# CI/CD workflows

Published articles for CI/CD workflows.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Turborepo and Vercel Remote Cache now support OpenID Connect (OIDC)

DevFeed: [Turborepo and Vercel Remote Cache now support OpenID Connect (OIDC)](<https://devfeed.tech/articles/turborepo-and-vercel-remote-cache-now-support-openid-connect-oidc-1114.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/turborepo-and-remote-cache-now-support-openid-connect-oidc>)

Author: Mery Kaftar

Published: 2026-07-30T00:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>), [Cache](<https://devfeed.tech/topics/cache.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [ci-cd-workflows](<https://devfeed.tech/tags/ci-cd-workflows.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [github](<https://devfeed.tech/tags/github.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [policy](<https://devfeed.tech/tags/policy.md>), [remote](<https://devfeed.tech/tags/remote.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

Turborepo and Vercel Remote Cache now support exchanging OIDC tokens from CI/CD workflows for short-lived Turborepo access tokens. The article recommends migrating from long-lived Personal Access Tokens to OIDC and explains where to configure the required policy.

### Source excerpt

You can now exchange OIDC tokens from CI/CD workflows, including GitHub workflows, for short-lived Turborepo access tokens. These tokens grant access to Vercel's Remote Cache, and are a more secure alternative to long-lived Personal Access Tokens (PATs). OIDC tokens are short-lived, only grant access to Vercel Remote Cache, and are associated with your Vercel team, rather than a specific team member. We recommend all customers migrate their CI/CD workflows from PATs to OIDC. Get started by adding a Turborepo OIDC policy under Settings -> Build and Deployment -> OIDC Policies for CLI Access and learn more in the documentation. Read more

## Introducing Chainguard Repository: A unified experience for secure-by-default open source artifacts

DevFeed: [Introducing Chainguard Repository: A unified experience for secure-by-default open source artifacts](<https://devfeed.tech/articles/introducing-chainguard-repository-a-unified-experience-for-secure-by-default-open-source-artifacts-13113.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-repository>)

Published: 2026-03-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard repository](<https://devfeed.tech/topics/chainguard-repository.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-repo](<https://devfeed.tech/tags/chainguard-repo.md>), [chainguard-repository](<https://devfeed.tech/tags/chainguard-repository.md>), [ci-cd-workflows](<https://devfeed.tech/tags/ci-cd-workflows.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [packages](<https://devfeed.tech/tags/packages.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [virtual-machine-images](<https://devfeed.tech/tags/virtual-machine-images.md>)

### AI overview

Chainguard introduces Chainguard Repository, a unified experience for consuming secure-by-default open source artifacts with configurable policy enforcement. It brings together container images, libraries, OS packages, agent skills, CI/CD workflows, and virtual machine images through Chainguard-managed endpoints and provides compliance controls, security improvements through source rebuilds, and visibility dashboards.

### Source excerpt

Chainguard Repository is a single, Chainguard-managed experience for pulling secure-by-default artifacts with built-in, configurable policy enforcement.

## Introducing Chainguard Actions: CI/CD workflows you can trust

DevFeed: [Introducing Chainguard Actions: CI/CD workflows you can trust](<https://devfeed.tech/articles/introducing-chainguard-actions-ci-cd-workflows-you-can-trust-13106.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-actions>)

Published: 2026-03-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard actions](<https://devfeed.tech/topics/chainguard-actions.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>)

Tags: [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-actions](<https://devfeed.tech/tags/chainguard-actions.md>), [chainguard-for-github](<https://devfeed.tech/tags/chainguard-for-github.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [ci-cd-workflows](<https://devfeed.tech/tags/ci-cd-workflows.md>), [coding-agents](<https://devfeed.tech/tags/coding-agents.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [secure-ci-cd-workflows](<https://devfeed.tech/tags/secure-ci-cd-workflows.md>), [secure-github-actions](<https://devfeed.tech/tags/secure-github-actions.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard introduces Chainguard Actions, a securely rebuilt and continuously maintained catalog of GitHub Actions and similar CI/CD workflows. The service aims to provide secure-by-default automation for privileged software delivery pipelines, reducing risks from unaudited third-party workflows, secret exposure, unsafe shell expressions, and insecure input handling.

### Source excerpt

Chainguard Actions is a securely rebuilt catalog of GitHub Actions and similar CI/CD workflows built and continuously maintained in the Chainguard Factory.

