UA DevOps
735 subscribers
799 photos
36 videos
25 files
1.56K links
Канал з новинами у DevOps світі. Актуальні статті та цікаві рішення.
Наш чат: @ua_devops_community
реклама: @yuliy_ceaser
Download Telegram
2
🔥3
🚀 How to bring your software delivery workflow into GitHub with agent apps

See how four GitHub agent apps can help you scope, secure, roll out, and ship a feature across the SDLC–all without leaving GitHub.
The post How to bring your software delivery workflow into GitHub with agent apps appeared first on The GitHub Blog.

🔗 Read more: https://github.blog/ai-and-ml/github-copilot/how-to-bring-your-software-delivery-workflow-into-github-with-agent-apps/
📰 Source: GitHub Blog
📅 2026-08-14 16:00 UTC

#DevOps #Tech #Automation #CloudNative
🚀 Talos Linux v1.14.0-rc.1 released

Talos 1.14.0-rc.1 (2026-08-14) Welcome to the v1.14.0-rc.1 release of Talos! This is a pre-release of Talos Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues . DNS over TLS (DoT) and DNS over HTTP...

🔗 Read more: https://github.com/siderolabs/talos/releases/tag/v1.14.0-rc.1
📰 Source: GitHub Releases (Orchestration & Runtime)
📅 2026-08-14 21:15 UTC

#DevOps #Tech #Automation #CloudNative
🚀 Calico v3.34.0-0.dev: Merge pull request #13537 from danudey/begin-dev-3.34 released

chore: begin development on v3.34

🔗 Read more: https://github.com/projectcalico/calico/releases/tag/v3.34.0-0.dev
📰 Source: GitHub Releases (Networking & Mesh)
📅 2026-08-15 20:02 UTC

#DevOps #Tech #Automation #CloudNative
🚀 Git Beyond Commit and Push: Why branching and history are how teams think

I have seen too many junior engineers, and even some seniors, treat Git as if it is merely a personal backup tool. They push directly to… Continue reading on Medium »

🔗 Read more: https://medium.com/@mark.w.1987/git-beyond-commit-and-push-why-branching-and-history-are-how-teams-think-fdee050db7e2?source=rss------ci_cd-5
📰 Source: Medium
📅 2026-08-17 05:58 UTC

#DevOps #Tech #Automation #CloudNative
🚀 Mimir mimir-distributed-6.3.0-weekly.408: Release mimir-distributed Helm chart 6.3.0-weekly.408 (#16393) released

Automated PR created by helm-weekly-release-pr.yaml Co-authored-by: mimir-vendoring[bot] <149193068+mimir-vendoring[bot]@users.noreply.github.com>

🔗 Read more: https://github.com/grafana/mimir/releases/tag/mimir-distributed-6.3.0-weekly.408
📰 Source: GitHub Releases (Observability)
📅 2026-08-17 12:13 UTC

#DevOps #Tech #Automation #CloudNative
🚀 Pulumi sdk/v3.258.0: Update language runtimes (#24345) released

Overview Bumps language runtime versions: dotnet v3.111.1 → v3.112.0 , java v1.36.0 → v1.36.1 , yaml v1.38.2 → v1.38.3 .

🔗 Read more: https://github.com/pulumi/pulumi/releases/tag/sdk%2Fv3.258.0
📰 Source: GitHub Releases (IaC & Provisioning)
📅 2026-08-17 12:36 UTC

#DevOps #Tech #Automation #CloudNative
🚀 Istio Istio 1.31.0-beta.1 released

New release of Istio in the Networking & Mesh category.

🔗 Read more: https://github.com/istio/istio/releases/tag/1.31.0-beta.1
📰 Source: GitHub Releases (Networking & Mesh)
📅 2026-08-17 12:46 UTC

#DevOps #Tech #Automation #CloudNative
🚀 GitHub Stacked PRs: A Practical Guide to Smaller, Faster Code Reviews

Large pull requests are difficult to review well. Continue reading on Level Up Coding »

🔗 Read more: https://levelup.gitconnected.com/github-stacked-prs-a-practical-guide-to-smaller-faster-code-reviews-77b63dfc227d?source=rss------gitops-5
📰 Source: Medium
📅 2026-08-17 15:27 UTC

#DevOps #Tech #Automation #CloudNative
👍1
🚀 How canvases make agentic workflows visible, steerable, and cost-efficient

Chat is great for intent, but agent work gets lost in the scroll. Here is how I use canvases with my agentic workflows—and why your workflow also deserves a canvas.
The post How canvases make agentic workflows visible, steerable, and cost-efficient a...

