> blog
Weekly news | 2024-09-04
news
- KeyConf24 program announced & livestream.
- Elasticsearch is Open Source, Again (AGPL) .
- Halliburton cyberattack linked to RansomHub ransomware gang.
- Proposal for llms.txt (e.g. like robots.txt).
- Figma Moves from ECS to Kubernetes to Benefit from the CNCF Ecosystem and Reduce Costs.
- Amazon S3 now supports conditional writes.
- Amazon DynamoDB announces support for Attribute-Based Access Control.
- CloudFormation simplifies resource discovery and template review in the IaC Generator.
- OpenTofu Registry Blocks Russia due to US sanctions. PR discussion.
Weekly news | 2024-08-28
news
- ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts.
- Amazon S3 no longer charges for several HTTP error codes.
- Amazon EC2 status checks now support reachability health of attached EBS volumes.
- StackExchange abused to spread malicious PyPi packages as answers.
- macOS Sequoia adds weekly permission prompt for screenshot and screen recording apps.
- System Initiative is now open source.
- Announcing 500 Kubestronauts.
toolings
- terrahash: Create and store a hash of the Terraform modules used by your configuration.
Weekly news | 2024-08-21
news
- AWS:
- Switzerland federal government requires releasing its software as open source.
- Folders for GitHub Action Workflows will not be supported this year.
- HashiCorp/IBM’s regulatory scrutiny could focus on cloud infrastructure management solutions.
- OpenTofu added to ThoughtWorks Technology Radar.
toolings
- helm-charts-oci-proxy: transform Helm Chart into OCI images on the fly. Address any Helm Chart as OCI image.
Weekly news | 2024-08-14
news
- Kubernetes 1.31 was released on August 13.
- PSA: Zero click RCE vulnerability on MS Windows, CVE Score 9.8, please patch now if you are using IPv6.
- Cyber insurers are winners from the biggest ever IT outage.
- The best hacks and security research from Black Hat and Def Con 2024.
- .internal is now officially a reserved TLD.
- Slack develops Bedrock Operator for Kubernetes StatefulSets.
- Proposal: terraform plan -light.
- Russ Cox steps down as tech lead of Go programming language.
Weekly news | 2024-08-07
news
- Google's online search monopoly is illegal, US judge rules.
- Crowdstrike drivers are a prime target for RCE and LPE.'
- Coinbase awarded a $500k bug bounty via hackerone.
- Coming soon to K8s: mount a docker container as a volume.
toolings
- aws-icons: SVG and PNG AWS icons for your architecture diagrams.
- logu: Extract patterns from (streaming) unstructured log messages.
Weekly news | 2024-07-31
news
- GitHub:
- GitHub Private Mirrors App – Public Beta.
- Actions Usage Metrics is generally available (GitHub Enterprise Only) .
- Validation on package name when submitting a new GitHub security advisory (GHSA).
- Copilot Enterprise Mixed Licensing beta.
- Repository updates July 31st 2024.
- Copilot network requests are now routed based on subscription.
- Secure Boot useless on hundreds of PCs from major vendors after key leak.
- Homebrew Undergoes Security Audit .
- AWS Silently Deprecates Code Commit, Cloud9.
- OpenTofu 1.8.0 is out: with Early Evaluation, Provider Mocking, and a Coder-Friendly Future.
- OpenTofu plans dynamic providers/loops.
- The 7th annual Open Source Management & OSPO survey is now accepting responses!.
Weekly news | 2024-07-24
news
- CrowdStrike
- GitHub:
- Code security configurations are supported in the audit log.
- Security overview dashboards, secret scanning metrics and enablement trends reports are now generally available.
- Deprecation of API endpoint to enable or disable a security feature for an organization.
- Enable secret scanning for non-provider patterns on repositories with the REST API.
- Enhance your pull request workflow: Copilot pull request text completion now in beta.
- the 2024 results from Stack Overflow’s Annual Developer Survey
- Wiz Rejects Google’s $23 Billion Offer, Seeks IPO Instead.
Weekly news | 2024-07-17
news
- AWS App Studio promises to generate enterprise apps from a written prompt.
- Google near deal to acquire cybersecurity startup Wiz for $23 billion.
- New Blast-RADIUS attack breaks 30-year-old protocol used in networks everywhere.
- CISA broke into a US federal agency, and no one noticed for a full 5 months.
toolings
- k8ssandra-operator: The Kubernetes operator for K8ssandra.
- aws-secretsmanager-agent: a local HTTP service that you can install and use in your compute environments to read secrets from Secrets Manager and cache them in memory.
- kaskade:a text user interface for kafka, which allows you to interact and consume topics from your terminal in style!
- tau: Open source distributed Platform as a Service (PaaS). A self-hosted Vercel / Netlify / Cloudflare alternative.
Weekly news | 2024-07-10
news
toolings
- sorry-cypress: Open-source, free, self-hosted alternative to Cypress Dashboard.
- pug: TUI for terraform.