Masthash

#devsecops

Sean D. Mack
20 hours ago

#DevSecOps is the future of software security. It's time to stop thinking of security as an afterthought and start integrating it into the development process from the very beginning.

Find out more in my upcoming book, "The DevSecOps Playbook: Deliver Continuous Security at Speed":
https://buff.ly/3qqdbjI

Freax
3 days ago
Don't miss your chance to join #OWASP for our Global #AppSec Singapore Conference on 05-October at Marina Bay Sands. Network with top-tier professionals and be educated by the best in the industry - get tickets now: singapore.globalappsec.org/?ut… #GlobalAppSecSG #devsecops nitter.at/owasp/status/1665856…
Freax
3 days ago
Don't miss out on OWASP's Global AppSec Singapore Conference on 05-October at Marina Bay Sands! Get your tickets NOW and join us for top-tier education, networking, and MORE - secure your spot today singapore.globalappsec.org/?ut… #OWASP #Conference #appsec #devsecops nitter.at/owasp/status/1665841…
Freax
3 days ago
Attention #appsec lovers! Join us at #OWASP's Global Appsec #Singapore on October 4th and 5th and explore topics like #threatmodeling and #devsecops. Let this be the beginning of your journey to greater security - secure your spot with tickets NOW: singapore.globalappsec.org/ nitter.at/owasp/status/1665795…
Freax
3 days ago
Don't miss out! Secure your spot and purchase your ticket for #OWASP's 3rd Global #AppSec Conference in Singapore on October 4-5 at Marina Bay Sands. #Threatmodeling, #DevSecOps and more! Link: singapore.globalappsec.org/ nitter.at/owasp/status/1665780…
Freax
3 days ago
CountdownToGlobalAppsec: It's almost time for Global Appsec Singapore 2023! Don't miss your chance to join this two-day data security conference happening October 4-5 at Marina Bay Sands. Get your ticket now: singapore.globalappsec.org/ #OWASP #appsec #threatmodeling #devsecops nitter.at/owasp/status/1665765…
Freax
3 days ago
📢📢 Calling all speakers 📢📢 #OWASP Global AppSec #Singapore is looking for speakers at our October conference. Do you have a topic you feel would benefit our community? Submit your paper NOW: owasp.submittable.com/submit/2… #threatmodeling #mobilesecurity #appsec #devsecops nitter.at/owasp/status/1665750…
Romano Roth
3 days ago

🚀 We have just released a brand new video on @GitHub Scheduled Pipelines!

🎥 In this our 11 video, Padi and I will show you how to configure a Schedule Pipeline for our #DevSecOps pipeline in #GitHub so that the pipeline runs at regular intervals.

