# security best practices

Published articles for security best practices.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS

DevFeed: [Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS](<https://devfeed.tech/articles/fast-track-ism-ready-cloud-environments-and-irap-assessments-with-landing-zone-accelerator-on-aws-4681.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/fast-track-ism-ready-cloud-environments-and-irap-assessments-with-landing-zone-accelerator-on-aws/>)

Author: Kevin Donohue

Published: 2026-08-25T21:53:49Z

Content type: article

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [australia](<https://devfeed.tech/tags/australia.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [governance](<https://devfeed.tech/tags/governance.md>), [government](<https://devfeed.tech/tags/government.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [irap](<https://devfeed.tech/tags/irap.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>)

### AI overview

This AWS security post announces an independent assessment report on Landing Zone Accelerator on AWS (LZA). It explains how LZA can automatically deploy multi-account AWS environments with coverage for Australian Government Information Security Manual (ISM) security controls, and describes configuration-drift testing and compliance documentation intended to support IRAP assessment readiness.

### Source excerpt

This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted [...]

## Announcing the CIS Benchmark for CockroachDB v25.x

DevFeed: [Announcing the CIS Benchmark for CockroachDB v25.x](<https://devfeed.tech/articles/announcing-the-cis-benchmark-for-cockroachdb-v25-x-23757.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/cis-benchmark-cockroachdb-security>)

Author: Adam Brennick,Ayog Mohanty

Published: 2026-07-14T00:00:00Z

Content type: release

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cockroach Labs](<https://devfeed.tech/topics/cockroach-labs.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Database](<https://devfeed.tech/topics/database.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cockroach-labs](<https://devfeed.tech/tags/cockroach-labs.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [published](<https://devfeed.tech/tags/published.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

The Center for Internet Security has published the CIS CockroachDB v25.x Benchmark, providing a consensus-driven security configuration guide for self-hosted CockroachDB deployments. The article explains how the benchmark can support standardized security practices, audits, compliance reviews, and production configuration validation.

### Source excerpt

We're proud to announce that the Center for Internet Security (CIS) has published the CIS CockroachDB v25.x Benchmark.

## The maturity gap in ML pipeline infrastructure

DevFeed: [The maturity gap in ML pipeline infrastructure](<https://devfeed.tech/articles/the-maturity-gap-in-ml-pipeline-infrastructure-13263.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-maturity-gap-in-ml-pipeline-infrastructure>)

Published: 2026-01-26T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [PyTorch](<https://devfeed.tech/topics/pytorch.md>)

Tags: [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard-pytorch-image](<https://devfeed.tech/tags/chainguard-pytorch-image.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [machine-learning-pipelines](<https://devfeed.tech/tags/machine-learning-pipelines.md>), [ml](<https://devfeed.tech/tags/ml.md>), [ml-ops](<https://devfeed.tech/tags/ml-ops.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [python](<https://devfeed.tech/tags/python.md>), [pytorch](<https://devfeed.tech/tags/pytorch.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [serialization](<https://devfeed.tech/tags/serialization.md>), [serialization-format](<https://devfeed.tech/tags/serialization-format.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

This article argues that ML pipeline infrastructure in 2026 has a security maturity gap: common tooling does not yet provide the secure-by-default protections expected in software engineering. It examines risks including data poisoning, model laundering, and insecure model serialization, and discusses short-term mitigations and longer-term industry improvements.

### Source excerpt

ML pipelines in 2026 still lack secure-by-default tooling. Learn the key security gaps in ML Ops and how teams can reduce risk today.

