The Cloud Native Computing Foundation (CNCF) announces the expansion of OpenTelemetry into CI/CD observability, enabling standardized and vendor-agnostic monitoring of CI/CD pipelines.
GitLab introduces CI/CD Steps, a new programming language designed for simplifying complex DevSecOps automation workflows.
Conor Barber explores the evolution of infrastructure from YAML configurations to pipelines-as-code, focusing on modern CI/CD systems like GitHub Actions, GitLab, and CircleCI. The presentation was given at QCon San Francisco 2023, discussing how moving away from YAML can improve scalability, cost efficiency, and developer experience.
Research shows that GitHub Actions, a popular CI/CD platform, is vulnerable to typosquatting attacks, where malicious actors exploit spelling mistakes in action names to trick developers into running malicious code.