TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Number of incidents affecting GitHub, Bitbucket, Gitlab and Jira is rising

23 点作者 t_believ-er8739 个月前

4 条评论

thanksgiving9 个月前
In my opinion, the only true solution is to slow down “velocity” in development teams. If the developers are to be held responsible for producing good, secure code, Only the developers can decide when a feature is ready, not the business.<p>If the business wants to dictate deadlines, the business is responsible for security.<p>Edit: I should say development team to include qa, but we don’t have those anymore at most places.
评论 #41200596 未加载
评论 #41200544 未加载
评论 #41200474 未加载
drewcoo9 个月前
The industry response to this seems to be &quot;DevSecOps,&quot; where the only real &quot;Sec&quot; is reactionary monitoring. Monitoring doesn&#x27;t keep incidents from happening. It only raises internal awareness.<p>This is the best that most separate security teams do, too.<p>In all fairness, the &quot;DevOps&quot; part of things can manage deploys in ways to minimize exposure. But most teams that I&#x27;ve seen revert to manual &quot;process&quot; whenever something unusual occurs, so forget about the ideal automated responses to problems we were promised when we were trying to automate sysadmins out of their jobs. There are several layers of broken here that we&#x27;re not allowed to talk about.
评论 #41234799 未加载
评论 #41200354 未加载
firtoz9 个月前
I wonder if eventually we&#x27;ll go back to either &quot;more open&quot; or &quot;more decentralised&quot; versions of these, in the longer term. I know there are quite a few that exist, which is in a way already &quot;somewhat decentralised&quot;, but some may need to be more &quot;inter-connected&quot; to at least have some of the core &quot;moat&quot; functionalities of GitHub e.g. &quot;see all things this person worked on&quot;, &quot;how active are they in the overall community&quot;, etc. I can think of some technical bridges, at least...?
CAP_NET_ADMIN9 个月前
Around 2021 a lot of higher-up people at my company pushed for moving from our local Gitlab instance (neatly hidden in our segmented VPN network) to the global one - because that&#x27;s what all of the cool guys are doing.<p>I&#x27;ve resisted this, because I know that I can sleep peacefully at night when the inevitable monthly &quot;GitLab Critical Patch Release&quot; email comes.