The threat actor targeted a highly popular open source project with more than 100 million weekly downloads, creating a large “blast radius.”
Harness Extends CD Platform to Address AI Coding Challenges
Harness expands its CD platform to tackle the “AI code explosion” with automated rollbacks, snowflake support, and warehouse-native feature management.
OpenTelemetry Gets Kotlin Multiplatform API & SDK
OpenTelemetry expands its observability reach with a native Kotlin Multiplatform API and SDK. Contributed by Embrace, this update enables vendor-neutral telemetry across JVM, iOS, and web, offering idiomatic Kotlin support and optimized performance for mobile and client-side applications.
Tekton Kubernetes-Native CI/CD Project Reaches CNCF Incubation
The CNCF TOC has voted to accept Tekton as an incubating project. As a Kubernetes-native framework for CI/CD, Tekton enables developers to build, test, and deploy across clouds by treating pipelines as standard K8s resources. Originally part of Knative, it now offers a modular ecosystem including Triggers and Chains for supply chain security, integrating deeply with Argo CD and Sigstore.
Five Great DevOps Job Opportunities
Explore this week’s top DevOps career opportunities featuring roles at SAP, Maximus, Inc., and Bellota Labs. Salaries range from $115k to $337k for senior and lead positions.
Sophisticated Supply Chain Attack Targeting Trivy Expands to Checkmarx, LiteLLM
The supply chain attack that compromised Aqua Security’s Trivy open source security vulnerability scanner and its associated GitHub Actions earlier this month continues to expand, with software development tools from Checkmarx and LiteLLM being the latest victims of the sophisticated campaign. The threat group behind it, TeamPCP, is using the attacks to create persistence and […]
Five Great DevOps Job Opportunities
Explore the latest staging-devopsy.kinsta.cloud weekly jobs report. Highlighting premier opportunities at Bank of America, Microsoft, and GEICO, with salary insights up to $300,000 for senior engineering and platform leadership roles.
Two Malicious npm Packages Aim to Steal Credentials and Other Secrets
Bad actors took over a npm maintainer account and have published two malicious packages designed to steal credentials, API keys, and other secrets from the computers of victims who download them from the repository. Analysts with Sonatype’s Security Research Team wrote in a report that the two packages – sbx-mask and touch-adv – likely are […]
OpenAI Bolsters AI Coding with Acquisition of Python Toolmaker Astral
OpenAI announced Thursday that it has reached an agreement to acquire Astral, the startup behind some of Python community’s most popular open-source developer tools. The acquisition marks further escalation in the rapidly evolving artificial intelligence (AI)-assisted development market, which has led to a coding war between OpenAI and its primary rivals, including Anthropic and the […]
Java 26 Arrives With AI Integration and a New Ecosystem Portfolio — What It Means for DevOps Teams
Overview of Java 26 emphasizing performance, concurrency, security, HTTP/3, and the new Java Verified Portfolio—positioning the JVM as a supported infrastructure layer for enterprise AI workloads and easing DevOps modernization of large Java estates.
- « Previous Page
- 1
- …
- 3
- 4
- 5
- 6
- 7
- …
- 172
- Next Page »










