# solarwinds

Published articles for solarwinds.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Growing up the hard way

DevFeed: [Growing up the hard way](<https://devfeed.tech/articles/growing-up-the-hard-way-13072.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/growing-up-the-hard-way>)

Published: 2026-07-22T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [ai regulation](<https://devfeed.tech/topics/ai-regulation.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-software-supply-chain-security](<https://devfeed.tech/tags/chainguard-software-supply-chain-security.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [oss](<https://devfeed.tech/tags/oss.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>)

### AI overview

This opinion argues that open source is entering a difficult transition after supply-chain incidents, regulatory pressure, and the industrialization of malware. It forecasts that the Open Source definition will remain intact while enterprise and regulatory requirements change which open source software organizations are willing or permitted to consume, with AI-driven vulnerability discovery and poisoned distribution channels creating pressure on both fronts.

### Source excerpt

Open source is growing up. Explore why AI, regulation, and enterprise security are reshaping how organizations consume open source software.

## Supply chain attacks expose weaknesses in open-source software trust

DevFeed: [Supply chain attacks expose weaknesses in open-source software trust](<https://devfeed.tech/articles/open-source-died-in-march-it-just-doesn-t-know-it-yet-13195.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/open-source-died-in-march-it-just-doesnt-know-it-yet>)

Published: 2026-04-09T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [code](<https://devfeed.tech/tags/code.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [oss](<https://devfeed.tech/tags/oss.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [trust](<https://devfeed.tech/tags/trust.md>), [vibe-coding](<https://devfeed.tech/tags/vibe-coding.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

This opinion article argues that a series of open-source supply chain attacks exposed a broken trust model. It discusses attacks involving npm and PyPI packages, stolen credentials, malicious contributors, and the limits of vulnerability scanning and hardening.

### Source excerpt

Five supply chain attacks in 12 days exposed a broken trust model. Learn why scanning and hardening fail, and why trusting the source is the only fix.

## Attacks rewritten: Where malware enters the build

DevFeed: [Attacks rewritten: Where malware enters the build](<https://devfeed.tech/articles/attacks-rewritten-where-malware-enters-the-build-12892.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/attacks-rewritten-where-malware-enters-the-build>)

Published: 2026-04-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [malware](<https://devfeed.tech/tags/malware.md>), [package-malware](<https://devfeed.tech/tags/package-malware.md>), [security](<https://devfeed.tech/tags/security.md>), [sha1-hulud](<https://devfeed.tech/tags/sha1-hulud.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>)

### AI overview

This article explains how modern software supply chain attacks can affect production deployments, CI/CD clusters, developer workstations, and other systems. It describes the shift from exploiting known production vulnerabilities to injecting malicious code upstream through compromised maintainer accounts, package managers, and binary dependencies.

### Source excerpt

Modern supply chain attacks target CI, dev machines, and dependencies. Learn how building from source helps prevent malware and reduce risk.

## From Fragmented Logs to Full-Stack Visibility with SolarWinds Papertrail

DevFeed: [From Fragmented Logs to Full-Stack Visibility with SolarWinds Papertrail](<https://devfeed.tech/articles/from-fragmented-logs-to-full-stack-visibility-with-solarwinds-papertrail-26404.md>)

Original publisher: [Read original article](<https://www.heroku.com/blog/fragmented-logs-to-full-stack-visibility-solarwinds-papertrail/>)

Author: Rachel Revoy

Published: 2026-03-12T15:00:36Z

Content type: article

Language: en

Sources: [Heroku](<https://devfeed.tech/sources/heroku.md>)

Topics: [Heroku](<https://devfeed.tech/topics/heroku.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [solarwinds](<https://devfeed.tech/topics/solarwinds.md>)

Tags: [add-ons](<https://devfeed.tech/tags/add-ons.md>), [apis](<https://devfeed.tech/tags/apis.md>), [databases](<https://devfeed.tech/tags/databases.md>), [developer-tools](<https://devfeed.tech/tags/developer-tools.md>), [dynos](<https://devfeed.tech/tags/dynos.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [heroku](<https://devfeed.tech/tags/heroku.md>), [logs](<https://devfeed.tech/tags/logs.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>)

### AI overview

The article describes how fragmented logs, metrics, deployment activity, and monitoring dashboards complicate troubleshooting for applications running on Heroku. It presents the expanded SolarWinds Papertrail add-on as a unified solution for delivering logs and metrics together.

### Source excerpt

Modern applications on Heroku don't just consist of code. They are living ecosystems comprised of dynos, databases, third-party APIs, and complex user interactions. As these systems scale, so do the logs and metrics. To efficiently extract the signals from the noise you need to understand system health in the context of external factors, like resource [...] The post From Fragmented Logs to Full-Stack Visibility with SolarWinds Papertrail appeared first on Heroku.

## Optimizing Enterprise Operations with Heroku's Advanced Logging Features

DevFeed: [Optimizing Enterprise Operations with Heroku's Advanced Logging Features](<https://devfeed.tech/articles/optimizing-enterprise-operations-with-heroku-s-advanced-logging-features-26481.md>)

Original publisher: [Read original article](<https://www.heroku.com/blog/optimizing-enterprise-operations-herokus-advanced-logging-features/>)

Author: Julián Duque

Published: 2025-05-13T15:00:13Z

Content type: article

Language: en

Sources: [Heroku](<https://devfeed.tech/sources/heroku.md>)

Topics: [Heroku](<https://devfeed.tech/topics/heroku.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>)

Tags: [backend](<https://devfeed.tech/tags/backend.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [distributed](<https://devfeed.tech/tags/distributed.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [heroku](<https://devfeed.tech/tags/heroku.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [operations](<https://devfeed.tech/tags/operations.md>), [performance-optimization](<https://devfeed.tech/tags/performance-optimization.md>), [private-spaces](<https://devfeed.tech/tags/private-spaces.md>), [security-compliance](<https://devfeed.tech/tags/security-compliance.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

The article explains how logging supports enterprise operations and presents Heroku's Private Space Logging as a way to centralize logs from applications and related services. It also mentions scalability, security, data residency, log drains, and compatibility with monitoring tools.

