News
Bad Actor Drops 36 Malicious Packages in npm, Targets Guardarian Users
The npm code repository is again being used by a bad actor to launch a supply chain attack that includes three dozen malicious packages that appear as Strapi CMS plugins but deliver ...
Five Great DevOps Job Opportunities
Explore this week’s top DevOps and Platform Engineering roles. From $300k Cloud Engineering in Maryland to cutting-edge Agentic AI positions at T-Mobile ...
Survey Surfaces Increased Reliance on Open Source Software to Build Apps
Open source adoption is surging, with 49% of IT teams increasing usage. However, 47% of staff spend 75% of their time on maintenance. Explore the impact of AI threats and EU regulations ...
Developers Using Anthropic Claude Code Hit by Token Drain Crisis
Anthropic’s Claude Code users report Max tier quotas exhausting in under 20 minutes. Explore the "Cache-22" of prompt caching, session limits, and why AI coding "opacity" is stalling developer workflows ...
North Korean Hackers Suspected in Supply Chain Attack on Popular Axios Project
The threat actor targeted a highly popular open source project with more than 100 million weekly downloads, creating a large "blast radius." ...
Harness Extends CD Platform to Address AI Coding Challenges
Harness expands its CD platform to tackle the "AI code explosion" with automated rollbacks, snowflake support, and warehouse-native feature management ...
OpenTelemetry Gets Kotlin Multiplatform API & SDK
OpenTelemetry expands its observability reach with a native Kotlin Multiplatform API and SDK. Contributed by Embrace, this update enables vendor-neutral telemetry across JVM, iOS, and web, offering idiomatic Kotlin support and optimized ...
Tekton Kubernetes-Native CI/CD Project Reaches CNCF Incubation
The CNCF TOC has voted to accept Tekton as an incubating project. As a Kubernetes-native framework for CI/CD, Tekton enables developers to build, test, and deploy across clouds by treating pipelines as ...
Five Great DevOps Job Opportunities
Explore this week’s top DevOps career opportunities featuring roles at SAP, Maximus, Inc., and Bellota Labs. Salaries range from $115k to $337k for senior and lead positions ...
Sophisticated Supply Chain Attack Targeting Trivy Expands to Checkmarx, LiteLLM
The supply chain attack that compromised Aqua Security’s Trivy open source security vulnerability scanner and its associated GitHub Actions earlier this month continues to expand, with software development tools from Checkmarx and ...
Five Great DevOps Job Opportunities
Explore the latest DevOps.com weekly jobs report. Highlighting premier opportunities at Bank of America, Microsoft, and GEICO, with salary insights up to $300,000 for senior engineering and platform leadership roles ...
Two Malicious npm Packages Aim to Steal Credentials and Other Secrets
Bad actors took over a npm maintainer account and have published two malicious packages designed to steal credentials, API keys, and other secrets from the computers of victims who download them from ...