## Stop choosing between fast incident response and secure access

DevFeed: [Stop choosing between fast incident response and secure access](<https://devfeed.tech/articles/stop-choosing-between-fast-incident-response-and-secure-access-11942.md>)

Original publisher: [Read original article](<https://incident.io/blog/opal-incident-io-integration>)

Author: Brian Hanson

Published: 2025-12-01T15:00:00Z

Content type: release

Language: en

Sources: [The incident.io Blog](<https://devfeed.tech/sources/the-incident-io-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-channel](<https://devfeed.tech/tags/incident-channel.md>), [incident-management](<https://devfeed.tech/tags/incident-management.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [integration](<https://devfeed.tech/tags/integration.md>), [on-call](<https://devfeed.tech/tags/on-call.md>), [operational](<https://devfeed.tech/tags/operational.md>), [outage](<https://devfeed.tech/tags/outage.md>), [post-mortem](<https://devfeed.tech/tags/post-mortem.md>), [production](<https://devfeed.tech/tags/production.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slack-incident](<https://devfeed.tech/tags/slack-incident.md>)

### AI overview

incident.io announces an integration with Opal Security that automatically grants and revokes time-bound production access based on an engineer's on-call schedule. The integration is intended to speed incident response while reducing permanent, overly broad permissions and improving auditability.

### Source excerpt

incident.io's new integration with Opal Security delivers automatic, time-bound production access for on-call engineers, eliminating slow approvals and permanent permissions.

## Cyborg and Redpanda: Secure streaming pipelines for enterprise AI

DevFeed: [Cyborg and Redpanda: Secure streaming pipelines for enterprise AI](<https://devfeed.tech/articles/cyborg-and-redpanda-secure-streaming-pipelines-for-enterprise-ai-12690.md>)

Original publisher: [Read original article](<https://www.redpanda.com/blog/cyborgdb-secure-streaming-enterprise-ai>)

Author: Nicolas Dupont

Published: 2025-10-14T00:00:00Z

Content type: article

Language: en

Sources: [Redpanda](<https://devfeed.tech/sources/redpanda.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Streaming](<https://devfeed.tech/topics/streaming.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Security](<https://devfeed.tech/topics/security.md>), [Embeddings](<https://devfeed.tech/topics/embeddings.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [embeddings](<https://devfeed.tech/tags/embeddings.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [product](<https://devfeed.tech/tags/product.md>), [rag](<https://devfeed.tech/tags/rag.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [use-cases](<https://devfeed.tech/tags/use-cases.md>)

### AI overview

This article explains how CyborgDB and Redpanda Connect can secure enterprise AI streaming pipelines. The approach encrypts vector embeddings before storage while supporting semantic search and RAG over sensitive data, helping organizations address security and compliance concerns.

### Source excerpt

Stream events from Redpanda Connect into CyborgDB for confidential, real-time Enterprise AI workflows.

## Applying Zero Trust Principles to Open Source Software Supply Chain Security

DevFeed: [Applying Zero Trust Principles to Open Source Software Supply Chain Security](<https://devfeed.tech/articles/this-shit-is-hard-applying-zero-trust-to-open-source-software-13299.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unchained-this-shit-is-hard-applying-zero-trust-to-open-source-software>)

Published: 2025-09-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [git](<https://devfeed.tech/tags/git.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [this-shit-is-hard](<https://devfeed.tech/tags/this-shit-is-hard.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article explains how Chainguard applies Zero Trust principles to open source software supply chain security. It discusses weaknesses in Git identity and long-lived credentials, including risks from impersonation, credential theft, and compromised package publishing.

### Source excerpt

Chainguard implements Zero Trust principles into everything we do to protect critical infrastructure in the age of open source. See how we do it.

## Evaluating Container Security with Container Hardening Priorities: Some CHPs for Your SLSA

DevFeed: [Evaluating Container Security with Container Hardening Priorities: Some CHPs for Your SLSA](<https://devfeed.tech/articles/evaluating-container-security-with-container-hardening-priorities-some-chps-for-your-slsa-13031.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/evaluating-container-security-with-container-hardening-priorities-some-chps-for-your-slsa>)

Published: 2025-04-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chps](<https://devfeed.tech/tags/chps.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container-hardening-priorities](<https://devfeed.tech/tags/container-hardening-priorities.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [standard](<https://devfeed.tech/tags/standard.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard introduces Container Hardening Priorities (CHPs), a framework for assessing container image security. CHPs complements SLSA and focuses initially on build-time characteristics including minimalism, provenance, configuration and metadata, and vulnerabilities.