👉https://youtu.be/Yy3KAloE5e0

Freax
3 days ago
Experience the Power of Paretto's Law at "Candies for Developers" with @vskourtis and #OWASP! It's an essential workshop for #developers to detect and learn how to remediate security issues. REGISTER NOW: www.eventbrite.com/e/owasp-202… #cybersecurity #appsec #devsecops nitter.at/owasp/status/1665539…
Freax
4 days ago
Hack the future! Sign up for @7aSecurity's #OWASP 2023 Virtual June Training and turn yourself into a master of hacking and defending modern web apps. Don't miss out - REGISTER NOW: www.eventbrite.com/e/600868583… #appsec #devsecops #webapps nitter.at/owasp/status/1665388…
Freax
4 days ago
Don't miss the chance to join @DevSecOps_Sara and uncover the techniques to protect your Angular Web application from potential OWASP TOP 10 security attacks on June 6-7! REGISTER NOW to join the #OWASP VIRTUAL Training: www.eventbrite.com/e/owasp-202… #appsec #devsecops nitter.at/owasp/status/1665331…
Freax
5 days ago
Don't miss out! Join the renowned @DevSecOps_Sara on June 6-7 for a #OWASP VIRTUAL Training to learn how to protect your Angular Web application from the OWASP TOP 10 threats. Don't wait - REGISTER NOW: www.eventbrite.com/e/owasp-202… #appsec #devsecops nitter.at/owasp/status/1665087…
Freax
5 days ago
Are you up for the challenge? Learn how to #hack and defend modern #webapps at OWASP 2023 Virtual June Training by @7aSecurity Don't miss your chance - REGISTER NOW: www.eventbrite.com/e/600868583… #appsec #devsecops nitter.at/owasp/status/1665055…
Freax
5 days ago
Don't miss out on this great opp! 🤩🤩 Registration for the June #OWASP Training has been extended until MONDAY MORNING - so don't miss out! 🎉 Register now and secure your place: www.eventbrite.com/e/owasp-202… #devsecops #appsec #cybersecurity nitter.at/owasp/status/1664995…
Freax
5 days ago
Be prepared to act quickly and detect vulnerabilities that cause 80% of attacks - train your eyes with "Candies for Developers", a workshop hosted by #OWASP and @vskourtis! Don't wait - REGISTER NOW: www.eventbrite.com/e/owasp-202… #cybersecurity #appsec #devsecops nitter.at/owasp/status/1664950…
Freax
6 days ago
Don't miss the chance to join @DevSecOps_Sara for the #OWASP VIRTUAL Training on June 6-7! Learn how to defend your Angular Web applications against the OWASP TOP 10 threats - REGISTER NOW: www.eventbrite.com/e/owasp-202… #devsecops #appsec nitter.at/owasp/status/1664784…
Freax
6 days ago
Hey #cybersecurity and #appsec pros - HAVE YOU HEARD? Registration for our June VIRTUAL Training has been extended til MONDAY! 🤩🎉 Take advantage of the offer & join us to take your cybersecurity education to the next level! REGISTER NOW: www.eventbrite.com/e/owasp-202… #devsecops nitter.at/owasp/status/1664723…
Freax
6 days ago
Wow, check it out! 🤩 Registration for the June #OWASP Training has been extended until MONDAY MORNING - don't miss out on this great opportunity! 🎉 REGISTER NOW: www.eventbrite.com/e/owasp-202… #cybersecurity #appsec #devsecops nitter.at/owasp/status/1664708…
Freax
6 days ago
Woohoo! 🤩 Great news #OWASP Community! 🎉👍 Get the expert training you need before it's too late! 🤓 Registration for our June VIRTUAL Training has been extended until MONDAY MORNING! 🕛 REGISTER NOW: www.eventbrite.com/e/owasp-202… #cybersecurity #appsec #devsecops nitter.at/owasp/status/1664693…
Freax
6 days ago
🤩 Great news #OWASP Community! 🎉👍 Registration for our June VIRTUAL Training has been extended!!! But, don't wait too long ⌛ this deal is only available until MONDAY MORNING! REGISTER NOW: www.eventbrite.com/e/owasp-202… #cybersecurity #appsec #devsecops nitter.at/owasp/status/1664682…
ReleaseTEAM, Inc
1 week ago

After the Air Force's #software project was three years behind schedule and $317 million over budget with waterfall methodology, something had to change. Read how #DevSecOps is helping federal agencies be more responsive and spend less: https://www.releaseteam.com/devsecops-for-federal-agencies/

Sean D. Mack
1 week ago

Just one week away! I'll be joining TechTalk Summits to speak about #DevSecOps and my upcoming book, The DevSecOps Playbook.

If you are a tech leader in the New York area join us at Michelin star restaurant, Al Coro, in Chelsea. You'll enjoy a three-course dinner, drinks, and great discussion.

Register today as seats are very limited and you must be approved to attend:
https://buff.ly/41wQoAt

Freax
1 week ago
📢📢 Calling all speakers 📢📢 #OWASP Global AppSec #Singapore is looking for speakers at our October conference. Do you have a topic you feel would benefit our community? Submit your paper NOW: owasp.submittable.com/submit/2… #threatmodeling #mobilesecurity #appsec #devsecops nitter.at/owasp/status/1664120…
Freax
2 weeks ago
📢📢 Calling all speakers 📢📢 #OWASP Global AppSec #Singapore is looking for speakers at our October conference. Do you have a topic you feel would benefit our community? Submit your paper NOW: owasp.submittable.com/submit/2… #threatmodeling #mobilesecurity #appsec #devsecops nitter.at/owasp/status/1661824…
Melinda Marks
2 weeks ago

As APIs proliferate w/ cloud-native development, what do we need to do to secure them? Looking forward to this webinar with
@filipv
from No Name Security to discuss my latest research findings and best practices fro API security

Join us here: https://nonamesecurity.zoom.us/webinar/register/WN_FYMRxXqbTK-3wSYXRBvzVA#/registration

#appsec #applicationsecurity #cloudsecurity #devsecops #apisecurity

Michael Friedrich 🦊
2 weeks ago

Working on my @CloudLandFestival learning sessions 🌱

#Observability for Efficient #DevSecOps Pipelines

See you soon! https://www.cloudland.org/en/home/

Sean D. Mack
2 weeks ago

Great to join TechTalk Summits and Gitlab to speak with other tech leaders about #DevSecOps last night in Newport Beach, CA.

