DevOps.com

  • Latest
    • Articles
    • Features
    • Most Read
    • News
    • News Releases
  • Topics
    • AI
    • Continuous Delivery
    • Continuous Testing
    • Cloud
    • Culture
    • DataOps
    • DevSecOps
    • Enterprise DevOps
    • Leadership Suite
    • DevOps Practice
    • ROELBOB
    • DevOps Toolbox
    • IT as Code
  • Videos/Podcasts
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • DevOps Unbound
  • Webinars
    • Upcoming
    • On-Demand Webinars
  • Library
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Related Sites
    • Techstrong Group
    • Container Journal
    • Security Boulevard
    • Techstrong Research
    • DevOps Chat
    • DevOps Dozen
    • DevOps TV
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
  • Media Kit
  • About
  • Sponsor
  • AI
  • Cloud
  • Continuous Delivery
  • Continuous Testing
  • DataOps
  • DevSecOps
  • DevOps Onramp
  • Platform Engineering
  • Low-Code/No-Code
  • IT as Code
  • More
    • Application Performance Management/Monitoring
    • Culture
    • Enterprise DevOps
    • ROELBOB
Hot Topics
  • DevOps Flow: Accelerating Velocity With Software Factory Best Practices
  • Survey: More Cybersecurity Pros Embedded in DevOps Teams
  • The Impact of Developer Happiness on Productivity
  • AWS Delivers on Latest Graviton3 Price/Performance Promise
  • Five Tips for Moving IT Ops to DevOps

Tag: secure code

software DevOps jobs secrets Libbpf BCC BPF kernel developer citizen secure software

Report Identifies Top 10 Open Source Software Risks

Avatar photoMike Vizard | March 6, 2023 | developers, Endor Labs, open source, oss, secure code, software
Endor Labs, a provider of a platform for managing open source software, published a report that classifies the top 10 open source software risks of 2023. The company published the list as ...
DevSecOps business SDLC Integrating Security in the Development Process with DevSecOps

Benefits and Challenges of DevSecOps for Business

Avatar photoKevin Kirkwood | February 22, 2023 | breach, devsecops, hackers, secure code, vulnerabilities
Almost every day, there is a new tactic or technique discovered that hackers can use to disrupt a company’s systems, obtain critical data and information or steal money. Often attackers look to ...
Rezilion DevOps radar

Rezilion Updates Open Source MI-X Tool to Better Secure App Development

Avatar photoMike Vizard | December 19, 2022 | application security, Rezilion, secure code, Software Supply Chain, vulnerability scanning
Rezilion has updated its open source MI-X vulnerability discovery tool to include mitigation and remediation recommendations. In addition, the tool can now produce machine-readable output in either a JSON or CSV format ...
How SASE Can Ease DevSecOps Adoption

How SASE Can Ease DevSecOps Adoption

Gilad David Maayan | December 19, 2022 | devsecops, edge computing, SASE, secure code
DevSecOps is a software development methodology that merges development (Dev), security (Sec) and operations (Ops) into one team that integrates security throughout the entire software development life cycle (SDLC). The goal is ...
shift left Jit Rezilion DevSecOps Shifting Left and Static Code Analysis with Perforce

Shift Left Testing in Microservices Environments

Avatar photoAnirudh Ramanathan | December 13, 2022 | continuous testing, microservices, secure code, shift left, testing
By now, it’s common knowledge that the later a bug is detected in the software development life cycle (SDLC), the longer it takes and the more expensive it is to fix that ...
open source coding Coder Accelerate Digital Transformation with Low-Code

Massive Number of Transitive Dependencies Traced to Open Source Code

Avatar photoMike Vizard | December 12, 2022 | dependencies, open source, secure code, transitive dependencies, vulnerabilities
An analysis of nearly 2,000 software packages published by Endor Labs found 95% of all application vulnerabilities can be traced back to a transitive dependency created when a developer used an open ...
open source Web GitHub DevSecOps security Dynatrace Sophos Web Isolation and Secure Web Gateways with Menlo Security

How Devs Can Improve Open Source Security in the Enterprise

Avatar photoNitzan Miron | December 8, 2022 | devsecops, open source, open source security, secure code
Modern applications are dynamic. They’re distributed and they’re often born in the cloud. These applications can be developed on the fly, spun up and scaled quickly to meet evolving user and market ...
Data GraphQL API Dynatrace

