Blogs

Securing CI/CD for an open source project: Controlling who runs what

Cncf

The last twelve months have been rough on the open source supply chain. Axios was compromised on npm and shipped a remote access trojan inside otherwise normal-looking releases.

Visit Site

Blogs Cncf

BlogsSecuring GitHub Actions CI dependencies: Recipe cardCncf BlogsFlipkart and LitmusChaos at KubeCon + CloudNativeCon India 2026: A recapCncf BlogsA decade of governance: Cloud Custodian at 10 and its role in the agentic AI eraCncf BlogsEvolving platform engineering for AI-native workloadsCncf BlogsRegistry Mirror Authentication with Kubernetes SecretsCncf BlogsThe AI-driven shift in vulnerability discovery: What maintainers and bug finders need to knowCncf NewsJaeger vs. Zipkin: Battle of the Open Source Tracing ToolsThenewstack NewsKyverno Defends Containers Against Security Configuration ErrorsThenewstack BlogsOpen Source Vulnerabilities: How to Maintain Speed, SecurityThenewstack ResourcesGo Wiki: InstallTroubleshooting - The Go Programming LanguageGo BlogsClickHouse docs relaunchClickhouse BlogsZeroTier Makes Running Private Cloud Storage More Accessible and Easier to UseZerotier PodcastsSecuring the Win - Episode 3 with Nimesh Kotecha | 1Password1password BlogsVideo: Getting started with Tailscale Access Control ListsTailscale BlogsWhat’s a Scrum board, and how can you create one?Notion So BlogsHow Sarah Jutras is teaching the world how to work for themselvesNotion So BlogsHow to build an art marketplace on NotionNotion So BlogsQwen 3.7 Plus is now live on FireworksFireworks BlogsLaunching Fireworks for Startups Program!Fireworks BlogsSimplifying Code Infilling with Code Llama and Fireworks.aiFireworks