If you missed it and are in the New York area make sure to join me at the Tech Talk Summit CXO Roundtable in at the Michelin star restaurant, Al Coro in #NYC on June 8.
https://techtalksummits.com/event/exclusive/cxo-roundtable-series/cxo-roundtable-new-york-ny

Michael Friedrich 🦊
2 weeks ago

Developer team onboarding a breeze, running securely in your cloud or datacenter? 👀 On-demand, cloud-based development environments are here in Beta with #GitLab 16 - give it a try ⚡

https://go.gitlab.com/Ngsfrd

#DevSecOps #DevX #CDE #Efficiency

"Accept the risk and continue" would be a good band name. #tls #devsecops

Freax
2 weeks ago
🎉Tickets for training at #OWASP Global #AppSec DC are available! Join us for in-person courses with our highly-rated list of trainers November 1-3 at the Marriott Marquis DC. LEARN MORE: dc.globalappsec.org/?utm_sourc… #mobilesecurity #threatmodeling #devsecops nitter.at/owasp/status/1661129…
sugaroverflow
2 weeks ago

It's GitLab 16.0 Release Day 🚀

🤖 Code Suggestions - now available to everyone, with support for 13 languages and now the default multi-file code editor across GitLab.

🛡️ Browser-based DAST scanner has been improved to perform faster and more accurately.

📊 The Value Streams Dashboard is now generally available. Use it to gather insights into your metrics!

⚡️ The new Web IDE is now generally available.

https://go.gitlab.com/pg4o9p

#GitLab16 #DevSecOps #CICD #Security #SoftwareDevelopment

Open Source JobHub
2 weeks ago

Interested in joining the #GitLab team? Check out open positions for backend engineers, sales, and more on #OSJobHub https://opensourcejobhub.com/company/706/ #database #engineer #PostgreSQL #DevSecOps #sales #jobs #career #OpenSource

GitLab logo on a white background
Michael Friedrich 🦊
2 weeks ago

#GitLab 16.0 is here - so many great features to highlight 💡 #efficiency #devsecops #ai #aipowered #community #remotedevelopment #DevX

https://go.gitlab.com/pg4o9p

Learn more ⬇️

Romano Roth
2 weeks ago

How to do Vulnerability Management in GitHub?

In our newest video, Padi and I show you the process of managing and tracking vulnerabilities using the GitHub Vulnerability Management (Security Tab).

👉https://youtu.be/cDf-U-wMgfc

#devops #devsecops #GitHub

Sean D. Mack
3 weeks ago

By integrating security into the development process, DevSecOps helps to identify and fix vulnerabilities early on, saving time and resources in the long run. #DevSecOps #ShiftLeft

Michael Friedrich 🦊
3 weeks ago

A little help from AI ... to summarize #GitLab merge request reviews ⚡ #efficiency #devsecops

https://go.gitlab.com/8zjPJx

𝕯𝖎𝖒𝖎
3 weeks ago

Morning on the first day of #DevOpsTalks #Sydney, and it's clear it should be renamed #DevSecOps talks :)

The main focus of everyone seems to be on #securiy, which is a good surprise and a relief. Getting more people interested and pushing good security practices in #development is bound to make everyone's life easier.

𝕯𝖎𝖒𝖎
3 weeks ago

Second talk done by Ben Ridley an accountant turned #linux admin turned #DevSecOps consultant, currently working at #gitlab ...

#DevOpsTalks #Sydney

À screen showing the text "The seamless DevSecOps journey"
À speaker on stage.
Sean D. Mack
3 weeks ago

DevSecOps isn't just a buzzword, it's a cultural shift in the software development process that prioritizes security at every stage.
#DevSecOps #SecurityFirst

IT News
3 weeks ago

Sigstore: Roots of trust for software artifacts - For the roughly five billion people who use the internet, only a tiny fraction have an... - https://www.infoworld.com/article/3696209/sigstore-roots-of-trust-for-software-artifacts.html#tk.rss_all #applicationsecurity #softwaredevelopment #opensource #devsecops #security

𝕯𝖎𝖒𝖎
4 weeks ago

@dwan and I will be at the #DevOps talks conference Wednesday and Thursday in #Sydney.

