News
Fast-Moving Shai-Hulud Attack Infects npm Packages with 2 Billion Monthly Downloads
Researchers at Aikido Security and Endor Labs are tracking a fast-spreading supply-chain attack that is compromising a wide range of npm software packages that combined have more than 2 billion installs a ...
N. Korea Group Behind Multiple Open Source Supply-Chain Attacks: Amazon
Amazon’s recent report attributing a series of compromises of open source software libraries to a North Korea-backed threat group encapsulates many of the expanding cyber risks increasingly facing developers, from the growing ...
Ten Great DevOps Job Opportunities
DevOps.com is now providing a weekly DevOps jobs report through which opportunities for DevOps professionals will be highlighted as part of an effort to better serve our audience. Our goal in these ...
Microsoft Confirms Copilot ‘Super App’ Is Coming This Year — and It’s About More Than Convenience
Microsoft is combining Copilot Chat, Code, Cowork and Autopilots into one super app, raising new questions about agent governance, identity, licensing and security ...
JetBrains Open-Sources KotlinLLM, a Research Prototype for Runtime Code Generation
JetBrains open-sources KotlinLLM, letting compiled Kotlin apps generate and persist LLM-written code at runtime instead of calling a model live ...
GitHub Brings Stacked Pull Requests Out of the Shadows
GitHub introduces native stacked pull requests, helping development teams break large changes into smaller, dependency-ordered PRs that are faster and easier to review ...
CISA’s 2026 SBOM Guidance Adds Hash Requirements and AI Coverage
CISA’s updated 2026 SBOM minimum elements expand software transparency requirements to AI, SaaS and open source while adding hashes, licenses and stronger validation ...
Tricentis Acquires Tabnine to Gain Knowledge Graph for AI Testing Agents
Tricentis today revealed it is acquiring Tabnine to gain access to a knowledge graph that will be used to provide context to AI agents that have been trained to automate a range ...
OpenAI Open Sources Codex Security CLI for the Merge Path
OpenAI has released its Codex Security command-line interface and software development kit as open source software under the Apache 2.0 license, providing a new way to bring its AI security scanner into ...
GitHub Gives Teams More Control Over Copilot’s Cloud Agent in Linear
GitHub’s Copilot cloud agent integration with Linear is now generally available, adding model, branch and team-level controls for delegated coding work ...
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
GitHub and PyPI are using time as a security control, delaying dependency updates and locking older releases against new file uploads ...
CodePen 2.0 Turns a Design Playground Into a Real Deployment Tool
CodePen 2.0 transforms the front-end playground into a file-based development platform with collaboration, version history and one-click deployment ...

