DEV Community

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Are AI Apps Safe? What Developers Should Build Into AI Systems Before Production

Are AI Apps Safe? What Developers Should Build Into AI Systems Before Production

1
Comments
9 min read
The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub

The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub

Comments
6 min read
Miasma Worm: How Opening a Repo in Claude Code Became a Credential Theft Vector

Miasma Worm: How Opening a Repo in Claude Code Became a Credential Theft Vector

Comments
9 min read
GitHub Organization Security Hardening: Exact Controls and Step-by-Step Setup Guide

GitHub Organization Security Hardening: Exact Controls and Step-by-Step Setup Guide

1
Comments
29 min read
組織向け GitHub セキュリティ・ハードニング完全ガイド

組織向け GitHub セキュリティ・ハードニング完全ガイド

Comments
29 min read
End-to-End GitHub Security Hardening Guide for Organizations

End-to-End GitHub Security Hardening Guide for Organizations

Comments
44 min read
When Chain Analysis Fails: Three Boundaries You Cannot Cross

When Chain Analysis Fails: Three Boundaries You Cannot Cross

Comments
4 min read
The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon

The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon

Comments
6 min read
Anyone with GitHub issue access can steal your CI/CD secrets. Here's why.

Anyone with GitHub issue access can steal your CI/CD secrets. Here's why.

Comments
6 min read
GitGuardian NHI Governance Now Gives More Comprehensive Visibility

GitGuardian NHI Governance Now Gives More Comprehensive Visibility

Comments
6 min read
2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk

2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk

1
Comments
5 min read
We benchmarked 24 SAST tools on ~700 real vulnerabilities. The 3 best known ones came last

We benchmarked 24 SAST tools on ~700 real vulnerabilities. The 3 best known ones came last

Comments
1 min read
Embracing Zero Trust Security Architecture: A DevOps and AI Engineer's Perspective

Embracing Zero Trust Security Architecture: A DevOps and AI Engineer's Perspective

Comments
2 min read
Trivy's March Supply Chain Attack Shows Where Secret Exposure Hurts Most

Trivy's March Supply Chain Attack Shows Where Secret Exposure Hurts Most

1
Comments 1
5 min read
Developers Are Now the Attack Surface

Developers Are Now the Attack Surface

Comments
10 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.