Is anybody else coming and/or want to meet?

#Security #Cyber #DevSecOps #DevOpsTalks

The flyer for the DevOps Talks Conference, in Sydney on the 17-18 May.
Workshops 19th May
With a picture of two attendance people.
Melinda Marks
1 month ago

I weighed in on the challenges with managing secrets security with cloud-native development and GitGuardian's State of Secrets Sprawl Report.
https://www.csoonline.com/article/3695583/majority-of-us-uk-cisos-unable-to-protect-company-secrets-report.html
#devsecops #cloudsecurity #applicationsecurity #appsec

Romano Roth
1 month ago

Is DevOps dead 💀 ?
I've had the pleasure to discuss this controversial topic with @eoehrlich on the latest episode of the Humans of DevOps Podcast from the @DEVOPSINST.
👉 https://www.devopsinstitute.com/ep101-devops-is-not-dead

#devops #devsecops #platformengineering #podcast

Melinda Marks
1 month ago

My new blog post addresses my issues with the concept of "shift left security." It's not wrong, it's just misunderstood.

Shifting left is about empowering developers to better secure their applications, freeing up security teams to scale to better support them. Security teams need to work with development throughout the SDLC to drive efficiency for remediation - helping both teams.

https://www.techtarget.com/searchsecurity/opinion/Addressing-the-confusion-around-shift-left-cloud-security

#devsecops #cloudsecurity #infosec #developersecurity #cnapp #applicationsecurity #appsec

Anonymous :anarchism: 🏴
1 month ago

Strengthen your product security with collaborative tools! Learn how to plan mitigation, identify abnormal behavior, and share security signals with other DevSecOps teams.

https://thehackernews.com/2023/05/strengthening-product-security.html

#cybersecurity #hacking #DevSecOps

ReleaseTEAM, Inc
1 month ago

Did you know that GitLab can automate #software delivery and secure your end-to-end software supply chain with their DevSecOps platform? Read about the platform here: https://about.gitlab.com/solutions/dev-sec-ops/ #DevSecOps #DevOpsTools

Melinda Marks
1 month ago

Security needs to function as the pit crew enabling developers to speed through instead of taking a view of a cop. Learn from security metrics expert Richard Seiersen and watch our short video about key metrics for better cloud security and cloud-native application security. https://www.techtarget.com/searchsecurity/opinion/Cloud-native-security-metrics-for-CISOs
#applicationsecurity #appsec #cloudsecurity #securitymetrics #ciso #cso #devsecops #infosec #infosecurity

I’ve just released attempt 2 at a workaround for monorepos with :github: Advanced Security Code Scanning results, to let you filter by project 🚀

My last try didn’t work out, but I’ve taken a new tack ⛵️ and come back with a new ✨ way…

https://github.com/advanced-security/monorepo-filtering-workaround

The sample Actions workflow I’ve shown works for CodeQL, but you can apply the same idea to any Code Scanning integration.

#GitHub #SAST #GitHubAdvancedSecurity #MonoRepo #DevSecOps #SecureCoding

I need to come up with some talk ideas for next autumn... #DevSecOps and #DevExperience as topics 🙃

Sean D. Mack
1 month ago

DevOps onramp is kicking off now! So much great focus on #DevSecOps!
Awesome lineup with @AndiMann, @botchagalupe, @lnxchk and many other tech leaders. 9AM - 4PM EDT today.
https://www.techstrongevents.com/devopsonramp

#community #events #DevOpsOnramp23

Cassandra Lee
1 month ago

It was a pleasure to co-author this article with a colleague and friend, Kristopher Morrison. Here are the the top #JavaScript security risks and how to mitigate them:

https://www.stationx.net/javascript-security/

#cybersecurity #cybersec #infosec #infosecurity #webdev #webdevelopment #webapp #mobile #devsecops #devops #dev #developer #js

Jason A Cox
1 month ago

Wow! Investments Unlimited made the CIOs nominated reading list published by The Wall Street Journal! https://wsj.com/amp/articles/cios-nominate-their-favorite-reads-of-2022-11672178125 #devops #devsecops

