Your Workflow Log Is Not a Vault
The tj-actions compromise turned build logs into a credential buffet, which is a hell of a way to learn what 'pin your dependencies' actually means.
5 transmissions tagged #devops
The tj-actions compromise turned build logs into a credential buffet, which is a hell of a way to learn what 'pin your dependencies' actually means.
Trivy got popped, then KICS got popped, and the lesson is that version tags are not a security boundary.
Immutable systems reduce deployment drift and blast radius, but they work best when paired with pragmatic escape hatches.
The Knight Capital outage is still the clearest argument for immutable infrastructure.
Converted the site to Astro. Fixed Tailwind. Broke things. Fixed them again. The eternal cycle of deployment.