### Source excerpt

Chainguard has announced Container Hardening Priorities (CHPs), a new framework to assess the security of container images. Learn how it works.

## Neon Joins GitHub's Secret Scanning Partner Program to Strengthen Database Security

DevFeed: [Neon Joins GitHub's Secret Scanning Partner Program to Strengthen Database Security](<https://devfeed.tech/articles/neon-joins-github-s-secret-scanning-partner-program-to-strengthen-database-security-5661.md>)

Original publisher: [Read original article](<https://neon.com/blog/neon-joins-githubs-secret-scanning-partner-program-to-strengthen-database-security>)

Author: Busra Demir

Published: 2025-04-02T14:24:49Z

Content type: news

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Secret Scanning](<https://devfeed.tech/topics/secret-scanning.md>), [Security](<https://devfeed.tech/topics/security.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Database](<https://devfeed.tech/topics/database.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [aws](<https://devfeed.tech/tags/aws.md>), [company](<https://devfeed.tech/tags/company.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [github](<https://devfeed.tech/tags/github.md>), [hashicorp-vault](<https://devfeed.tech/tags/hashicorp-vault.md>), [secret-scanning](<https://devfeed.tech/tags/secret-scanning.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>)

### AI overview

Neon announces its participation in GitHub's Secret Scanning Partner Program. GitHub detects exposed Neon database credentials and API keys in public repositories and npm packages, then Neon validates the credentials, alerts its security team through Slack, and notifies affected customers. The article also recommends environment variables, secret management tools, and regular credential rotation.

### Source excerpt

We're excited to announce that Neon is now a GitHub Secret Scanning Partner, joining a group of leading enterprises and technology firms working to enhance security. This partnership helps protect Neon users by automatically detecting exposed Neon database credentials and API key...

## Neon is HIPAA Compliant

DevFeed: [Neon is HIPAA Compliant](<https://devfeed.tech/articles/neon-is-hipaa-compliant-5328.md>)

Original publisher: [Read original article](<https://neon.com/blog/hipaa>)

Author: Busra Demir

Published: 2025-03-13T16:17:42Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Database](<https://devfeed.tech/topics/database.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Shared Responsibility Model](<https://devfeed.tech/topics/shared-responsibility-model.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [company](<https://devfeed.tech/tags/company.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [database](<https://devfeed.tech/tags/database.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [shared-responsibility](<https://devfeed.tech/tags/shared-responsibility.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Neon announces completion of its HIPAA compliance audit, enabling customers to store Protected Health Information (PHI) on its database platform. The article describes safeguards including encryption, role-based access control, audit logging, continuous monitoring, incident response, breach notification, employee training, third-party requirements, and shared customer responsibilities.

### Source excerpt

Neon has completed its HIPAA compliance audit, adding to our security achievements: SOC 2 Type 2, ISO 27001, ISO 27701, GDPR, and CCPA. If your company needs a HIPAA-compliant database, Neon can now securely store Protected Health Information (PHI). What is HIPAA Compliance? The...

## Can Snyk Detect JWT Security Issues?

DevFeed: [Can Snyk Detect JWT Security Issues?](<https://devfeed.tech/articles/can-snyk-detect-jwt-security-issues-7857.md>)

Original publisher: [Read original article](<https://snyk.io/blog/can-snyk-detect-jwt-security-issues/>)

Author: Liran Tal

Published: 2025-03-04T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [API](<https://devfeed.tech/topics/api.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Microservices](<https://devfeed.tech/topics/microservices.md>), [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apis](<https://devfeed.tech/tags/apis.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [json](<https://devfeed.tech/tags/json.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [payload](<https://devfeed.tech/tags/payload.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [signing](<https://devfeed.tech/tags/signing.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [stateless](<https://devfeed.tech/tags/stateless.md>), [token](<https://devfeed.tech/tags/token.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [verify](<https://devfeed.tech/tags/verify.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains what JSON Web Tokens are, how their header, payload, and signature work, and how their stateless design supports authentication for APIs, microservices, and distributed systems. It focuses on detecting and preventing JWT security risks, including broken authentication vulnerabilities and the danger of storing sensitive data in unencrypted tokens.

