Skip to main content

Posts

GitHub Slams the Brakes on Private Vulnerability Reports

Drowning in AI-generated bug reports? GitHub has a radical answer: Stop accounts from reporting them. GitHub’s new limits on bug reports aren’t a solution to the AI bug-report flood. Anything but! They’re an admission that the traditional security-disclosure workflow, with human maintainers in the loop, simply doesn’t scale. The scarce resource is no longer discovering security holes; it’s informed human judgment. Specifically, GitHub has introduced daily rate limits on new private vulnerability reports. The goal is to give open-source maintainers breathing space to reduce the burden of low-quality and automated security submissions without closing off private disclosure channels to legitimate researchers. As GitHub said, and we all know, open-source maintainers are receiving an increasing number of reports that “bury the reports that matter.” These new restrictions respond to the flood of bulk and automated filings. As Dan Lorenc, co-founder and CEO ...
Recent posts

Ten Great DevOps Job Opportunities

DevOps.com is now providing a weekly DevOps jobs report through which opportunities for DevOps professionals will be highlighted as part of an effort to better serve our audience. Our goal in these challenging economic times is to make it just that much easier for DevOps professionals to advance their careers. Of course, the pool of available DevOps talent is still relatively constrained, so when one DevOps professional takes on a new role, it tends to create opportunities for others. The ten job postings shared this week are selected based on the company looking to hire, the vertical industry segment and naturally, the pay scale being offered. We’re also committed to providing additional insights into the state of the DevOps job market. In the meantime, for your consideration. Greenhouse Datadog New York, NY Senior Software Engineer – CI/CD Security $192,000 to $240,000 GitLab Remote, US Distinguished Engineer, Core DevOps $250,000 to $349,000 Motional Boston...

Open Source Mod Brings Rate Limits, Costs and CI Status Into View for Claude Code Users

AI coding agents burn through resources in ways that are hard to see. A developer starts a long task in Claude Code, and the session quietly eats into a context window, a five-hour rate limit, a weekly cap, and a budget. Most of the time, nobody notices until something runs out. An open-source project called Claude Statuspane takes a crack at that problem. Built by developer Anji Xu and published on GitHub under an MIT license, it adds a floating status card above the Claude Code prompt in the terminal. The card shows the active model and reasoning effort level, how much of the context window is in use, progress against five-hour and seven-day rate limits with reset countdowns, the current directory and git branch, and the session’s running cost. It’s a small tool. But it points to a bigger issue for DevOps teams. As AI agents take on longer, more autonomous work, the people running them need the same kind of telemetry they already expect from build systems and production ...

How to Move AI SRE Agents From Demo to Production

An AI agent that works on an engineer’s laptop can feel like a breakthrough. It can read logs, query observability tools, inspect cloud resources and connect a failed deployment to a bad configuration change in minutes. For a single investigation, under close human supervision, that is real progress. It is also the easy part. The hard part is making that same capability available across production environments. On a laptop, an agent does not have to manage concurrent sessions, preserve investigation history, control token spend or enforce scoped permissions. It can act with borrowed access and temporary context. The same setup can break down quickly once the agent becomes part of real incident response. In production, the agent has to keep working after the first session, leave behind evidence others can trust, and stay inside the access, cost and automation guardrails the business has set. A Supervised Session Is Not a Production System Local agent frameworks make experimentation...

The DevOps Standard Gives Teams a Shared Model for Software Delivery

A release can pass every pipeline check and still leave an organization uncertain about whether to proceed. Security evidence may exist in another system, the recovery plan may be incomplete, and nobody may own the final decision. The difficulty lies in how the delivery system connects its capabilities and responsibilities. The new DEVOPS INSTITUTE Official Book: The DevOps Standard , published by PeopleCert on October 1, 2026, addresses that problem with a vendor-neutral definition and operating model. It gives practitioners a shared reference for examining delivery across organizational boundaries, including AI-assisted work. It helps teams identify which capability needs attention and what evidence would demonstrate improvement. I served as the book’s lead contributor. PeopleCert and many professionals who reviewed the material helped shape a reference intended for use across different organizations and technology environments. The question is how that reference changes ever...

From Software Supply Chains to AI Vulnerabilities: Why Neither Solves Enterprise Linux Security

For nearly a decade, cybersecurity has been dominated by one overarching concern: securing the software supply chain. Organizations invested heavily in Software Bills of Materials (SBOMs), artifact signing, provenance frameworks, reproducible builds, and vulnerability scanners capable of identifying compromised dependencies before software reached production. The software supply chain became the industry’s focal point, accelerated by incidents such as SolarWinds, Log4Shell, XZ Utils, and the increasing sophistication of nation-state attacks targeting open source ecosystems. Today, however, the spotlight has shifted once again. AI models, autonomous agents, prompt injection attacks, model poisoning, insecure MCP servers, and malicious agent interactions have become the new security frontier. Vendors are rapidly introducing AI security platforms capable of monitoring prompts, identifying unsafe agent behavior, validating tool usage, and detecting model vulnerabilities. This trans...

IBM Moves Its Bob Coding Agent Inside the Firewall

Plenty of enterprises want AI coding agents. Fewer are willing to send their source code to someone else’s cloud to get them. That tension has slowed adoption at banks, insurers, government agencies and other organizations that build software under strict rules about where code and data can live. IBM is betting a self-hosted option will help close the gap. This week, the company announced that IBM Bob, its agentic software development platform, can now run on-premises, in private clouds, in sovereign clouds and in fully air-gapped environments. IBM made Bob generally available as a SaaS offering in April. At the time, it said on-premises deployment would come in a future release. That release is now here. Bob is meant to do more than complete code. IBM pitches it as a partner across the software development lifecycle, from planning and design through coding, testing, deployment, and modernization. It coordinates specialized agents for code, tests, documentation, and pipelines. ...