# Jenkins

Jenkins is an open-source automation server used for continuous integration, continuous delivery, building, testing, and deploying software.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Best Jenkins Alternatives in 2026

DevFeed: [Best Jenkins Alternatives in 2026](<https://devfeed.tech/articles/best-jenkins-alternatives-in-2026-20420.md>)

Original publisher: [Read original article](<https://semaphore.io/blog/best-jenkins-alternatives-in-2026>)

Author: Pete Miloravac

Published: 2026-07-24T09:56:00Z

Content type: article

Language: en

Sources: [Semaphore Engineering](<https://devfeed.tech/sources/semaphore-engineering.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Groovy](<https://devfeed.tech/topics/groovy.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [circleci](<https://devfeed.tech/tags/circleci.md>), [compare](<https://devfeed.tech/tags/compare.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [groovy](<https://devfeed.tech/tags/groovy.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

A 2026 guide compares Jenkins alternatives and explains why teams migrate away from Jenkins, citing maintenance overhead, plugin conflicts, Groovy pipeline complexity, and security-patch concerns. It highlights Semaphore, GitHub Actions, GitLab CI/CD, and CircleCI for different use cases.

### Source excerpt

Jenkins earned its place as the default CI server of the 2010s: it was free, endlessly extensible, and available before any serious managed CI/CD competitor existed. More than a decade later, that same flexibility has become the thing teams complain about most -- plugin sprawl, Groovy pipeline scripts nobody wants to maintain, and infrastructure that [...] The post Best Jenkins Alternatives in 2026 appeared first on Semaphore.

## Nix flake check + JUnit = Junix

DevFeed: [Nix flake check + JUnit = Junix](<https://devfeed.tech/articles/nix-flake-check-junit-junix-31356.md>)

Original publisher: [Read original article](<https://discourse.nixos.org/t/nix-flake-check-junit-junix/79124>)

Author: Yajo

Published: 2026-07-23T12:35:46Z

Content type: release

Language: en

Sources: [Announcements - NixOS Discourse](<https://devfeed.tech/sources/announcements-nixos-discourse.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [build](<https://devfeed.tech/tags/build.md>), [ci](<https://devfeed.tech/tags/ci.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [gitlab-ci](<https://devfeed.tech/tags/gitlab-ci.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>)

### AI overview

Junix converts Nix JSON output into standard JUnit XML reports, allowing Nix builds and checks to integrate with JUnit-compatible CI systems such as GitLab CI, Jenkins, and GitHub Actions. It can evaluate system checks, repeat failed evaluations for full tracebacks, build local checks, include logs, and print a human-readable summary.

### Source excerpt

Hi all! I'd like to share Junix, a small tool that converts Nix @nix JSON output into standard JUnit XML so you can integrate Nix builds with any JUnit-compatible CI (GitLab CI, Jenkins, GitHub Actions, etc.). Try it: cd your/flake nix run gitlab:moduon/junix check -o result.xml This will: Eval all systems checks in one shot If any eval fails, repeat that check's eval to get full traceback Build local system checks Write the JUnit XML report in result.xml with check build logs and eval failure logs, if any Print a colorful human-readable summary 9 posts - 6 participants Read full topic

## Osmocom.org Servers - server outage of host3.osmocom.org

DevFeed: [Osmocom.org Servers - server outage of host3.osmocom.org](<https://devfeed.tech/articles/osmocom-org-servers-server-outage-of-host3-osmocom-org-32755.md>)

Original publisher: [Read original article](<https://osmocom.org/news/328>)

Author: laforge

Published: 2026-07-06T18:58:49Z

Content type: news

Language: en

Sources: [Open Source Mobile Communications: News](<https://devfeed.tech/sources/open-source-mobile-communications-news.md>)

Topics: [servers](<https://devfeed.tech/topics/servers.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [maintenance](<https://devfeed.tech/topics/maintenance.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [debian](<https://devfeed.tech/tags/debian.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [issue](<https://devfeed.tech/tags/issue.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [outage](<https://devfeed.tech/tags/outage.md>), [server](<https://devfeed.tech/tags/server.md>), [servers](<https://devfeed.tech/tags/servers.md>), [tracker](<https://devfeed.tech/tags/tracker.md>), [update](<https://devfeed.tech/tags/update.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

Osmocom.org reports an outage affecting host3.osmocom.org during routine maintenance for a Debian upgrade. The host, which primarily serves Jenkins, downloads, and people subdomains, has fully recovered.

