↵ select ↓ ↑ navigate esc close

DevOps.com

npub13egq5ynwls09z359jzac4phfnee7kh0jw5jq7vuvajxqlwh65e6s5p0eur@drss.io

Where the world meets DevOps

https://devops.com/

Keeping Humans Accountable as AI Agents Take On the SDLC

28 Sep 2026

Ming Wu joins Alan Shimel to explain governed agent loops, shared context and traceability across AI-assisted development, with people remaining accountable for the results.

Headless DevOps Gives AI Agents Access to Delivery Workflows

28 Sep 2026

Federico Larsen joins Alan Shimel to examine agent-accessible delivery workflows, API and MCP interfaces, and the testing and security checks needed for headless DevOps.

Docker Introduces Open Sandbox Kit Spec for AI Agent Permissions

28 Sep 2026

AI agents are getting good at probing the boundaries developers put around them. Their ability to improvise makes them hard to contain. “You ask for something in a very high-level, vague-at-best

Survey: Lack of Confidence in Software Supply Chain Security Runs High

28 Sep 2026

A survey of 400 platform and security engineers in the U.S and United Kingdom (UK), finds nearly three quarters (73%) are either only moderately confident (58%) or not confident (15%) in the ability

DHH Declares End of Hand-Writing Code at Rails World 2026

28 Sep 2026

Controversial developer David Heinemeier Hansson (aka DHH) announced last week at Rails World 2026 that the end of handwritten code is upon us, calling it the modern era’s “Brownie” moment. The

Ten Great DevOps Job Opportunities

28 Sep 2026

DevOps.com is now providing a weekly DevOps jobs report through which opportunities for DevOps professionals will be highlighted as part of an effort to better serve our audience. Our goal in these

GitHub’s Security Autofix Agent Now Remembers What It Fixed

28 Sep 2026

GitHub’s agentic autofix now uses Copilot Memory to reuse repository-specific security fix patterns, helping Copilot apply lessons from past vulnerabilities across future alerts, reviews and coding

Leaked GitLab Email Tokens Can Reach Code, Secrets and CI/CD Pipelines

25 Sep 2026

Security researchers have uncovered a GitLab behavior that could let attackers use a leaked project email address to push code, trigger CI/CD jobs and reach other repositories accessible to the

Blitzy Makes Sandbox for Reverse Engineering Code Available at No Cost

25 Sep 2026

Blitzy has made available a sandbox where DevOps teams can reverse-engineer up to one million lines of code, generate up to 25,000 lines of tested end-to-end code, and identify security

Dependency Mocking Approach That Gets More Accurate as Your Services Deploy More Often

25 Sep 2026

Traffic-based dependency mocking turns frequent upstream deployments into opportunities to refresh mocks from real behavior and reduce integration test drift.

Why Old Azure DevOps Releases Survive a Pipeline Cutover

25 Sep 2026

Old Azure DevOps Classic releases can retain retired deployment tasks, Helm names, image paths and variables long after a pipeline cutover, leaving stale redeploy paths active.

DevSecOps Teams as Partners in Secure Software Delivery

25 Sep 2026

DevSecOps teams can reduce last-minute release delays by shifting security decisions earlier, improving guardrails, clarifying ownership and making findings actionable.

Why Plan Review Stopped Working

24 Sep 2026

The control that held your infrastructure together was plan review, meaning a person reading a diff and deciding whether to approve it. Not the policy document and not the pipeline configuration. It

Smoothing the Never-Ending Road to Modernization

24 Sep 2026

In IT, it can sometimes feel like the finish line keeps getting farther away, no matter how fast we run. Cloud migration reshaped how organizations think about infrastructure, offering new

Talentica Software Unfurls Managed AI Service to Optimize Software Delivery

24 Sep 2026

Talentica Software this week launched a managed software delivery service that leverages artificial intelligence (AI) to enable DevOps teams to deploy applications developed using AI coding tools at

Why Software Supply Chain Security Is Moving to the Gate

24 Sep 2026

March 2026: malicious versions of axios get published directly to npm. May 2026: attackers forge valid provenance for 42 TanStack packages on npm, with 84 malicious versions shipped before detection.