## Watch the on-demand webinar: Shift left without the strain

DevFeed: [Watch the on-demand webinar: Shift left without the strain](<https://devfeed.tech/articles/watch-the-on-demand-webinar-shift-left-without-the-strain-7749.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/watch-the-on-demand-webinar-shift-left-without-the-strain>)

Author: Rob Samuels

Published: 2025-07-14T13:00:00Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [ci-cd-workflows](<https://devfeed.tech/tags/ci-cd-workflows.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [containers](<https://devfeed.tech/tags/containers.md>), [docker](<https://devfeed.tech/tags/docker.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-delivery](<https://devfeed.tech/tags/software-delivery.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article promotes an on-demand webinar about shifting application security left without slowing software delivery. It discusses the challenges of integrating DAST into CI/CD workflows, including slow scans, false positives, and workflow friction, and presents Burp Suite DAST as a fast, configurable, Docker-based solution that integrates with common pipeline tools.

### Source excerpt

Shifting security left promises faster, safer software delivery - but for many teams, that promise is undercut by painful scan performance, false positives, and pipeline friction. In our recent webina

## CI CD for OpenHarmony Project -- GitHub Action

DevFeed: [CI CD for OpenHarmony Project -- GitHub Action](<https://devfeed.tech/articles/ci-cd-for-openharmony-project-github-action-24547.md>)

Original publisher: [Read original article](<https://medium.com/snapp-mobile/ci-cd-for-openharmony-project-github-action-8ba7940a3d2d?source=rss----bcd96e620b02---4>)

Author: Payam Zahedi

Published: 2024-12-09T12:05:48Z

Content type: tutorial

Language: en

Sources: [Snapp Mobile - Medium](<https://devfeed.tech/sources/snapp-mobile-medium.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [ark-ts](<https://devfeed.tech/tags/ark-ts.md>), [build](<https://devfeed.tech/tags/build.md>), [building](<https://devfeed.tech/tags/building.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [ci-cd-pipeline](<https://devfeed.tech/tags/ci-cd-pipeline.md>), [ci-cd-workflows](<https://devfeed.tech/tags/ci-cd-workflows.md>), [github](<https://devfeed.tech/tags/github.md>), [github-action](<https://devfeed.tech/tags/github-action.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [harmony-os](<https://devfeed.tech/tags/harmony-os.md>), [open-harmony](<https://devfeed.tech/tags/open-harmony.md>), [sdk](<https://devfeed.tech/tags/sdk.md>), [testing](<https://devfeed.tech/tags/testing.md>), [verify](<https://devfeed.tech/tags/verify.md>)

### AI overview

This tutorial explains how to create a GitHub Actions CI/CD workflow for building and verifying an OpenHarmony application. It introduces the roles of DevEco Studio, Hvigor, OHPM, the OpenHarmony Code Linter, and the reusable oh-action for preparing the required SDK and command-line tools.

### Source excerpt

CI CD for OpenHarmony Project -- GitHub Action When developing OpenHarmony, we typically use DevEco Studio to write our code, build the project, test it, and run it on our devices, with DevEco Studio taking care of everything under the hood. However, as engineers, we love to automate repetitive processes, right? This is where CI/CD workflows become incredibly useful. GitHub Actions, in particular, is a popular and highly customizable workflow solution. In this article, we'll explore how to create a workflow on GitHub Actions to build and verify our OpenHarmony application. A Little Context To write our GitHub Action workflow, we first need to understand how DevEco Studio works under the hood. Specifically, what tools does it install, and how are they used? In this article, we won't dive too deep into all OpenHarmony tools and DevEco Studio capabilities. Instead, we'll provide a brief overview to understand the components needed for our workflow. hvigorw Hvigor is a simple build tool, much like Gradle for Android, but designed specifically for OpenHarmony apps. It helps you manage tasks, dependencies, and builds easily. DevEco Studio uses hvigorw to build, test, and run apps on devices. ohpm OHPM (OpenHarmony Package Manager) is akin to npm for JavaScript, but tailored for OpenHarmony applications. It helps facilitate the publishing, installation, and management of dependencies for shared packages. DevEco Studio uses OHPM to manage third-party libraries within OpenHarmony projects. Code Linter OpenHarmony's Code Linter is a tool that checks ArkTS and TypeScript code for best practices and coding standards. It helps developers identify and fix issues during development, ensuring high-quality code. Now that we have a good understanding of the tools involved, the next step is to bring these components together into a cohesive GitHub Action that can automate our workflow. This is where oh-action steps in. GitHub - Snapp-Mobile/oh-action: The oh-action is a GitHub Action t