a Futurum company

Coverage Area

CI/CD

The latest CI/CD news, analysis and insights from DevOps.com.

24Articles shown
15Contributors
LatestUpdates
AllCI/CDCloud ComputingAI-Native DevOpsAIOpscertificate lifecycle managementCI/CD securityAzure DevOps
Most recent
AI

The Rise of AI-Native DevOps: How AI Is Reshaping Software Delivery in 2026

For years, DevOps had a pretty straightforward mission: help teams ship reliable software faster by getting development and operations folks working together. Tools like automation, continuous integration, continuous delivery, infrastructure as code, and better observability have all been key pieces of the puzzle. But now, things are shifting again. This time, artificial intelligence is changing […]

Sannan Ali · Aug 11, 2026
Blogs

Zero Trust Starts at the Code: Building Secure Systems with PKI and DevOps Automation

When a certificate expires, it can take down a production system, and teams usually only find out after something goes wrong. These issues are hard to catch because they rarely trigger alerts. Expired certificates often remain unnoticed in a config file or an old key until they cause trouble. Enterprise apps are no longer single, […]

BALA CHANDAR NAGALLA · Jul 21, 2026
AI

Novee Uncovers Cordyceps: The Latest Threat to CI/CD Pipelines

A newly discovered supply chain security flaw is once again putting a spotlight on inherent weaknesses in CI/CD pipelines and the growing interest among cyberthreat actors to exploit them. Security researchers with Novee, an AI penetration testing platform provider, wrote about Cordyceps, an exploitable pattern in the open source supply chain that can allow attackers […]

Jeff Burt · Jul 6, 2026
Blogs

Modernization Is Not Migration

Modernization worked only if the platform became easier to change, easier to understand and safer to run under pressure. That is not a philosophical position — it is a measurable one.

kumar vaibhav sharma · Jun 26, 2026
AI

Security Flaw in Claude Code Illustrates the Risk of AI in Developer Workflows

AI coding agents are reshaping software development—but they’re also expanding the attack surface. Researchers uncovered a now-patched vulnerability in Anthropic’s Claude Code GitHub Action that could have enabled prompt injection attacks to expose CI/CD secrets, API keys, and credentials. As AI agents gain autonomy in development workflows, organizations must treat untrusted inputs as hostile and rethink CI/CD security models. Natural language is becoming executable code—and attackers know it.

Jeff Burt · Jun 10, 2026
Blogs

The Silent Risk of AI-Written DevOps Pipelines

These days, when a developer needs a CI/CD pipeline, they don’t always dive into GitHub Actions docs or spin up Jenkins from scratch. Instead, they pull up an AI assistant and type out something like: “Create a deployment pipeline for a containerized application.” Seconds later, the AI spits out a complete workflow. It looks polished. […]

Sannan Ali · Jun 4, 2026
Blogs

Regression Testing Tools in the Age of AI-Assisted Development: What Has Changed

For most of the past decade, the conversation around regression testing tools was fairly stable. The tools got faster, the integrations got smoother, and the underlying approach stayed largely the same: write tests, run them in CI, fix failures. The fundamental model did not change much because the problem did not change much. AI-assisted development […]

Sophie Lane · Jun 2, 2026
Blogs

AI Agents in CI/CD Pipelines: Speed vs Control in Modern DevOps

The moment you push your code, deployment fires off on its own. The pipeline kicks in, the tests sail through, and within a few minutes your app is live in production. There is no manual sign-off and no one scanning through the final changes. Everything is running on the decisions of an AI agent plugged […]

Sannan Ali · May 22, 2026
Blogs

The Great Decoupling: Scaling the Outer Loop for the Agentic Era

The “Inner Loop” of software development—the iterative cycle of writing, building, and debugging code—has just broken the sound barrier. With the emergence of agentic coding tools like Claude Code and GitHub Copilot Workspace, the developer experience has undergone a fundamental shift. Developers are no longer merely tab-completing snippets; they are orchestrating agents that generate entire […]

