSecOps
Many argue that application security should be the responsibility of a security team. However, while security professionals can contribute, developers are usually the only ones with the technical ability to fix software ...
GitLab Research Reveals DevOps and Cybersecurity Disconnects
DevOps and cybersecurity teams have a complicated relationship, which impacts code quality, research shows Finger-pointing has long been the name of the game when it comes to cybersecurity failures. After all, who ...
The Challenge of Securing Open Source Applications
As enterprises have increased their reliance on applications over the years, there has been a significant rise in the use of reusable software components such as third-party libraries and open source code ...
ASF Moves OpenWhisk Serverless Computing Forward
The Apache Software Foundation (ASF) announced today that the OpenWhisk serverless computing framework has now become a high-level open source project. Matt Rutkowski, CTO for serverless technologies and advocacy for IBM, said ...
3 Reasons Why Ephemeral Access is Best for DevOps
Recently, we worked with a customer, MOST Digital, whose developers were struggling with a common workflow challenge we hear from many companies. The company is in the software robotics automation space—it essentially ...
Product IT Operating Model: The Next-Gen Model for a Digital World
Digitization presents many new opportunities for businesses to create value. At the same time, it forces IT to rethink the way it operates. Modern CIOs need an operating model that understands the ...
GitLab Survey Surfaces Major DevSecOps Challenges Ahead
A report based on a survey of 4,071 software professionals published this week by GitLab, a provider of a continuous integration and continuous deployment (CI/CD) platform, found that while appreciation of the ...
Transforming the Security Team Into a DevOps Partner
Securing DevOps environments is an increasingly important concern for chief information security officers (CISOs) and security teams. While developers often recognize security is important, it is not their top priority. More typically, ...
DevOps Chat: Mayhem Testing With ForAllSecure
Secure software depends on people finding vulnerabilities and deploying fixes before they are exploited in the wild. This has lead to a world of security researchers and bug bounties directed at finding ...
DevSecOps Survey Finds Failure to Communicate
While it's generally agreed that shifting more cybersecurity responsibility onto the shoulders of developers is a good idea, a failure to communicate across application development and cybersecurity teams has contributed to little ...
State of the Software Supply Chain: Secure Coding Takes Spotlight
After almost a year of research that involved studying 36,000 open source software projects, 12,000 enterprise development teams and 3.7 million open source releases, we at Sonatype are excited to share the ...
6 Traits That Define DevSecOps
How do we define DevSecOps? A combination of DevOps and security is readily apparent, but the philosophy goes much deeper. In a recent eBook, The State of DevSecOps, we asked industry experts ...

