Moving DevOps Security Out Of The 'Stone Age'
DARKReading, Thursday, September 26th, 2024
Developers need to do more than scan code and vet software components, and ops should do more than just defend the deployment pipeline.
Combining software development, deployment, and operations pipelines into DevOps teams promises increased efficiency, easier and more frequent updates, and higher-quality applications. Yet the complexity of the infrastructure has also led to a growing attack surface that is hard to monitor and maintain.
On the development side, the average organization uses four to nine different programming languages, deals with millions of new packages and images every year, and has to remediate thousands of vulnerabilities in the most common open source components, according to JFrog's "Software Supply Chain State of the Union 2024" report.