### Source excerpt

We're currently experiencing some troubles during routine maintenance (Debian upgrade) of host3.osmocom.org, which is primarily hosting jenkins.osmocom.org, downloads.osmocom.org and people.osmocom.org. We ask for your patience while we try to resolve the situation. Update: host3 has fully recovered.

## hh.ru's Test Framework Experiments for Handling Flaky Tests

DevFeed: [hh.ru's Test Framework Experiments for Handling Flaky Tests](<https://devfeed.tech/articles/flaky-30665.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/hh/articles/1031996/>)

Author: yzhanov (hh.ru)

Published: 2026-05-07T07:10:11Z

Content type: article

Language: ru

Sources: [HeadHunter RU](<https://devfeed.tech/sources/headhunter-ru.md>)

Topics: [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Job](<https://devfeed.tech/topics/job.md>), [ui](<https://devfeed.tech/topics/ui.md>)

Tags: [flaky](<https://devfeed.tech/tags/flaky.md>), [hh](<https://devfeed.tech/tags/hh.md>), [hh-ru](<https://devfeed.tech/tags/hh-ru.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [job](<https://devfeed.tech/tags/job.md>), [qa](<https://devfeed.tech/tags/qa.md>), [qa-automation](<https://devfeed.tech/tags/qa-automation.md>), [qa-automation-engineer](<https://devfeed.tech/tags/qa-automation-engineer.md>), [qa-engineer](<https://devfeed.tech/tags/qa-engineer.md>), [qa-management](<https://devfeed.tech/tags/qa-management.md>), [qa-mobile](<https://devfeed.tech/tags/qa-mobile.md>), [qa-testing](<https://devfeed.tech/tags/qa-testing.md>), [retry](<https://devfeed.tech/tags/retry.md>), [tag-4adf7d504f34](<https://devfeed.tech/tags/tag-4adf7d504f34.md>), [tag-95a52fc82d81](<https://devfeed.tech/tags/tag-95a52fc82d81.md>), [tag-b7f0358ac141](<https://devfeed.tech/tags/tag-b7f0358ac141.md>), [tag-e34f6dec12c4](<https://devfeed.tech/tags/tag-e34f6dec12c4.md>), [tag-e932065bc8da](<https://devfeed.tech/tags/tag-e932065bc8da.md>), [ui](<https://devfeed.tech/tags/ui.md>)

### AI overview

An hh.ru engineer describes experiments in the test framework to reduce the impact of flaky tests on release automation. One experiment allowed repeated retries until the queue emptied; it added about three minutes to build time and was not adopted in production.

### Source excerpt

Привет, Хабр! Меня зовут Юра Жанов, я занимаюсь автоматизацией тестирования в hh.ru. Про flaky-тесты написано много, борьбу с ними не прекращаем и мы. Но сегодня немного о другом -- хочу поделиться нашим опытом минимизации неприятностей, которые наносят такие тесты. Для этого мы провели ряд экспериментов со стороны тестового фреймворка. Читать далее

## Jenkins Series

DevFeed: [Jenkins Series](<https://devfeed.tech/articles/jenkins-series-4532.md>)

Original publisher: [Read original article](<https://feeds.feedblitz.com/~/953170670/0/baeldung/ops~Jenkins-Series>)

Author: baeldung

Published: 2026-04-03T12:36:55Z

Content type: tutorial

Language: en

Sources: [Baeldung - Ops](<https://devfeed.tech/sources/baeldung-ops.md>)