### Source excerpt

Logging is the unsung hero of enterprise operations--quietly saving the day, one log line at a time. Imagine trying to maintain successful applications without knowing what's happening inside them. This would be like flying a plane blindfolded at night, in a storm, with no instruments. Spoiler alert: Neither scenario would end well! Today's distributed systems [...] The post Optimizing Enterprise Operations with Heroku's Advanced Logging Features appeared first on Heroku.

## How SolarWinds uses ClickHouse BYOC for real-time observability at scale

DevFeed: [How SolarWinds uses ClickHouse BYOC for real-time observability at scale](<https://devfeed.tech/articles/how-solarwinds-uses-clickhouse-byoc-for-real-time-observability-at-scale-5297.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/how-solarwinds-uses-clickhouse-for-realtime-observability-at-scale>)

Author: Tony Burke, SolarWinds

Published: 2025-03-11T16:03:36Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [observability](<https://devfeed.tech/topics/observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [solarwinds](<https://devfeed.tech/topics/solarwinds.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>)

Tags: [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [clusters](<https://devfeed.tech/tags/clusters.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [observability](<https://devfeed.tech/tags/observability.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [speed](<https://devfeed.tech/tags/speed.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

SolarWinds uses ClickHouse to process millions of telemetry messages per second for real-time observability, dashboards, alerts, and troubleshooting. The article describes how its platform engineering team tuned ClickHouse and optimized time-sensitive queries to scale while maintaining fast performance, especially for the freshest 60 minutes of incoming telemetry.

### Source excerpt

Read about how SolarWinds leverages ClickHouse to process millions of telemetry messages per second, optimizing query performance for real-time observability at scale.

## Strengthening your software supply chain security

DevFeed: [Strengthening your software supply chain security](<https://devfeed.tech/articles/strengthening-your-software-supply-chain-security-13242.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/strengthening-your-software-supply-chain-security>)

Published: 2024-01-08T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [grype](<https://devfeed.tech/tags/grype.md>), [image](<https://devfeed.tech/tags/image.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software](<https://devfeed.tech/tags/software.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article explains software supply chain risks from open-source and third-party components, using the SolarWinds attack as an example. It recommends verifying artifacts, signing container images, minimizing dependencies, updating software, scanning for vulnerabilities, using smaller base images, adopting reproducible builds, and increasing SLSA maturity.

### Source excerpt

Secure your codebase with advanced supply chain security tactics: artifact authentication, minimal images and more from Chainguard.

## Application and AI roundup - October

DevFeed: [Application and AI roundup - October](<https://devfeed.tech/articles/application-and-ai-roundup-october-36684.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-oct-2023/>)

Author: Adam

Published: 2023-11-09T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Adversarial attacks](<https://devfeed.tech/topics/adversarial-attacks.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [browser](<https://devfeed.tech/topics/browser.md>), [okta](<https://devfeed.tech/topics/okta.md>), [solarwinds](<https://devfeed.tech/topics/solarwinds.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [browser](<https://devfeed.tech/tags/browser.md>), [large-language-models](<https://devfeed.tech/tags/large-language-models.md>), [okta](<https://devfeed.tech/tags/okta.md>), [security](<https://devfeed.tech/tags/security.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An October roundup covering the SEC's case against SolarWinds and its CISO, research on vulnerabilities in large language models and adversarial attacks, AI policy and model behavior, and threat-modeling issues involving browser privacy, Okta's support system, and bug hunting.

### Source excerpt

Exciting news from the SEC, lots of AI, and lots of threat modeling.

## The Cyber Safety Review Board Should Investigate Major Historical Incidents

DevFeed: [The Cyber Safety Review Board Should Investigate Major Historical Incidents](<https://devfeed.tech/articles/the-cyber-safety-review-board-should-investigate-major-historical-incidents-36749.md>)

Original publisher: [Read original article](<https://shostack.org/blog/cyber-safety-review-board-historical-incidents/>)

Author: Adam

Published: 2023-05-25T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [solarwinds](<https://devfeed.tech/topics/solarwinds.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [incident](<https://devfeed.tech/tags/incident.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>)

### AI overview

The article argues that the U.S. Cyber Safety Review Board should investigate major historical cyber incidents, beginning with SolarWinds, to build a respected shared history of cyber incidents. It notes that the board has not investigated SolarWinds and highlights its report on the open source Log4Shell vulnerabilities as clear and helpful.

### Source excerpt

Tarah Wheeler and Adam write in CFR

## The Asset Trap

DevFeed: [The Asset Trap](<https://devfeed.tech/articles/the-asset-trap-36999.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-asset-trap/>)

Author: Adam

Published: 2020-12-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [solarwinds](<https://devfeed.tech/topics/solarwinds.md>), [digital signatures](<https://devfeed.tech/topics/digital-signatures.md>), [email](<https://devfeed.tech/topics/email.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [email](<https://devfeed.tech/tags/email.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [systems](<https://devfeed.tech/tags/systems.md>)

### AI overview

This commentary uses the SolarWinds attack to explain an asset-focused threat-modeling trap. It argues that defenders should consider assets attackers want, such as DKIM keys, which can be used to forge emails that pass validity checks, and recommends rotating those keys regularly.

### Source excerpt

As we look at what's happened with the Russian attack on the US government and others via Solarwinds, I want to shine a spotlight on a lesson we can apply to threat modeling.