### Source excerpt

How to detect and prevent JWT security risks? Follow Snyk's JWT security best practices for enhanced security.

## How to Build a Secure Project Management Platform with Next.js, Clerk, and Neon

DevFeed: [How to Build a Secure Project Management Platform with Next.js, Clerk, and Neon](<https://devfeed.tech/articles/how-to-build-a-secure-project-management-platform-with-next-js-clerk-and-neon-5373.md>)

Original publisher: [Read original article](<https://neon.com/blog/how-to-build-a-secure-project-management-platform-with-next-js-clerk-and-neon>)

Author: Brian Morrison

Published: 2025-02-22T01:41:21Z

Content type: tutorial

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Next.js](<https://devfeed.tech/topics/next-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Database](<https://devfeed.tech/topics/database.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [community](<https://devfeed.tech/tags/community.md>), [database](<https://devfeed.tech/tags/database.md>), [developer](<https://devfeed.tech/tags/developer.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [rag](<https://devfeed.tech/tags/rag.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>)

### AI overview

A tutorial on building Kozi, a secure collaborative project and knowledge management web application with Next.js, Clerk, and Neon. It presents security practices including authenticated route protection, authorization checks, expiring tokens, and server-side database access, while outlining features such as organizations, collaborative notes, comments, notifications, and RAG for notes and uploaded files.

### Source excerpt

This article was first published in the Clerk blog. Around 30,000 websites and applications are hacked every day*, and the developer is often to blame. The vast majority of breaches occur due to misconfiguration rather than an actual vulnerability. This could be due to exposed da...

## Announcing Chainguard Custom Assembly: Image Customization Without Complexity

DevFeed: [Announcing Chainguard Custom Assembly: Image Customization Without Complexity](<https://devfeed.tech/articles/announcing-chainguard-custom-assembly-image-customization-without-complexity-12877.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-custom-assembly-image-customization-without-complexity>)

Published: 2025-02-20T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [bash](<https://devfeed.tech/tags/bash.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [curl](<https://devfeed.tech/tags/curl.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [customization](<https://devfeed.tech/tags/customization.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [development](<https://devfeed.tech/tags/development.md>), [docker](<https://devfeed.tech/tags/docker.md>), [image](<https://devfeed.tech/tags/image.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [no-vulnerabilities](<https://devfeed.tech/tags/no-vulnerabilities.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard announces the beta release of Custom Assembly, a product for tailoring Chainguard Images with required packages while preserving hardened builds, security practices, and CVE remediation coverage. The article explains that the product addresses complex, maintenance-heavy customization workflows involving manual image changes, Docker builds, and proprietary pipelines.

### Source excerpt

Custom Assembly is Chainguard's new image customization product that enables companies to consume zero-CVE open source software tailored to unique requirements.

## 10 Docker Security Best Practices

DevFeed: [10 Docker Security Best Practices](<https://devfeed.tech/articles/10-docker-security-best-practices-7763.md>)

Original publisher: [Read original article](<https://snyk.io/blog/10-docker-image-security-best-practices/>)

Author: Liran Tal; Omer Levi Hevroni

Published: 2025-01-08T18:58:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Docker](<https://devfeed.tech/topics/docker.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [alpine](<https://devfeed.tech/tags/alpine.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [c](<https://devfeed.tech/tags/c.md>), [cheat-sheet](<https://devfeed.tech/tags/cheat-sheet.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [debian](<https://devfeed.tech/tags/debian.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [go](<https://devfeed.tech/tags/go.md>), [google](<https://devfeed.tech/tags/google.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains Docker security across image builds, container runtime, supply-chain risks, and orchestration. It presents best practices including using minimal or distroless base images, multi-stage builds, reducing attack surface, and running containers with the least privilege. It also references Docker Hub, Kubernetes, Helm, Alpine Linux, Go, C, Debian, Node, and Google distroless images.

### Source excerpt

Understand the basics of Docker security best practices with our Docker Cheat Sheet to improve container security.