Wall Street Journal - CIOs Nominated Their Favorite Reads of 2022. Ramon Richards, chief information officer, Fannie Mae nominated Investments Unlimited: A Novel About DevOps, Security, Audit Compliance, and Thriving in the Digital Age Helen Beal, Bill Bensing, Jason Cox, Michael Edenzon and John Willis (2022) “The storytelling in the book outlines an approach to operating efficiently with DevOps, audit, compliance and security to deliver high-quality software.”
prabhu
2 months ago

I will believe that an organization takes application security seriously when a junior developer could ask for an extra week to implement security test cases in addition to building the feature. If not, you're only pretending to be #DevSecOps

Randall Degges
2 months ago

DevSecCon is June 27th for 24 hours of non-stop DevSecOps action. Featuring experts and practitioners from the DevOps, development, and security communities, this event is a must-attend for anyone interested in secure software practices.

Learn, network, and collaborate on best practices, processes, and tooling at this free virtual conference!

Our Call for Papers is open until April 28th. Submit your talk today: https://sessionize.com/devseccon24-2023 #DevSecOps #security

I've opensourced Actions/scripts to enhance #GitHub Code Scanning

🔖 tag-sarif: for filtering results in a #monorepo
🧭 remap-sarif: for scanning code that transpiles to #JavaScript

tag-sarif attaches custom tags to results to allow filtering in the Code Scanning UI

remap-sarif lets you scan languages/frameworks, such as Dart/Next.is, using Source Maps

Source:
https://lnkd.in/dZerNsGs
https://lnkd.in/dvmruWDJ

Actions:
https://lnkd.in/dTzVg-X3
https://lnkd.in/d9dSZ2ER

#SAST #DevSecOps #AppSec

Michael Friedrich 🦊
2 months ago

Let's meet at #KubeConEU 🤗

🎯 GitLab code challenge (booth P1) with stroopwafels swag
⚡ Lightning talk: Efficient #DevSecOps Pipelines
💬 Chat about #Observability, #eBPF & AI
☕ Coffee/lunch/dinner

My availability is updated publicly: https://go.gitlab.com/dxMbWj

Screenshot of GitLab epic for KubeCon EU 2023, showing dnsmichi's availability schedule for the week.
Michael Friedrich 🦊
2 months ago

I’m attending #KubeCon + #CloudNativeCon in Amsterdam from April 19th - April 21st, and I invite you to stop by Booth P1 for my lightning talk Efficient DevSecOps pipelines in a cloud native world on April 19 at 19:30 CEST. https://bit.ly/3yvBn5j #DevSecOps

Rob Bos
2 months ago

Did you know that you can now enable #GitHub Advanced Security features for all your personal repositories in one go? Go to https://github.com/settings/security_analysis to enable them!

Want to learn more about GitHub Advanced Security? Check out my LinkedIn Learning course on it! https://www.linkedin.com/learning/github-advanced-security/github-advanced-security?autoplay=true

#GHAS #DevSecOps #Security

Doyensec
2 months ago

New advisory! Viktor Chuchurski provides details on a CSRF protection bypass he discovered in Sveltekit. Ensure your apps are up-to-date.

#doyensec #appsec #javascript #DevSecOps #sveltekit #svelte

https://doyensec.com/resources/Doyensec_SvelteKit_CSRF_Protection_Bypass_Advisory.pdf

Sean D. Mack
2 months ago

I'm excited to announce that my upcoming book, The DevSecOps Playbook: Delivering Continuous Security, is now available for pre-order on Amazon!

Whether you're a security professional, a developer, or a business leader, this book will give you the tools you need to adopt DevSecOps and deliver secure software at speed.

Pre-order your copy today and be among the first to get your hands on this essential resource!
https://a.co/d/c6UA1m4

#DevSecOps #ContinuousSecurity #CyberSecurity

Matt Brunt
2 months ago

#Dev
#DevOps
#DevSecOps

Do we just keep adding things on now?

When does it end?!?!

