News

GitHub Action Compromise Risks Data Leaks for 23,000 Repositories
The attacker introduced malicious Python code that would expose secrets like authentication credentials in public repositories ...

Five Great DevOps Job Opportunities
The five DevOps job postings shared this week include opportunities at Spotify, Ace Hardware Corp., and Boeing Intelligence and Analytics ...

Semaphore Goes Open Source: A New Dawn for DevOps Professionals
Semaphore's CI/CD platform goes open source under Apache 2.0, offering DevOps professionals a scalable solution without vendor lock-in. Explore how this changes the game ...

Consortium Driving OpenStack to Become Arm of The Linux Foundation
The Open Infrastructure Foundation (OpenInfra), which oversees the development of the open source OpenStack cloud computing framework, this week agreed to become an arm of The Linux Foundation as part of an ...

Cycloid Adds Ability to Customize Components of a Software Stack to DevOps Platform
Cycloid today extended its platform for managing and governing software engineering workflows to provide DevOps teams with more granular control over how stacks of software components are constructed and managed ...

Eclipse Foundation to Release Open Source IDE Infused with AI Agents
The Eclipse Foundation today made available an alpha release of an instance of its open source Theia integrated development environment (IDE), that provides access to artificial intelligence (AI) agents that will automate ...

Sonar Combines SAST and SCA Tools in Single Offer
Sonar today revealed it will at the end of May add an offering that combines its Static Application Security Testing (SAST) tool with the software composition analysis (SCA) tools it gained with ...

Analysis of GitHub Repositories Surfaces Nearly 23M Secrets
An analysis of public GitHub repositories published today finds 22.8 million hardcoded secrets, representing a 25% increase since a similar study was done a year ago ...

Synopsys Accelerates Software-Defined Product Development with Virtualizer Native Execution on Arm
Synopsys' new Virtualizer Native Execution on Arm hardware significantly speeds up virtual prototyping for automotive, HPC and IoT development workflows ...

GitHub’s Enhanced Pull Request Merge Experience: Streamlining the DevOps Workflow
GitHub enhances the pull request experience with logical check grouping, improved rule enforcement and better accessibility — making DevOps workflows more efficient and intuitive ...

Survey Surfaces Lack of DevOps Visibility into Consumption of Cloud Infrastructure
A survey of engineering leaders and developers from the U.S. and United Kingdom (UK) conducted by Harness finds less than half have access to real-time insights into idle cloud resources (43%), unused ...

DeepSource Open Sources Globstar Alternative to Semgrep to Analyze Code
DeepSource has made available an open source static code analysis tool, dubbed Globstar, that DevSecOps teams can employ to embed code checkers in their pipelines ...