In a sophisticated supply chain manipulation, the xygeni-action GitHub Action was recently targeted by a critical “tag...
CI/CD security
Christopher Robinson, Chief Technology Officer and Chief Security Architect at the Open Source Security Foundation (OpenSSF), has...
Maintainers of Jenkins, the world’s leading open-source automation server, have issued critical security updates to address two...
The maintainers of PHPUnit, the industry-standard testing framework for PHP, have released a critical security update to...
A seemingly minor misconfiguration in a regular expression could have allowed attackers to seize control of critical...
GitLab has released an important security update today affecting both its Community Edition (CE) and Enterprise Edition...
The Docker Compose project has disclosed a high-severity path traversal vulnerability tracked as CVE-2025-62725 (CVSS v4 8.9),...
GitLab has released versions 18.5.1, 18.4.3, and 18.3.5 for both Community Edition (CE) and Enterprise Edition (EE)...
A critical vulnerability in AWS Amplify’s UI generation tool, @aws-amplify/codegen-ui, is putting developers—and their build pipelines—at serious...
Jenkins, a popular open-source automation server, is a crucial tool for many development and operations teams. A...