FEATURES

Video Interviews

Autonomous Patching for Cloud-Native Workloads

Autonomous Patching for Cloud-Native Workloads

|
The cloud-native stack didn’t make security go away—it just spread it across more layers, more repos, more images, and more ...
KubeCon, cloud native, ai, cloud-native,

From Cloud First to Cloud Fit: Rethinking Where Workloads Belong

|
Induprakas “Indu” Keri explores why organizations are increasingly shifting from a cloud-first mindset to a cloud-fit strategy as containerized applications ...

LATEST FROM DEVOPS.COM

Security as Code is Becoming the New Baseline: Continuous Compliance in DevOps 

There was a time when compliance meant a quarterly ritual. Someone from security would walk over with a spreadsheet, ask a few questions, tick a few boxes and disappear until the next audit cycle. The infrastructure team would scramble to prove that yes, encryption was enabled, and no, that S3 bucket was not public anymore. Everyone felt relieved, […] [...]

Sophisticated Supply Chain Attack Targeting Trivy Expands to Checkmarx, LiteLLM

The supply chain attack that compromised Aqua Security’s Trivy open source security vulnerability scanner and its associated GitHub Actions earlier this month continues to expand, with software development tools from Checkmarx and LiteLLM being the latest victims of the sophisticated campaign. The threat group behind it, TeamPCP, is using the attacks to create persistence and […] [...]

Akuity Adds Ability to Customize Kargo Pipelines

Akuity this week at the KubeCon + CloudNativeCon Europe conference revealed it has added an ability to customize the steps used to promote applications into a production environment using a Kargo orchestration engine it developed to manage software using a GitOps workflow. Company CEO Hong Wang said the Custom Steps capability added to Kargo will […] [...]