## GitHub branch protection bypass can expose protected credentials to workflows

DevFeed: [GitHub branch protection bypass can expose protected credentials to workflows](<https://devfeed.tech/articles/working-as-unexpected-13341.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/working-as-unexpected>)

Published: 2024-05-31T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>)

Tags: [branch-protection-rules](<https://devfeed.tech/tags/branch-protection-rules.md>), [github](<https://devfeed.tech/tags/github.md>), [github-branch-protections](<https://devfeed.tech/tags/github-branch-protections.md>), [new-branches](<https://devfeed.tech/tags/new-branches.md>), [protected-branches](<https://devfeed.tech/tags/protected-branches.md>), [release-branches](<https://devfeed.tech/tags/release-branches.md>), [release-workflow](<https://devfeed.tech/tags/release-workflow.md>), [secret-storage](<https://devfeed.tech/tags/secret-storage.md>), [secret-store](<https://devfeed.tech/tags/secret-store.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [use-of-github](<https://devfeed.tech/tags/use-of-github.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

The article describes a GitHub branch protection behavior that can allow a newly created branch to become protected and gain access to environment secrets through workflows. The author argues that this behavior can enable credential exfiltration and create risks for projects using wildcard branch protection rules, particularly release workflows.

### Source excerpt

Don't let the unexpected derail your projects. Read our guide on embracing uncertainty in software development and unlock new possibilities.

## Signing CISA's Secure by Design pledge

DevFeed: [Signing CISA's Secure by Design pledge](<https://devfeed.tech/articles/signing-cisa-s-secure-by-design-pledge-13231.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/signing-cisas-secure-by-design-pledge>)

Published: 2024-05-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Auth0](<https://devfeed.tech/topics/auth0.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [auth0](<https://devfeed.tech/tags/auth0.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cve](<https://devfeed.tech/tags/cve.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Chainguard describes signing CISA's Secure by Design pledge and explains how its products and internal systems address the pledge's goals. The article discusses passwordless human login through SSO, MFA requirements, phishing-resistant security keys, and limitations in provider support for OIDC MFA claims.

### Source excerpt

Chainguard proudly signs CISA's Secure by Design pledge. Learn why we support this critical software security initiative.

## Open sourcing Octo STS

DevFeed: [Open sourcing Octo STS](<https://devfeed.tech/articles/open-sourcing-octo-sts-13197.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/open-sourcing-octo-sts>)

Published: 2024-05-02T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [octo sts](<https://devfeed.tech/topics/octo-sts.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [credential-leak](<https://devfeed.tech/tags/credential-leak.md>), [github](<https://devfeed.tech/tags/github.md>), [github-credentials](<https://devfeed.tech/tags/github-credentials.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [octo-sts](<https://devfeed.tech/tags/octo-sts.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-token-service](<https://devfeed.tech/tags/security-token-service.md>), [source](<https://devfeed.tech/tags/source.md>)

### AI overview

Chainguard announces the open sourcing of Octo STS, a GitHub Security Token Service designed to exchange short-lived third-party tokens for short-lived first-party tokens. The repository includes its source code and the infrastructure as code used to deploy and monitor it, enabling teams to inspect, host, and manage their own instance.

### Source excerpt

Open Source Octo STS Released -- Chainguard's solution to eliminate long-lived GitHub credentials. Improve security, collaborate, get updates.

## Zero CVEs and just as fast: Chainguard's Python & Go Images

DevFeed: [Zero CVEs and just as fast: Chainguard's Python & Go Images](<https://devfeed.tech/articles/zero-cves-and-just-as-fast-chainguard-s-python-go-images-13347.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/zero-cves-and-just-as-fast-chainguards-python-go-images>)

Published: 2024-04-24T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Python](<https://devfeed.tech/topics/python.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [benchmark](<https://devfeed.tech/tags/benchmark.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [go](<https://devfeed.tech/tags/go.md>), [performance](<https://devfeed.tech/tags/performance.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard benchmarks its Python and Go container images against upstream open-source equivalents using standard test suites. The Python image averages 1.5 percent faster across 104 tests, while the Go image averages less than one percent slower across 24 tests, indicating essentially tied performance alongside low-to-no CVEs and supply-chain security features.

