DEV Community

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
DevOps Security Gaps in Startups: What Fast-Growing Teams Keep Getting Wrong

DevOps Security Gaps in Startups: What Fast-Growing Teams Keep Getting Wrong

Comments
3 min read
NemoClaw for the Enterprise: Matrix as the Communication Channel (Part 3)

NemoClaw for the Enterprise: Matrix as the Communication Channel (Part 3)

Comments
9 min read
Secret Rotation: 3 Core Principles for Secure Applications

Secret Rotation: 3 Core Principles for Secure Applications

Comments
12 min read
Causa GitHub, or: Your Editor Extensions Run as You

Causa GitHub, or: Your Editor Extensions Run as You

Comments 1
5 min read
We built a free open source alternative to Wiz for Azure — here is how it works

We built a free open source alternative to Wiz for Azure — here is how it works

Comments
3 min read
How I Discovered and Deobfuscated a Hidden PHP Backdoor on My Server

How I Discovered and Deobfuscated a Hidden PHP Backdoor on My Server

1
Comments
2 min read
Why LLM Engineering Is a Cloud Security Problem Nobody Is Talking About

Why LLM Engineering Is a Cloud Security Problem Nobody Is Talking About

Comments 1
1 min read
The TanStack Attack: How a Worm Slipped Through the npm Pipeline

The TanStack Attack: How a Worm Slipped Through the npm Pipeline

Comments
6 min read
10 Python modules, one dangerous pattern: How I found 13 critical vulnerabilities in an SDK

10 Python modules, one dangerous pattern: How I found 13 critical vulnerabilities in an SDK

Comments 2
2 min read
What LucidShark Would Have Caught Before the TanStack Attack Landed

What LucidShark Would Have Caught Before the TanStack Attack Landed

Comments
7 min read
Every CISO Needs an AIBOM in 2026 — Here's What Vendors Get Wrong

Every CISO Needs an AIBOM in 2026 — Here's What Vendors Get Wrong

Comments
8 min read
Skill files are the new supply chain attack surface. Your CI pipeline does not know that yet.

Skill files are the new supply chain attack surface. Your CI pipeline does not know that yet.

1
Comments 2
4 min read
How to Review Code Your AI Agent Wrote While You Were Sleeping

How to Review Code Your AI Agent Wrote While You Were Sleeping

Comments
7 min read
Clinejection: When Your AI Coding Tool Became the Weapon

Clinejection: When Your AI Coding Tool Became the Weapon

1
Comments
9 min read
Why Every CISO Needs an AIBOM in 2026 — And What Vendors Miss

Why Every CISO Needs an AIBOM in 2026 — And What Vendors Miss

Comments
9 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.