FEATURES

Video Interviews

Autonomous Patching for Cloud-Native Workloads

Autonomous Patching for Cloud-Native Workloads

|
The cloud-native stack didn’t make security go away—it just spread it across more layers, more repos, more images, and more ...
KubeCon, cloud native, ai, cloud-native,

From Cloud First to Cloud Fit: Rethinking Where Workloads Belong

|
Induprakas “Indu” Keri explores why organizations are increasingly shifting from a cloud-first mindset to a cloud-fit strategy as containerized applications ...

LATEST FROM DEVOPS.COM

AI-Fueled Development Pushes Open-Source Risk to Extremes: Report

Artificial intelligence has shortened the timeline for software development from months to days. But according to new research, that acceleration is creating significant risks for security and compliance issues. Black Duck’s 2026 Open Source Security and Risk Analysis (OSSRA), based on audits of 947 commercial codebases spanning 17 industries, shows that vulnerabilities inside enterprise applications […] [...]

Harness Readies Resilience Testing Platform to Make Applications More Robust

Harness today revealed that it will make available a set of open source tools for testing the resiliency of applications that are based on a chaos engineering platform the company gained with the acquisition of LitmusChaos. The Harness Resilience Testing platform extends the scope of the tests provided to include application load and disaster recovery […] [...]

Malicious NPM Package Gets Downloaded 50K Times Before Discovery

A malicious package downloaded approximately 50,000 times from a node package manager (npm) is providing an object lesson for adopting more DevSecOps best practices. Security researchers from Tenable discovered a “ambar-src” package that was first published Feb. 13 and then updated again before being discovered. It is aimed at developers building JavaScript applications on Windows, […] [...]