While there is general agreement on the importance of software supply chain security, there is a significant disconnect on how to achieve that goal.
3 Steps to Secure Your CI/CD Pipelines
Palo Alto Networks’ Daniel Krivelevich shares a general three-step framework organizations can use to secure the CI/CD pipeline and surrounding areas.
Summit Highlights Open Source Software Security Progress
The OpenSSF hosted a Secure Open Source Software (SOSS) Summit 2023 event during which it made available a Secure Open Source Software Vision Brief 2023.
Survey Surfaces Spike in Generative AI Usage Across IT
A survey of DevOps and SecOps leaders found nearly all are making use of generative artificial intelligence (AI).
Styra Makes Source Code Available for Enterprise Edition of OPA
Styra is making the Open Policy Agent (OPA) enterprise code available under a license that enables IT teams to modify or change the underlying code as they see fit.
Snyk Survey: AI Generating More Vulnerabilities in Code
A Snyk survey finds the use of artificial intelligence (AI) to write code is creating a software security paradox.
Extending the GitOps Pipeline: DevSecOps and Trusted Application Delivery
The fusion of DevSecOps and trusted application delivery can extend the GitOps pipeline and add business value.
JFrog Adds Curation Capability for Open Source Software Components
JFrog is adding a curation capability for open source software that will use metadata generated by binaries to identify malicious packages and software components with licensing issues.
Unleashing the Power of AI-Engineered DevSecOps
In my recent article Revolutionizing the Nine Pillars of DevOps with AI-Engineered Tools, I explained that AI-engineered tools can help implement the portion of continuous security practices known as DevSecOps. […]
Atlassian Advances DevSecOps via Jira Integrations
Atlassian announced today it has allied with Snyk, Mend, Lacework, Stackhawk and JFrog to make it simpler to aggregate vulnerability data within the Jira project management software that many organizations […]