Nassir Khan · May 6, 2026
CI/CD

AI Agents in DevOps: Hype vs. Reality in Production Pipelines

The demos look super cool! An AI agent detects a failing deployment, rolls it back, opens a GitHub issue, and notifies Slack — all before the on-call engineer has finished reading the alert. If you’ve been following the DevOps tooling space over the last 18 months, you’ve probably seen some version of this pitch. But […]

Bala Priya · Apr 22, 2026
AI

Agentic CI/CD is Not Automation: Why the Distinction Will Define DevOps in 2026

There is a dangerous conflation happening across our industry right now. Teams are plugging LLM-powered agents into their deployment pipelines, calling it “agentic CI/CD,” and treating it as the next logical step after shell scripts and Terraform modules. It is not. Automation executes predefined instructions. An agent reasons about context, makes decisions, and takes actions […]

Muhammad Yawar Malik · Apr 14, 2026
Blogs

Akuity Adds Ability to Customize Kargo Pipelines

Akuity this week at the KubeCon + CloudNativeCon Europe conference revealed it has added an ability to customize the steps used to promote applications into a production environment using a Kargo orchestration engine it developed to manage software using a GitOps workflow. Company CEO Hong Wang said the Custom Steps capability added to Kargo will […]

Mike Vizard · Mar 25, 2026
AI

Harness Extends AI Security Reach Across Entire DevOps Workflow

Harness today added an ability to automatically secure code as it is being written by an artificial intelligence (AI) coding tool in addition to adding a module to its DevOps platform that discovers, tests, and protects AI components within applications. Secure AI Coding is an extension of the static application security testing (SAST) and software […]

Mike Vizard · Mar 17, 2026
AI

Sonar Unfurls Framework for Managing DevOps Workflows in the Age of AI

Sonar this week launched an Agent Centric Development Cycle (AC/DC) framework that promises to modernize continuous integration (CI) in the age of artificial intelligence (AI) coding. Announced at an online Sonar Summit, the AC/DC framework incorporates multiple tools and platforms the company has developed to better secure software supply chains, including now in beta Sonar […]

Mike Vizard · Mar 4, 2026
Blogs

Harness Makes Registry for Integrating Artifacts into DevOps Workflows Available

Harness today made generally available an Artifact Registry it has added to its portfolio of DevOps tools and platforms. At the same time, Harness also revealed it has added a Dependency Firewall to the registry that enables DevSecOps teams to enforce controls at the point of ingestion. Rather than relying on downstream scans after a […]

Mike Vizard · Feb 24, 2026
CI/CD

Observability, SRE and Uptime in Telehealth Platforms: A DevOps Playbook

Virtual care went from nice to have to must have during the COVID-19 pandemic and while in-person visits are starting to pick up again, telemedicine is here to stay. Its growth will continue: health-tech companies are predicting the telemedicine market will be $143.49 billion by 2025 (it will be $167.74 billion in 2025 and $584.99 […]

Michael Chukwube · Dec 18, 2025
CI/CD

Malicious VS Code Extensions Take Screenshots, Steal Info

Developers were the targets of two new malicious Microsoft Visual Studio Code (VS Code) extensions created by a threat actor that security researchers believe is experimenting with methods for delivering information-stealing malware to the victims’ systems. The malicious extensions come posing as a harmless “premium dark theme” and an AI-powered coding assistant, but both – […]

Jeff Burt · Dec 10, 2025
Blogs

Survey Sees Argo CD Starting to Gain Significant Traction

A survey of 185 software development professionals who have adopted the Argo continuous delivery (CD) platform finds that 97% are now using it in production environments, with 60% running Argo for more than two years.

Mike Vizard · Jul 25, 2025
Blogs

Bitrise to Invest $3M in DevOps Cloud for Mobile Apps in EU

Bitrise, a provider of a DevOps platform for building mobile applications, plans to invest $3 million to create data centers in the European Union (EU) that meet sovereign cloud requirements. Company CEO Barnabás Birmacher said Bitrise has spent much of the past year integrating its stack and consolidating the infrastructure it needs to support its […]

Mike Vizard · Jul 2, 2025