DevOps.com, Friday, September 18th, 2026
Why Your CI/CD Pipeline Is Your Most Unprotected Attack Surface
CI/CD pipelines represent critical security vulnerabilities due to privileged access and automated code execution.
more →
269 articles · page 1 of 6
DevOps.com, Friday, September 18th, 2026
CI/CD pipelines represent critical security vulnerabilities due to privileged access and automated code execution.
more →
DevOps.com, Friday, September 18th, 2026
Strategic outsourcing decisions should prioritize capability and velocity over cost, with hybrid models offering optimal balance.
more →
DCIG, Thursday, September 17th, 2026
AI agents with legitimate credentials pose data risks requiring independent, immutable backups.
more →
DevOps.com, Wednesday, September 16th, 2026
SecMLOps applies DevSecOps controls to ML pipelines for auditable security evidence.
more →
DevOps.com, Wednesday, September 16th, 2026
Framework for balancing AI automation with human oversight in incident response through three trust levels.
more →
DevOps.com, Wednesday, September 16th, 2026
System outages can occur when healthy components interact unsafely, not just from individual failures.
more →
DevOps.com, Tuesday, September 15th, 2026
Risk-based testing prioritizes critical failures over exhaustive coverage for better release quality.
more →
DevOps.com, Friday, September 11th, 2026
Five August incidents traced to capacity saturation, retry storms and database bottlenecks as Actions and Copilot usage surged.
more →
DevOps.com, Friday, September 11th, 2026
Optimizing the CI/CD pipeline locally can miss the system constraint that Flow, Feedback and Learning were meant to find.
more →
DevOps.com, Thursday, September 10th, 2026
Determining exploitability needs deterministic graph traversal of the supply chain, not language model inference.
more →
DevOps.com, Wednesday, September 9th, 2026
AI made code and test generation cheap, but verification and judgment stayed expensive, shifting the delivery bottleneck to review.
more →
DevOps.com, Wednesday, September 9th, 2026
AI speeds code generation, but larger pull requests and unchanged pipelines make verification the new DevOps constraint.
more →
DevOps.com, Wednesday, September 9th, 2026
Only 46 percent of 2,300 Rust developers use a debugger; 81 percent reach for print statements instead.
more →
DevOps.com, Wednesday, September 9th, 2026
CVE-2026-82533 let unauthenticated attackers bypass sandbox restrictions through host header spoofing.
more →
DevOps.com, Tuesday, September 8th, 2026
Apica Ascent 3.0 adds the Venn AI agent and an MCP server for natural-language telemetry pipeline management.
more →
DevOps.com, Friday, September 4th, 2026
Right-sizing, pipeline efficiency and progressive rollouts cut carbon as a side effect of good engineering.
more →
DevOps.com, Friday, September 4th, 2026
Cutting telemetry to cut cost strips out the exact signals you need for rare failures and AI-written code.
more →
DevOps.com, Thursday, September 3rd, 2026
Observability 2.0: Why DevOps Teams Are Moving From Monitoring to Intelligent System Understanding
more →
DevOps.com, Thursday, September 3rd, 2026
From the Horse's Mouth: Anthropic Says AI Has Changed the SDLC
more →
DevOps.com, Wednesday, September 2nd, 2026
The pull request has become the control point for infrastructure change across Kubernetes and cloud services.
more →
DevOps.com, Tuesday, September 1st, 2026
Trusted Open Source Catalogs for AI and Developers
more →
DevOps.com, Monday, August 31st, 2026
From Operator to Agent Manager: The Real Shift in Network Engineering
more →
DevOps.com, Friday, August 28th, 2026
Pillar Security exploited a prompt injection in Google's Gemini CLI to gain unauthorized cloud access.
more →
DevOps.com, Friday, August 28th, 2026
Treating TLS certificate renewal as a full deployment workflow, not a scheduled task, prevents silent outages.
more →
DevOps.com, Thursday, August 27th, 2026
Attackers are planting prompt-injection payloads in repos and READMEs to hijack AI coding agents into running malware.
more →
DevOps.com, Thursday, August 27th, 2026
Enterprise releases need production validation as a business-control layer beyond traditional testing.
more →
DevOps.com, Wednesday, August 26th, 2026
Alert correlation is not diagnosis; trustworthy incident AI needs causal reasoning and good postmortem data.
more →
DevOps.com, Wednesday, August 26th, 2026
AI-generated infrastructure code carries a measurable security gap that CI/CD pipelines must gate for.
more →
DevOps.com, Tuesday, August 25th, 2026
Backend monitoring alone misses frontend performance problems that damage user experience and revenue.
more →
DevOps.com, Tuesday, August 25th, 2026
Competing AI coding agents look different depending on which metric you use to measure the market.
more →
DevOps.com, Tuesday, August 25th, 2026
Sonatype found 91 patched Spring Framework vulnerabilities affecting over 209,000 components from Broadcom.
more →
DevOps.com, Tuesday, August 25th, 2026
Java and Jakarta EE already provide the foundations for integrating AI into enterprise applications.
more →
DevOps.com, Tuesday, August 25th, 2026
CI/CD pipelines must treat models, features, and data as first-class versioned production artifacts.
more →
DevOps.com, Monday, August 24th, 2026
Drew Thompson argues measuring AI coding tools by token consumption is as flawed as counting lines of code.
more →
DevOps.com, Monday, August 24th, 2026
A Jenkins fleet control plane cut administrative overhead through centralized automation and observability.
more →
DevOps.com, Monday, August 24th, 2026
Agencies should redesign infrastructure for agentic AI around workflows rather than hardware purchases.
more →
DevOps.com, Friday, August 21st, 2026
Traditional SRE metrics stay green while an AI system fails customers, so evals are needed before release, in CI and on live traffic.
more →
DevOps.com, Friday, August 21st, 2026
Post-quantum migration starts with discovering where vulnerable cryptography exists, which requires a continuous cryptographic inventory.
more →
DevOps.com, Friday, August 21st, 2026
AI test generators produce too many tests while missing boundary and business-logic cases; separating judgment from mechanics helps.
more →
DevOps.com, Friday, August 21st, 2026
DevOps.com argues stage-gated waterfall becomes useful again as a lightweight control structure over fast AI-generated work.
more →
DevOps.com, Wednesday, August 19th, 2026
OpenTelemetry delivers vendor-neutral instrumentation but carries significant ongoing operational labor.
more →
DevOps.com, Wednesday, August 19th, 2026
A study finds no universal best model for secure code, and higher cost does not mean safer output.
more →
DevOps.com, Monday, August 17th, 2026
GitHub's Copilot update lets developers switch AI models mid-session rather than committing to one.
more →
TechTarget, Tuesday, August 19th, 2025
Developers push back on AI because it redefines the job, not because they fear losing it.
more →
TechTarget, Tuesday, August 19th, 2025
When 40 alerts fire for one broken payment service, correlation is the bottleneck, not detection.
more →
TechTarget, Tuesday, August 19th, 2025
A ten-step guide for developers building fully homomorphic encryption applications that compute on encrypted data.
more →
TechTarget, Tuesday, August 19th, 2025
Autonomous security testing enables continuous proof-based vulnerability detection while local models protect sensitive data.
more →
TechTarget, Tuesday, August 19th, 2025
80% of executives traced a production incident to AI-generated code in the past year.
more →
TechTarget, Tuesday, August 19th, 2025
AI is transforming DevOps by embedding intelligent automation into CI/CD, incident response, and infrastructure management.
more →
TechTarget, Tuesday, August 19th, 2025
Standardized environments alone cannot eliminate inconsistencies across host systems, CI, and external services.
more →