Security Radar · Issue 6 DevSecOps Weekly July 5, 2026 · Weekly Edition Registries under siege, an unpatched pipeline flaw with no fix in sight, and JFrog’s governance play takes center stage. At a glance Package-registry supply-chain attacks dominated the week, and JFrog’s own research desk was in the middle…
Category: Secure
DevSecOps Weekly — June 28, 2026
Security Radar · Issue 5 DevSecOps Weekly June 28, 2026 · Weekly Edition Pipeline, registry, and platform security — what shipped, what broke, what to do about it. At a glance CI/CD pipeline attacks dominated the week. The Cordyceps research exposed critical flaws in GitHub Actions workflows across more than…
DevSecOps Weekly — June 21, 2026
Security Radar · Issue 4 DevSecOps Weekly June 21, 2026 · Weekly Edition Pipeline, registry, and platform security — what shipped, what broke, what to do about it. At a glance North Korea owned the supply-chain headlines this week, and the vector was npm. JFrog's threat-research team caught “easy-day-js” —…
DevSecOps Weekly — June 14, 2026
Security Radar · Issue 3 DevSecOps Weekly June 14, 2026 · Weekly Edition Pipeline, registry, and platform security — what shipped, what broke, what to do about it. At a glance This week the package registries are the front line again, and the attackers have shifted technique. The headline event…
DevSecOps Weekly — June 7, 2026
Security Radar · Issue 2 DevSecOps Weekly June 7, 2026 Pipeline, registry, and platform security — what shipped, what broke, what to do about it. At a glance The TanStack postmortem closes the May 11 chapter with the most useful artifact yet: a maintainer-side breakdown of the chained GitHub Actions…
The DevSecOps Signal — May 24, 2026
DevSecOps Bulletin · Inaugural Issue · May 24, 2026 The DevSecOps Signal Secure software supply chains, build-pipeline integrity, and the developer-security-ops collaboration This week at a glance Welcome to the inaugural issue of The DevSecOps Signal. This bulletin focuses on the seams where development, security, and operations collide — secure…