Skip to content
Topic

#Devsecops

17 articles on Devsecops — news, releases, guides and analysis from the SourceFeed engine.

npm's Frictionless Publish Era Is Over
Article 5d ago 0

npm's Frictionless Publish Era Is Over

GitHub's new npm and Actions defaults trade release speed for survivability — and the signing debate misses why.

Emeka Okafor
Shai-Hulud Returns, and Provenance Signed the Malware

Shai-Hulud Returns, and Provenance Signed the Malware

Article · 1w ago5
Build a Private Harbor Registry That Blocks Vulnerable Images

Build a Private Harbor Registry That Blocks Vulnerable Images

Tutorial · 1w ago0
npm Breaks Its Oldest Promise to Kill the Worm

npm Breaks Its Oldest Promise to Kill the Worm

Article · 2w ago4
You Never Had the Scans GitHub Just Paywalled

You Never Had the Scans GitHub Just Paywalled

Article · 2w ago2
Why You Need a Vulnerability Harness, Not a Security Agent

Why You Need a Vulnerability Harness, Not a Security Agent

Article · 1mo ago0
How to Stop AI Agents From Committing Your Secrets

How to Stop AI Agents From Committing Your Secrets

Article · 1mo ago0
Stop GitHub Copilot From Sabotaging Your Terraform Security

Stop GitHub Copilot From Sabotaging Your Terraform Security

Article · 1mo ago2
When Seven AI Security Gates All Say LGTM

When Seven AI Security Gates All Say LGTM

Article · 1mo ago2
The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

Article · 1mo ago0
Vulnerability Reports Lost Their Privilege. Now What?

Vulnerability Reports Lost Their Privilege. Now What?

Article · 1mo ago3
Catch Risky Code Before It Merges: Add Semgrep SAST to Your GitHub Actions Pipeline

Catch Risky Code Before It Merges: Add Semgrep SAST to Your GitHub Actions Pipeline

Tutorial · 1mo ago0
Agentjacking: How Public Sentry Keys Turn AI Coding Agents Into Trojan Horses

Agentjacking: How Public Sentry Keys Turn AI Coding Agents Into Trojan Horses

Article · 1mo ago4
Securing AI Agents: Inside NVIDIA's SkillSpector Scanner

Securing AI Agents: Inside NVIDIA's SkillSpector Scanner

Article · 1mo ago3
The AUR Namespace Trap: Lessons from the Atomic Arch Attacks

The AUR Namespace Trap: Lessons from the Atomic Arch Attacks

Article · 1mo ago5
The GitHub Clone Farm That Beat VirusTotal

The GitHub Clone Farm That Beat VirusTotal

Article · 1mo ago2