Danilo Poccia
2 months ago

Integrating with GitHub Actions – Amazon CodeGuru in your #DevSecOps Pipeline 👉 To analyze and detect potential security vulnerabilities in the code before deploying it https://aws.amazon.com/blogs/devops/integrating-with-github-actions-amazon-codeguru-in-your-devsecops-pipeline/ #AWS #DevOps #Security

Michael Friedrich 🦊
3 months ago

In June, I'm excited to join the German #cloudnative festival @CloudLandFestival Let's learn together! 🤗

⚡ Talk: Observability for Efficient #DevSecOps Pipelines

💡 Workshop: Learning #eBPF for better #Observability

Lineup: https://en.shop.doag.org/events/cloudland/2023/agenda/#eventDay.all

#CloudLand2023

Michael Friedrich 🦊
3 months ago

looking forward to seeing you at #KubeConEU 2023 in april 🌐

find me at the #GitLab booth 🦊 talk about efficient #DevSecOps ⚡ join great conversations & code challenges 💡grab swag ☀️ enjoy time together 🤗

https://about.gitlab.com/events/kubecon/

Anonymous :anarchism: 🏴
3 months ago

Attention #CloudSecurity aficionados!

📣 Gartner® has published the first Market Guide for Cloud-Native Application Protection Platforms (CNAPP), marking a major turning point in cloud security.

🎉 Join Uptycs on Thursday March 23rd for their live discussion on the key takeaways from this guide: https://thn.news/cnapp-market-guide

#InfoSec #IT #DevSecOps #CNAPP #XDR

Michael Friedrich 🦊
3 months ago

👋 🌱 🐝 🤖 🛡️⛅ 👁️ 📚 🔖 🎯 🎥 🎤

Love to learn together, and follow the Ops in Dev newsletter?

Subscribe at https://buttondown.email/opsindev.news

#observability #devsecops #cloudnative #MachineLearning

Michael Friedrich 🦊
3 months ago

⚡ Recording for my "Efficient #DevSecOps Pipelines in a Cloud-Native World" talk at @clt_news
Chemnitz Linux Days is here: https://go.gitlab.com/9gx7Om

🌱 Many best practices, #gitlab tips, and future ideas.

Michael Friedrich 🦊
3 months ago

Efficient #DevSecOps pipelines in a cloud-native world - slides from my Chemnitz Linux Days talk, to learn & iterate async 🤗💡🌱🔥

https://go.gitlab.com/RPog2h #GitLab

Melinda Marks
3 months ago

New #WomeninCybersecurity show is out featuring the amazing and inspiring #appsec guru @SheHacksPurple! Find out how playing guitar got her into #cybersecurity and learn about her free #applicationsecurity training courses + resources https://www.esg-global.com/blog/women-in-cybersecurity-tanya-janca
#devsecops #cloudsecurity #securitytraining #infosec

Michael Friedrich 🦊
3 months ago

⚡ I'm excited to speak at QCon London about my #eBPF learning story with debugging production, verifying #observability with #chaosengineering, and #eBPF benefits, risks, #DevSecOps to-dos : https://qconlondon.com/presentation/mar2023/monitoring-observability-ebpf-chaos?utm_campaign=community&utm_content=gitlab_developer_evangelism_talks&utm_source=mastodon&utm_medium=social&utm_budget=cmty

🤗 March 27-29, in-person or online at #QConLondon

Discount ⬇️

You can use this discount code to register for #QConLondon - MichaelFQUK2350

💡 Early bird runs until March 6. https://qconlondon.com/

See you soon in London! Make sure to visit the #GitLab booth and chat 🦊

Michael Friedrich 🦊
3 months ago

🛡️ Secure your #GitLab CI/CD workflows using #OIDCJWT on a #DevSecOps platform

Learn about JSON Web tokens, their current CI/CD integration, and what's coming with GitLab 16.0 soon 🌱

https://about.gitlab.com/blog/2023/02/28/oidc/?utm_campaign=community&utm_content=blog_general&utm_source=mastodon&utm_medium=social&utm_budget=cmty

Randall Degges
3 months ago

THE BIG FIX 24-HOUR LIVESTREAM IS ABOUT TO START! https://www.youtube.com/watch?v=dVedZpqWybI #DevSecOps #TheBigFix

I've just published my latest blog post, titled "You can't do 'DevSecOps' without doing 'DevOps'".

If you want to level up your #AppSec organization and transform the way you work into #DevSecOps - start here:

https://securing.dev/posts/no-devsecops-without-devops/

Sean D. Mack
3 months ago

Is "monitoring" a bad word now? I've noticed many people, especially vendors simply replacing "monitoring" with "observability" without really understanding what observability means.