### Source excerpt

Upgrade your Python and Go security without sacrificing speed. Chainguard Images offer zero CVEs and blazing performance.

## Avoid exploit chaining threats with Chainguard Images

DevFeed: [Avoid exploit chaining threats with Chainguard Images](<https://devfeed.tech/articles/avoid-exploit-chaining-threats-with-chainguard-images-12894.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/avoid-exploit-chaining-threats-with-chainguard-images>)

Published: 2024-04-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [coding](<https://devfeed.tech/topics/coding.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [coding](<https://devfeed.tech/tags/coding.md>), [cve](<https://devfeed.tech/tags/cve.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploit-chaining](<https://devfeed.tech/tags/exploit-chaining.md>), [github](<https://devfeed.tech/tags/github.md>), [image-cve](<https://devfeed.tech/tags/image-cve.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [software](<https://devfeed.tech/tags/software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how attackers combine multiple low-severity vulnerabilities into exploit chains that can produce severe compromise. It uses examples involving Pwn2Own devices and a Chrome renderer RCE analysis to emphasize risks from complex software interactions, memory management, and sandbox escapes, and it presents Chainguard Images and secure coding as defensive considerations.

### Source excerpt

Understand exploit chaining -- linking vulnerabilities for devastating attacks. Learn defense strategies with Chainguard Images and secure coding practices.

## How CVEs slow down developer productivity

DevFeed: [How CVEs slow down developer productivity](<https://devfeed.tech/articles/how-cves-slow-down-developer-productivity-13087.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-cves-slow-down-developer-productivity>)

Published: 2024-04-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [developer-productivity](<https://devfeed.tech/topics/developer-productivity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [common-exposures-and-vulnerabilities](<https://devfeed.tech/tags/common-exposures-and-vulnerabilities.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developer-productivity](<https://devfeed.tech/tags/developer-productivity.md>), [diy](<https://devfeed.tech/tags/diy.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [pain-of-cve](<https://devfeed.tech/tags/pain-of-cve.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how CVE management consumes developer time and harms productivity. It describes false positives, confusing vulnerability information, and regression-testing and dependency challenges, with particular attention to companies that build or operate containers.

### Source excerpt

Tired of wasting time on CVEs? Learn how to streamline container security, boost developer productivity, and reduce risk. Data-backed insights inside.

## 5 security best practices for adopting generative AI code assistants like GitHub Copilot

DevFeed: [5 security best practices for adopting generative AI code assistants like GitHub Copilot](<https://devfeed.tech/articles/5-security-best-practices-for-adopting-generative-ai-code-assistants-like-github-copilot-7776.md>)

Original publisher: [Read original article](<https://snyk.io/blog/5-security-best-practices-generative-ai-code-assistants-copilot/>)

Author: Liqian Lim (林利蒨)

Published: 2024-03-05T12:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Code](<https://devfeed.tech/topics/code.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-completion](<https://devfeed.tech/tags/code-completion.md>), [code-reviews](<https://devfeed.tech/tags/code-reviews.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [errors](<https://devfeed.tech/tags/errors.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-tools](<https://devfeed.tech/tags/security-tools.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

This article presents five security best practices for adopting generative AI code assistants such as GitHub Copilot. It emphasizes keeping humans in the loop, validating and reviewing AI-generated code, educating teams about risks, and using security tools and guardrails.

### Source excerpt

Learn how you can safely adopt AI code completion tools (like Copilot) by applying these 5 best practices and see how Snyk can make it easy to stay secure.

