Tag: CI/CD security
DevSecOps Teams as Partners in Secure Software Delivery
DevSecOps teams can reduce last-minute release delays by shifting security decisions earlier, improving guardrails, clarifying ownership and making findings actionable ...
GitHub Separates Who Writes Code From Who Runs Your CI
GitHub’s new workflow execution protections let teams control who and what can trigger Actions workflows, reducing CI/CD attack paths and tightening pipeline security ...
Why Your CI/CD Pipeline Is Your Most Unprotected Attack Surface
CI/CD pipelines often hold privileged credentials, execute third-party code and connect directly to production, making pipeline security one of the most overlooked risks in modern DevOps ...
More JFrog Artifactory Bugs Are Under Attack, and All Three Have Patches
Attackers are actively exploiting three JFrog Artifactory flaws, exposing how slow patching can turn artifact repositories into software supply chain attack paths ...
GitLab’s Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing
GitLab patches two critical flaws, including a CVSS 10.0 unauthenticated file-read vulnerability, putting self-managed instances under urgent pressure to upgrade ...
AI Can Generate Your Infrastructure. Can Your CI/CD Pipeline Trust It?
AI-generated infrastructure code is exposing a growing security gap, pushing platform teams to add stronger automated gates, provenance tracking and human review before Terraform, Kubernetes and CI/CD changes reach production ...
Why Cryptographic Inventory Is the First Step Toward Quantum Readiness
Post-quantum readiness starts with visibility. DevOps teams need a continuous cryptographic inventory to map algorithms, keys, certificates, libraries, infrastructure and third-party dependencies before PQC migration begins ...
The Agent Proposes, the Pipeline Disposes: Controls for AI-Authored Change
When agents write code and open pull requests faster than humans can read them, ‘the diff looked fine’ stops being a control. The durable controls live outside the agent’s reasoning loop ...
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
GitHub and PyPI are using time as a security control, delaying dependency updates and locking older releases against new file uploads ...
The Trust Graph: Why Infrastructure Diagrams No Longer Describe Modern Systems
Traditional architecture diagrams miss the identity relationships that now drive breaches and outages. Platform teams need trust graphs that map who and what can act across modern systems ...
Zero Trust Starts at the Code: Building Secure Systems with PKI and DevOps Automation
When a certificate expires, it can take down a production system, and teams usually only find out after something goes wrong. These issues are hard to catch because they rarely trigger alerts ...
Why Developer Workstations Have Become a Critical Part of the Software Supply Chain
For years, software supply-chain security discussions focused on centralized infrastructure such as build servers, package registries, and CI/CD systems. Recent attacks suggest that this view is incomplete. The Megalodon campaign injected malicious ...

