Apr 3 · 40 min read · TL;DR — Read This First On March 19, 2026 at approximately 17:43 UTC, threat actor group TeamPCP silently redirected trivy-action@0.34.2 — a real, trusted release already running in thousands of CI/CD
CCorrelic commented
Apr 2 · 12 min read · If it hurts, do it more frequently, and bring the pain forward. — Jez Humble & Dave Farley, Continuous Delivery (2010) Shift left and continuous testing are two of the most misunderstood terms in sof
Join discussion
Mar 30 · 27 min read · Security architecture is not just about selecting the right controls or designing secure systems. It is about proving those controls work, tracking their effectiveness over time, and communicating res
Join discussion
Mar 26 · 5 min read · Every team I've worked with underestimates the cost of finding bugs late. Not by a little, by orders of magnitude. The math is brutal, the pattern is predictable, and yet organisations keep repeating
Join discussion