#monitoring #observability #devops #devsecops

Michael Friedrich 🦊
3 months ago

⚡ GitLab 15.9 released

🔐 Secure CI/CD workflows with OIDC
🔥 Code suggestions in closed beta
🌱 Your work sidebar - incl. activity view
🏎️ Tasks: Convert Markdown checklists & quick actions
📈 Epics with child epics from different group hierarchies

https://go.gitlab.com/ORP8ZL

#DevSecOps #Efficiency #SoftwareFaster

Michael Friedrich 🦊
4 months ago

👋 🌱 🐝 🤖 🛡️⛅ 👁️ 📚 🔖 🎯 🎥 🎤

Love to learn together, and follow the Ops in Dev newsletter?

Subscribe at https://buttondown.email/opsindev.news

#observability #devsecops #cloudnative #MachineLearning

Michael Friedrich 🦊
4 months ago

A beginners tutorial with python-gitlab & advanced #DevSecOps use cases with the #GitLab API in one blog post: https://go.gitlab.com/JPIoWd

Kudos to the python-gitlab project, fantastic API library & pure joy using as a #Python developer (I literally could not stop writing the blog post) 🤗

Astra Kernel :verified:
4 months ago

Devs: We should add a kiosk mode to make the application safer.

Manager: No time for such nonsense, deploy it now.

#infosec #appsec #pentesting #blueteam #bugbounty #DevSecOps

Credit: @stux

Michael Friedrich 🦊
4 months ago

#GitLab’s 2023 predictions: What’s next for #DevSecOps?

Including my predictions for #observability 💥

https://go.gitlab.com/HhEsH3

Rob Bos
4 months ago

I have enabled GitHub's Secret scanning for 14k forked repositories from the Actions Marketplace. Here is what I have found (and why you should make sure you have this enabled)!

https://devopsjournal.io/blog/2023/01/22/Making-the-case-for-secret-scanning?utm_source=dlvr.it&utm_medium=mastodon

#DevSecOps #SecretScanning #GitHub

Phillip :unverified:
5 months ago

@The_Stitched That makes sense. I'm eyeing a #devsecops role at a company that by most accounts has pretty solid company culture and seems to really care about their employees. I imagine that would help combat the burnout. I appreciate the insight!

Phillip :unverified:
5 months ago

Hey #devops peeps - what is your best definition of the job? What do you do in your day-to-day? Bonus points for #devsecops info

I have a general idea of what the job entails and I'm interested in potentially working in the field, but should probably learn a bit more first 😅

Michael Friedrich 🦊
5 months ago

🔥 Passionate about hands-on content to help educate everyone about #DevSecOps #cloudnative #AI #observability ?

🤗 #DevRel #opensource and #community engagement makes you happy ?

🌐 You live and breath #remote #async #transparency #diversity ?

💥 YES to all of them? Apply now and join our amazing Developer Evangelism team at GitLab!

https://boards.greenhouse.io/gitlab/jobs/6521569002

#jobs #remotework #gitlab

sharon✨️
5 months ago

Security is everyone's responsibility.
I stole this from the training - it's facts.
#devsecops #devops

Remember - Security is everyone's responsibility - Dev, Sec & Ops.
Xe :verified:
5 months ago

📢 TODAY (9:00 PST / 11:00 CST / 12:00 EST): Join Josh Kodroff @joshkodroff and Xe Iaso @cadey to learn how to use #Pulumi with Tailscale to seamlessly and securely connect your devices and #cloud resources using a modern, zero-trust model! 👉Register here: https://pulumip.us/Building-VPN

#DevSecOps #DevOps #security #AWS

@edbro @SheHacksPurple oh trust me, I know a thing or two about #DevSecOps 😉 For the sake of space I was just giving a couple of examples 😊👍 and yes, Tanya is a fantastic person!

Tailscale
5 months ago

[Re. @PulumiCorp]
TOMORROW (11 AM CST): Join @JoshKodroff and Xe Iaso (@Tailscale) to learn how to use #Pulumi with Tailscale to seamlessly and securely connect your devices and #cloud resources using a modern, zero-trust model! 👉Register https://t.co/rwPHYfRXoz

#DevSecOps #DevOps #security

Tailscale
10 months ago

[Re. @symops]
👋 Hello! We’re thrilled to announce our new integration with @tailscale for SSH access.

Sym’s approvals-as-code are the perfect complement to Tailscale’s ACLs-as-code — what more could a #DevSecOps engineer want?

Read our full announcement here: https://t.co/hLba3q2XHT 🎉