What I Learned Building Cloud-Portable Services Across Multiple Providers

24 Sep 2026

Multi-cloud strategies often stumble over provider-specific behavior. A layered abstraction built on official SDKs can normalize differences while preserving access to valuable native capabilities.

The Observability Tax: When Monitoring Costs Exceed Downtime Costs

24 Sep 2026

Observability costs can spiral when teams collect more telemetry than they actually use. A more mature approach prioritizes the data that directly improves incident detection, diagnosis and recovery.

GitHub Gives Enterprises a Full Count of Who Holds the Keys

24 Sep 2026

GitHub Enterprise Cloud now lets organizations export a full inventory of credentials, helping security teams identify stale, overprivileged and forgotten access across users, apps and automation.

TeamPCP Supply Chain Attack Leads to CrowdSec Source Code Being Stolen

24 Sep 2026

CrowdSec says attackers stole source code from about 170 private GitHub repositories after a TanStack npm supply chain attack exposed an OAuth token tied to a former employee.

Why DNS Needs to Be Treated as Critical Infrastructure

23 Sep 2026

DNS is one of those infrastructure components that only gets attention when something breaks, and by then, the damage is already done. An application may appear healthy, servers may be reachable, and

Speeding Up Software Delivery Is Changing How We Debug Performance

23 Sep 2026

Deployment frequency has become one of the clearest markers of a mature engineering organization. Teams that once shipped monthly now ship daily, and teams that shipped daily now ship several times a

AWS Adds Harness to Open Source SDK for Building AI Agents

23 Sep 2026

Amazon Web Services (AWS) this week revealed it has added a harness to the open source software development kit (SDK) it makes available for building artificial intelligence (AI) agents. First

Avalara Ushers in New Era of Agentic Tax and Compliance with Avalara Aviator

23 Sep 2026

Avalara’s new agent hub brings together specialized AI agents to execute complex tax and compliance workflows while keeping people in control of the decisions that matter. FORT LAUDERDALE, Fla. —

Cycode Extends DevSecOps Reach to Software Packages Developers Download

23 Sep 2026

Cycode is adding workstation-level protection to stop developers and AI coding agents from downloading malicious or insufficiently vetted software packages.

Your AI Coding Assistant Has the Keys to the Repo. Z.ai Just Showed Why That Matters

23 Sep 2026

ZCode’s default-on indexing feature reportedly uploaded entire developer workspaces to cloud storage, highlighting why AI coding assistants should be treated as privileged software and closely

Why Shift Left is Dead

23 Sep 2026

AI-driven development is exposing risks before code is written, forcing security teams to move beyond shift-left and govern agents, prompts, tools and data across the entire development lifecycle.

New npm Threat Bypasses Install Script Protections

22 Sep 2026

A malicious npm package that has been downloaded millions of times comes with a new way of spreading the malware that makes it easier to bypass security protections, say researchers with security

Ten Great DevOps Job Opportunities

22 Sep 2026

DevOps.com is now providing a weekly DevOps jobs report through which opportunities for DevOps professionals will be highlighted as part of an effort to better serve our audience. Our goal in these

GitLab Tightens Rate Limits as Coding Agents Drive Demand

21 Sep 2026

GitLab is introducing new rate limits for its cloud-based DevOps platform as growing demand from AI agents and automated development tools increases pressure on its infrastructure. The changes, which

Codex Sandbox Escapes Show Why Agent Guardrails Can’t Live Inside the Agent

21 Sep 2026

Two patched OpenAI Codex vulnerabilities, Heapjack and Overpatch, exposed how coding agents can escape sandboxes and reach developer systems without approval prompts.

Claude Code Adds AGENTS.md Fallback, Cutting Instruction File Sprawl

21 Sep 2026

Claude Code now supports AGENTS.md, giving development teams a shared instruction format across multiple AI coding agents and reducing configuration drift.

GitHub Separates Who Writes Code From Who Runs Your CI

21 Sep 2026

GitHub’s new workflow execution protections let teams control who and what can trigger Actions workflows, reducing CI/CD attack paths and tightening pipeline security.