🔗 Read more: https://github.blog/ai-and-ml/github-copilot/how-canvases-make-agentic-workflows-visible-steerable-and-cost-efficient/
📰 Source: GitHub Blog
📅 2026-08-17 16:00 UTC

#DevOps #Tech #Automation #CloudNative
🚀 Open Policy Agent v1.19.1 released

This release uses the latest version of Go (1.26.6) to build OPA, fixing stdlib vulnerabilities in code that OPA's HTTP handler and crypto builtins use: https://pkg.go.dev/vuln/GO-2026-6218 https://pkg.go.dev/vuln/GO-2026-6091 https://pkg.go.dev/vuln...

🔗 Read more: https://github.com/open-policy-agent/opa/releases/tag/v1.19.1
📰 Source: GitHub Releases (Secrets & Security)
📅 2026-08-17 16:38 UTC

#DevOps #Tech #Automation #CloudNative
😁2😢1
🚀 Managing variant drift with generic Helm templates

Generic helm templates push variant drift management into values files, which are not amenable to reusable tooling. Continue reading on ITNEXT »

🔗 Read more: https://itnext.io/managing-variant-drift-with-generic-helm-templates-f7b8433dd0b8?source=rss------gitops-5
📰 Source: Medium
📅 2026-08-17 16:58 UTC

#DevOps #Tech #Automation #CloudNative
🚀 OpenTelemetry Collector service/telemetry/telemetrytest/v0.159.0 released

Module set beta, Version v0.159.0

🔗 Read more: https://github.com/open-telemetry/opentelemetry-collector/releases/tag/service%2Ftelemetry%2Ftelemetrytest%2Fv0.159.0
📰 Source: GitHub Releases (Observability)
📅 2026-08-17 17:22 UTC

#DevOps #Tech #Automation #CloudNative
🚀 OpenTelemetry Collector service/v0.159.0 released

Module set beta, Version v0.159.0

🔗 Read more: https://github.com/open-telemetry/opentelemetry-collector/releases/tag/service%2Fv0.159.0
📰 Source: GitHub Releases (Observability)
📅 2026-08-17 17:22 UTC

#DevOps #Tech #Automation #CloudNative
😁2
npm-пакет @7nohe/openapi-react-query-codegen був скомпрометований внаслідок недосконалої конфігурації workflow GitHub Actions.

Зловмисник виявив, що workflow дозволяв фактично будь-якому учаснику Pull Request ініціювати публікацію пакета шляхом додавання коментаря npm publish. При цьому відсутня перевірка повноважень користувача на виконання релізу. Завдяки механізмам npm Trusted Publishing та OIDC, workflow мав достатній рівень привілеїв для публікації шкідливих версій пакета.

Було опубліковано 10 заражених версій. Шкідливий код активувався під час встановлення пакета та намагався:

• викрасти GitHub credentials / tokens;
• отримати доступ до Google Cloud metadata;
• виявити інструменти SSH/SCP;
• переглянути список запущених процесів;
• завантажити та виконати додатковий payload за допомогою Bun.

Ключовий висновок для спеціалістів DevOps: механізми Trusted Publishing/OIDC не забезпечують захисту від компрометації, якщо сам CI/CD workflow дозволяє недовіреному користувачу ініціювати job із підвищеними привілеями. Необхідно перевіряти author_association та повноваження для команд, надісланих у PR, уникати виконання коду з недовірених PR у release jobs та максимально обмежувати доступ id-token: write.

У разі використання пакета автори рекомендують перейти на відому безпечну версію, ізолювати потенційно уражені системи та виконати ротацию усіх credentials, до яких мав доступ runner.
😢1