< ciso
brief />
Tag Banner

All news with #devsecops tag

129 articles

AWS Control Tower AFT adds plan-only customization

🛠️ AFT now supports plan-only customization runs that let administrators preview Terraform changes without applying them. This update enables safe pre-rollout validation, drift detection, and integration with CI/CD review workflows across all AFT-supported Terraform distributions. The feature is available in all Regions where AWS Control Tower Account Factory for Terraform is supported; see the AFT documentation and 1.22.0 release notes for setup details.
read more →

ECS adds VPC Lattice blue/green and canary deploys

🔧 Amazon Elastic Container Service (Amazon ECS) now provides built-in blue/green, linear, and canary deployment strategies for services using Amazon VPC Lattice. Applications using VPC Lattice for cross-VPC and cross-account communication can leverage managed traffic shifting directly from ECS when rolling out updates. Teams can validate new versions with test traffic, use lifecycle hooks for custom validations or manual approvals, and rely on CloudWatch alarms and the ECS deployment circuit breaker to trigger automatic rollbacks.
read more →

Building the Next Git Platform for Agentic Development

🛠️ Cloudflare has launched Artifacts, a versioned filesystem that speaks Git and scales to millions of repositories, designed as programmable primitives developers can use to build workflows and agent-driven products. Artifacts now integrates with Workers Builds to deploy production branches and Workers Previews for other branches, supports repository events for automation, offers jurisdictional data controls, and exposes repository metrics in the dashboard. The open beta invites developers to build the next-generation Git platform for hundreds or thousands of agents working concurrently, with a competition accepting submissions through October 14, 2026.
read more →

Amazon Managed Grafana adds Grafana 13.2 support

🔔 Amazon Managed Grafana now supports creating new workspaces with Grafana version 13.2, bringing features from Grafana 13.0–13.2 such as Git Sync, dynamic dashboards, and PromQL support in the Amazon CloudWatch plugin. Git Sync enables treating dashboards as code by linking a workspace to a Git repository for version control. Dynamic dashboards allow responsive layouts driven by data and variables. The CloudWatch data source plugin now accepts PromQL queries for metrics ingested via OTLP. Grafana 13.2 is available in all AWS regions where the service is generally available.
read more →

Agent Harnesses, Shifting Left, and Autonomous Coding

🧭 This recap summarizes a conversation with Ryan Lopopolo on building autonomous coding agents using an agent harness around an LLM. It explains how harness engineering, shifting interventions left, and providing discoverable tools and documentation enable agents to operate autonomously and produce reviewable artifacts like pull requests. The piece also covers practical harness patterns, tooling choices, and advice to avoid bespoke scaffolding.
read more →

GKE agentic migration for safer cloud modernizations

🔧 Google Cloud released the open-source GKE agentic migration plugin to simplify migrations from AWS EKS to Google Kubernetes Engine. The tool combines LLM-driven translations with deterministic server-side validation and GitOps PR workflows to avoid direct changes to live clusters. It persists long-running migration state for multi-persona handoffs and produces runbooks for stateful transport, enabling human-in-the-loop approvals and safer, auditable migrations.
read more →

Hardening Code Pipelines and CI/CD Infrastructure

🔒 This blog outlines practical guidance for protecting the software supply chain by hardening CI/CD pipelines, developer workstations, repositories, and artifact registries. It describes modern attacker techniques—compromising developer tools, IDE extensions, and pipeline tokens—and recommends concrete controls like EDR/UEM integration, fine‑grained short‑lived credentials, strict dependency pinning, sandboxed developer environments, and centralized artifact proxies. The post emphasizes defense‑in‑depth across five SDLC pillars with actionable steps for continuous verification, provenance, and automated policy enforcement.
read more →

Cloudflare Worker Previews: Branch-Isolated Environments

🚀 Worker Previews provide a production-like environment per Git branch, each with its own code, configuration, URL, observability, and isolated state. Run npx wrangler preview to create a Preview that uses separate variables, secrets, and Durable Object namespaces so changes can be tested safely without impacting production. The dashboard surfaces Previews alongside Production, with full Workers Observability and optional custom domains or Access protection.
read more →

Google Cloud enhances Secure Source Manager for CI/CD

🔒 Google Cloud announced two generally available Secure Source Manager (SSM) features to harden CI/CD pipelines: enhanced blocking of unauthorized access across version control, build, and deployment systems, and a new Code Owners system for granular per-file and per-branch approver controls. The Code Owners feature supports nested ownership, branch-specific governance, glob-style path rules, and independent approval sections, while Developer Connect and Private Network Integrations let SSM connect CI/CD and runtimes across private networks with VPC Service Controls and Private Service Connect.
read more →

AI-native agents for continuous code security

🔒 Google describes AI-native, agent-driven methods that embed high-precision vulnerability scanning and automated patching into the software development lifecycle. By evolving the open-source Mantis multi-agent harness and using localized threat models plus call-graph analysis, pre-submit scans detect issues in near real-time with low false-positive rates. A two-step validation (fast triage agent then nightly post-submit testing) and an automated bug-fix agent streamline detection-to-resolution while preserving developer productivity.
read more →