GraphQL Vulnerability Analysis: The Top Threats

Avatar photoShahar Binyamin | December 1, 2022 | code vulnerabilities, GraphQL, MITRE, secure code
Publicly available vulnerability data can be a goldmine for insights into how DevOps and DevSecOps teams can prioritize threats and improve security across the pipeline. With this in mind, Inigo recently performed ...
Rezilion Cisco serverless windows

Cisco Adds Open Source Tool to Validate Serverless Functions

Avatar photoMike Vizard | November 8, 2022 | Cisco Systems, code signing, open source, secure code, serverless
Cisco has launched an open source project, dubbed FunctionClarity, that makes it possible to verify signatures before code is deployed in a serverless computing environment. Vijoy Pandey, vice president of emerging technologies ...
risk Sigstore GraphQL security Checkmarx Sonatype WhiteSource the secure software development

GraphQL: Security by Obscurity Just Isn’t Enough

Avatar photoBill Doerrfeld | October 13, 2022 | APIs, authorization management, GraphQL, secure code, software security
The debate about how to secure GraphQL rages on. Many organizations are hesitant to adopt GraphQL for public-facing APIs as there is no precise method to handle authorization concerns as of yet ...
Aqua DevSecOps, federal agencies

Federal Agencies Share DevSecOps Guidelines

Avatar photoMike Vizard | September 6, 2022 | CISA, Cybersecurity, devsecops, ESF, secure code
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the Office of the Director of National Intelligence (ODNI) have published a set of DevSecOps best practices based on the Enduring ...
cybersecurity threats API security, JIT JUst in time security APIs What is the NIST Cybersecurity Framework

How DevOps Teams Can Defend Against API Attacks

Avatar photoPratik Roychowdhury | July 20, 2022 | APIs, devsecops, Ransomware, secure code
Remember when ransomware was the main security threat that DevOps teams needed to worry about? Those days are over. Ransomware attacks are certainly still happening, but API security breaches—which increased by a ...
Show More Loading...

Techstrong TV – Live

Click full-screen to enable volume control
Watch latest episodes and shows

Upcoming Webinars

Getting Kubernetes Costs Under Control
Wednesday, March 8, 2023 - 1:00 pm EST
Terraform Cloud Workshop: Security Beyond Static Misconfiguration Checking
Thursday, March 9, 2023 - 11:00 am EST
The State of Infrastructure-as-Code (IaC) 2023
Thursday, March 9, 2023 - 3:00 pm EST

Sponsored Content

The Google Cloud DevOps Awards: Apply Now!

January 10, 2023 | Brenna Washington

Codenotary Extends Dynamic SBOM Reach to Serverless Computing Platforms

December 9, 2022 | Mike Vizard

Why a Low-Code Platform Should Have Pro-Code Capabilities

March 24, 2021 | Andrew Manby

AWS Well-Architected Framework Elevates Agility

December 17, 2020 | JT Giri

Practical Approaches to Long-Term Cloud-Native Security

December 5, 2019 | Chris Tozzi

Latest from DevOps.com

DevOps Flow: Accelerating Velocity With Software Factory Best Practices
March 7, 2023 | Neil McEvoy
Survey: More Cybersecurity Pros Embedded in DevOps Teams
March 7, 2023 | Mike Vizard
The Impact of Developer Happiness on Productivity
March 7, 2023 | Aaron Upright
AWS Delivers on Latest Graviton3 Price/Performance Promise
March 6, 2023 | Mike Vizard
Five Tips for Moving IT Ops to DevOps
March 6, 2023 | Itzik Reich

TSTV Podcast

On-Demand Webinars

DevOps.com Webinar ReplaysDevOps.com Webinar Replays

GET THE TOP STORIES OF THE WEEK

Most Read on DevOps.com

LinkedIn Job Scams: Out of Hand ¦ 4-Day Workweek: Let’s Get Serious
March 2, 2023 | Richi Jennings
How GitHub Actions Simplifies Your CI/CD Workflow
March 2, 2023 | Sirish Patel
Despite Tech Layoffs, Developer Shortage Continues
March 2, 2023 | George V. Hulme
Why You Need to Break the Observability Data Silo
March 1, 2023 | Chris Cooney
Sysdig Launches Wireshark Foundation
March 2, 2023 | Mike Vizard
  • Home
  • About DevOps.com
  • Meet our Authors
  • Write for DevOps.com
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • Privacy Policy

Powered by Techstrong Group, Inc.

© 2023 ·Techstrong Group, Inc.All rights reserved.