## 5 Node.js security code snippets every backend developer should know

DevFeed: [5 Node.js security code snippets every backend developer should know](<https://devfeed.tech/articles/5-node-js-security-code-snippets-every-backend-developer-should-know-7774.md>)

Original publisher: [Read original article](<https://snyk.io/blog/5-node-js-security-code-snippets-every-backend-developer-should-know/>)

Author: Liran Tal

Published: 2024-02-28T14:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Code](<https://devfeed.tech/topics/code.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backend](<https://devfeed.tech/tags/backend.md>), [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [npm](<https://devfeed.tech/tags/npm.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This blog post presents essential Node.js security code snippets for backend developers. It discusses security best practices such as sanitizing user input, protecting passwords, managing dependencies, and using the Node.js Permissions Model to restrict runtime access to resources.

### Source excerpt

In this blog post, we will be exploring some essential Node.js security code snippets every backend developer should know in 2024.

## An easier road to SOC 2 begins with the right approach -- and the right technology

DevFeed: [An easier road to SOC 2 begins with the right approach -- and the right technology](<https://devfeed.tech/articles/an-easier-road-to-soc-2-begins-with-the-right-approach-and-the-right-technology-12868.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/an-easier-road-to-soc-2-begins-with-the-right-approach-and-the-right-technology>)

Published: 2024-01-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [SOC](<https://devfeed.tech/topics/soc.md>), [Security](<https://devfeed.tech/topics/security.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [breach](<https://devfeed.tech/tags/breach.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [organizational](<https://devfeed.tech/tags/organizational.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

The article explains how SOC 2 certification standardizes the evaluation of an organization's security, availability, processing integrity, confidentiality, and privacy. It presents certification as a way to demonstrate trustworthy security and organizational processes while reducing the need for repeated security questionnaires. The supplied source summary states that Chainguard achieved SOC 2 certification by using its own technology to streamline security processes.

### Source excerpt

Discover how Chainguard achieved SOC 2 certification by leveraging its own technology to streamline security processes.

## Cybersecurity hygiene in co-working spaces: A practical guide

DevFeed: [Cybersecurity hygiene in co-working spaces: A practical guide](<https://devfeed.tech/articles/cybersecurity-hygiene-in-co-working-spaces-a-practical-guide-13018.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cybersecurity-hygiene-in-co-working-spaces-a-practical-guide>)

Published: 2024-01-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [network security](<https://devfeed.tech/topics/network-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Git](<https://devfeed.tech/topics/git.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [USB](<https://devfeed.tech/topics/usb.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [git](<https://devfeed.tech/tags/git.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [guide](<https://devfeed.tech/tags/guide.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-security](<https://devfeed.tech/tags/kubernetes-security.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [usb](<https://devfeed.tech/tags/usb.md>)

### AI overview

A practical guide to cybersecurity hygiene in co-working spaces. It covers Kubernetes security, Git repository protection, device safety, layered defenses, incident response, and security awareness training.

### Source excerpt

Navigate the cybersecurity landscape in shared work environments with essential tips on device safety and incident response.

## Command injection in Python: examples and prevention

DevFeed: [Command injection in Python: examples and prevention](<https://devfeed.tech/articles/command-injection-in-python-examples-and-prevention-7868.md>)

Original publisher: [Read original article](<https://snyk.io/blog/command-injection-python-prevention-examples/>)

Author: Rubaiat Hossain

Published: 2023-12-21T07:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [apps](<https://devfeed.tech/tags/apps.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [developer](<https://devfeed.tech/tags/developer.md>), [draftdotdev](<https://devfeed.tech/tags/draftdotdev.md>), [examples](<https://devfeed.tech/tags/examples.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains command injection vulnerabilities in Python applications, including how unsafe user input passed to system shells or dynamically constructed commands can enable arbitrary command execution. It describes potential consequences such as data breaches and system compromise, and presents security best practices for prevention.

### Source excerpt

In this article, you'll learn all about command injection, including how this vulnerability can manifest in your programs. You'll also learn about common security best practices to safeguard your Python apps from command injection attacks.

[Next page](<https://devfeed.tech/tags/security-best-practices.md?cursor=WyIyMDIzLTEyLTIxVDA3OjAwOjAwKzAwOjAwIiwgImFhMWVlYWQ1LTJjZTctNDhmNC1iYjhmLTlmY2ZkNjQ0YjY1YyJd>)