Automating IAM least-privilege remediation via CI/CD

🔒 This post describes an automated workflow that turns AWS IAM Access Analyzer findings into actionable remediation artifacts. It classifies roles by origin—IaC-managed, manually created, or unused—and produces either a production-ready CDK pull request, a migration issue with recommended policies, or a soft-disable decommission plan. The automation integrates Access Analyzer, CloudTrail, Amazon Bedrock, and your CI/CD pipeline to create reviewable, deployable changes instead of accumulating tickets.
read more →

AWS launches one-line CLI for .NET modernization

🚀 AWS announced general availability of an AWS-managed .NET modernization transformation accessible via a single one-line CLI command. The transformation can run interactively or be scripted into pipelines and complements existing AWS Transform for .NET experiences such as the web app, Visual Studio IDE, Kiro Power, and MCP agents. AWS Transform custom supports ready-to-use and customizable transformations to upgrade languages, migrate frameworks, optimize performance, and analyze codebases at scale.
read more →

Cloudflare Workers new module registry aligns with Node

🛠️ The Workers runtime's module registry in workerd has been rewritten to improve speed, standards compliance, and alignment with Node.js module semantics. Enabling the new_module_registry flag activates features like import.meta.url, import.meta.main, and import.meta.resolve(), Node-style require(esm) behavior, and correct handling of json import attributes. The registry now uses URL-based specifiers, supports separate module files (including Wasm) and shared compilation caches, and enables bundlers like Rollup/Vite to rely more on the runtime for resolution.
read more →

Timestream for InfluxDB adds custom Python plugins

🛠️ Amazon Timestream for InfluxDB now supports running custom Python plugins on managed InfluxDB 3 Core and Enterprise editions. You store plugin code in public or private repositories you control, and the processing engine fetches and executes it in response to supported triggers, enabling in-database data transformation, alerting, aggregation, and service integrations. Plugins run in a managed Python environment with the standard library and Amazon-vetted packages; private repos are authenticated via tokens in AWS Secrets Manager. To enable a plugin, configure a plugin repository in a DB parameter group, apply it to your cluster, and create triggers referencing the plugin via the influxdb3 CLI or HTTP API; the feature is available in all Regions where the service is offered.
read more →

Automating Dual‑Write Migration to Cloud Spanner

🔧 Google’s Finance Engineering team automated a complex migration from a legacy datastore to Cloud Spanner using Antigravity CLI in headless mode to perform repeatable, multi-file refactoring. They standardized DAO refactoring around a MutationConverter interface, enabling deterministic code generation, automated unit tests, and CI-driven verification. The headless pipeline ran batch conversions, executed tests, and fed failures back into Antigravity for self-correction, dramatically reducing manual effort and ensuring high data fidelity.
read more →

Shai‑Hulud Infostealer Expands Credential Reach

🔍 GitGuardian researchers observed a Shai‑Hulud infostealer worm variant in August that now scans 469 locations for credentials across developer environments, CI/CD tooling, cloud configs, and AI tool settings. Earlier variants checked 189 paths, indicating attackers increasingly hunt for existing reusable authority rather than breaking trust relationships. Defenders are urged to prioritize removing long‑lived publishing tokens, adopt short‑lived identity‑backed publishing, and treat secrets detection as credential risk management.
read more →

SageMaker CI/CD adds AI manifest and notebooks

🤖 Amazon SageMaker Unified Studio CI/CD adds two open-source features: an AI agent skill to auto-generate deployment manifests and native notebook promotion across environments. The manifest skill inspects project resources, applies least-privilege IAM guidance, and substitutes environment variables to avoid hardcoded identifiers. Notebook promotion synchronizes notebooks in place, preserving run history, supports selective promotion and dry-run validation, and integrates with existing CI/CD commands. Both features are available in all Regions offering SageMaker Unified Studio.
read more →

Equifax adopts AI to modernize cybersecurity

🔒 Equifax is combating evolving threats by combining strengthened cybersecurity hygiene with AI-driven automation across operations and development. EVP and CISO Jeremy Koppen highlights a 30% rise in attacks driven by automation and a shrinking window to patch vulnerabilities. Equifax has rolled out passwordless access for partners, a business exposure map, automated certificate management, and AI-assisted code review that reduced review time from 46 to 18 days.
read more →

AWS ParallelCluster 3.16 Adds On-Node Diagnostics

🛠️ AWS ParallelCluster 3.16 is now generally available and introduces pcluster-diag, an on-node diagnostics tool included in ParallelCluster AMIs that produces structured reports to simplify issue identification. The release also improves cluster lifecycle resilience with more robust creation, updates, and image builds. The HPC and AI/ML software stack receives updates to NVIDIA drivers, CUDA, EFA installer, and Slurm.
read more →

MWAA Serverless Adds PythonOperator and BashOperator

🆕 Amazon Managed Workflows for Apache Airflow (Amazon MWAA) Serverless now supports running custom Python functions and shell scripts directly in the serverless runtime using PythonOperator and BashOperator. Package your Python modules or shell scripts as code packages, upload them to Amazon S3, and reference them when creating or updating a workflow. The service snapshots your code at workflow creation time and uses that snapshot for all subsequent runs, ensuring execution consistency. This capability is available in all AWS Regions where MWAA Serverless is offered.
read more →