US District Court Decision in AI’s Favor Worries Open-Source Developers

18 Sep 2026

A federal appeals court handed GitHub, Microsoft, and OpenAI an important win in the first major appellate ruling over how AI coding tools can use open-source code. As we all know, all the AI

Splunk Open Sources Token Meter Tool for Application Developers

18 Sep 2026

Splunk’s open-source Token Meter gives developers real-time visibility into AI coding agent activity, token consumption and estimated costs across tools including Claude Code, Codex and Cursor.

IT Outsourcing Versus In-House Development

18 Sep 2026

The debate isn’t new — but the stakes are. In 2026, the gap between companies that get this decision right and those that don’t is measured in product cycles, burn rate, and competitive ground

Why Your CI/CD Pipeline Is Your Most Unprotected Attack Surface

18 Sep 2026

CI/CD pipelines often hold privileged credentials, execute third-party code and connect directly to production, making pipeline security one of the most overlooked risks in modern DevOps.

Anthropic Adds a Coordinator to Claude Projects for Running AI Work in Parallel

18 Sep 2026

Anthropic’s redesigned Claude Projects coordinates parallel Claude Code sessions, delegates work across branches and brings the results back through familiar pull-request review workflows.

Anthropic Brings Parallel Coding Workflows to Claude Projects

17 Sep 2026

Anthropic announced it has redesigned Claude Projects to coordinate multiple coding sessions in parallel, with the new experience debuting in beta for Claude Code users. In the redesigned Projects, a

StackHawk Delivers Wingman to Fix Vulnerabilities as Developers Write Code

17 Sep 2026

StackHawk this week launched Wingman, an artificial intelligence (AI) tool that makes it possible for application developers to automatically fix vulnerability issues as code is being written.

Harness Previews Revamped Platform for the Agentic Engineering Era

17 Sep 2026

Harness today previewed a revamped user interface for its platform for managing software deployments that makes it simpler for software engineers to manage teams of artificial intelligence (AI)

How I Consolidated Duplicate Delivery Pipelines With Parameters and Build Tags

16 Sep 2026

Two modules in a repository had near-identical Azure DevOps build and release definitions. A third would have required another pair. The delivery chain used five definitions: one change decider, two

Splunk Preps Second Open Source LLM for Telemetry Data

16 Sep 2026

Splunk is gearing up to make an artificial intelligence (AI) model for analyzing log data available on Hugging Face under an open source license. Additionally, Splunk at its .conf26 conference this

Can Rust Improve Real Django API Performance? Testing Django-Bolt Beyond Synthetic Benchmarks

16 Sep 2026

Django-Bolt uses Rust to accelerate Django request handling, but real-world gains depend on database work, authentication, serialization and where an API actually spends its time.

Why MLOps Pipelines Need Security Audits

16 Sep 2026

A practical SecMLOps experiment shows how Apache Airflow ML pipelines can adopt DevSecOps controls for secrets, validation, artifact integrity and auditable security evidence.

The Three Tiers of Agentic Incident Response: When to Trust AI Autonomy

16 Sep 2026

A three-tier model for agentic incident response balances AI automation with human oversight, matching autonomy to risk, reversibility, blast radius and diagnostic confidence.

The Most Dangerous Reliability Failures Aren’t Component Failures

16 Sep 2026

A production provisioning failure shows why reliability problems can emerge from interactions between healthy components, and how system-level constraints and feedback can prevent them.

Factory Raises $200M as It Builds Agents Across the Software Lifecycle

15 Sep 2026

Enterprise coding agent startup Factory announced it has raised $200 million at a $5 billion valuation, more than tripling its valuation from its last funding round five months ago. Founded in 2023,

LocalStack Acquires WonderTwin AI to Gain SaaS App Emulation Platform

15 Sep 2026

LocalStack this week revealed it has acquired WonderTwin AI, a provider of an emulator of software-as-a-service (SaaS) applications that is used to build custom applications for those platforms.

Java 27 Tackles Post-Quantum Security and a Faster Patch Cadence

15 Sep 2026

Java 27 strengthens enterprise security with monthly critical patch updates and post-quantum TLS 1.3 support, helping organizations prepare for AI-driven threats and future quantum risks.