companies I've worked at to prove my credentials go here> I've done security since +++ATH0 was a problem 2 — DevOpsDays PDX ! infosec.exchange/@bea [email protected]
added them to CI, and stopped developers being able to ship new features, just so some Java/Javascript library you weren't using in that way wouldn't be included in some image. 3 — DevOpsDays PDX ! infosec.exchange/@bea [email protected]
{ } '$schema': 'https://docs.renovatebot.com/renovate-schema.json', extends: ['config:recommended'], dependencyDashboard: true, // it's JSON5, you can have comments! // I know, it's like living in the future! 12 — DevOpsDays PDX ! infosec.exchange/@bea [email protected]
priority in the world, despite that really only coming from marketing material for things that pretend to solve this, you can't do that because SuPpLy ChAiN AtTaCkS!! 11eleventy" 15 — DevOpsDays PDX ! infosec.exchange/@bea [email protected]
packages/images automatically on new versions → follow Dependabot and OSV.dev security alerts → defends again the evil spectre of supply chain attacks! 19 — DevOpsDays PDX ! infosec.exchange/@bea [email protected]