Topics: [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Groovy](<https://devfeed.tech/topics/groovy.md>), [Scripting](<https://devfeed.tech/topics/scripting.md>), [Server](<https://devfeed.tech/topics/server.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [administration](<https://devfeed.tech/tags/administration.md>), [automation](<https://devfeed.tech/tags/automation.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [docker](<https://devfeed.tech/tags/docker.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [jenkins-series](<https://devfeed.tech/tags/jenkins-series.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [scripting](<https://devfeed.tech/tags/scripting.md>), [series](<https://devfeed.tech/tags/series.md>), [server](<https://devfeed.tech/tags/server.md>)

### AI overview

A tutorial series covering Jenkins pipelines, job management, administration, Groovy scripting, parameterized and parallel builds, and server maintenance across the CI/CD lifecycle.

### Source excerpt

This tutorial provides an overview of Jenkins pipelines, job management, and administration. Related Stories Git Series Troubleshoot Docker Daemon Connection Issues in Jenkins Troubleshooting Jenkins 403 No Valid Crumb in Request Error

## Odin: Dream11's Open-Source Deployment Platform Built After Jenkins Deployment Challenges

DevFeed: [Odin: Dream11's Open-Source Deployment Platform Built After Jenkins Deployment Challenges](<https://devfeed.tech/articles/say-hello-to-odin-from-jenkins-mayhem-to-multicloud-mastery-22625.md>)

Original publisher: [Read original article](<https://medium.com/dreamlockerroom/say-hello-to-odin-from-jenkins-mayhem-to-multicloud-mastery-a42fb5e31d45?source=rss----5c7a7f580b01---4>)

Author: Dream Blog

Published: 2025-12-11T07:55:37Z

Content type: article

Language: en

Sources: [Dream11 Engineering](<https://devfeed.tech/sources/dream11-engineering.md>)

Topics: [Deployment](<https://devfeed.tech/topics/deployment.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Microservice](<https://devfeed.tech/topics/microservice.md>)

Tags: [deployment](<https://devfeed.tech/tags/deployment.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [dream-horizon](<https://devfeed.tech/tags/dream-horizon.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [tech](<https://devfeed.tech/tags/tech.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

This article introduces Odin, Dream Horizon's open-source deployment platform from Dream11. It describes how Dream11 evolved from numerous Jenkins jobs to a deployment system intended to support building, testing, and deploying services through on-demand environments. The article identifies job complexity, limited support for virtual machines and Kubernetes, and the lack of a unified deployment-lifecycle vision as challenges in the earlier setup.

### Source excerpt

By Suraj Gour and Ankit Pare Dream Horizon, our open-source effort to make Dream11's battle-tested tech available to every developer, brings you Odin -- a high-performance deployment platform that lets developers build, break, test, and ship smarter and more efficiently. Explore Odin here. Deployments at Dream11 have come a long way. From Jenkins jobs to on-demand environments, we have reimagined how services are built, tested and deployed. With Odin -- our new deployment system -- developers define what they need and deploy with confidence in seconds. This evolution started with key lessons from our earlier setup. Navigating Jenkins Mayhem: When Jobs Ran Wild It was a regular day at Dream11. A new joiner was browsing onboarding documents, trying to understand how to test their code alongside other dependent microservices, and then eventually deploy it live in production. They simply asked their teammate how to proceed. Here's how their conversation went: The newly joined developer (looking perplexed) asked: "My code is master-merged. How can I test the complete user authentication flow? And what are the steps I need to follow to get my feature live in production? I can't seem to find any documentation around this."The teammate (with a sympathetic sigh) replied: "Come with me. Let's talk to the DevOps team. They'll guide you and take you through the process."Upon reaching the DevOps team, our developer presented their request.The DevOps team (calmly, with the weariness of having answered this question several times) responded: "You want to push this code to production? Alright. We have a set of Jenkins jobs for this."The newly joined developer asked again: "And what about testing in a dev environment and performing a load test?"The DevOps team replied: "For load tests, we have... guess what... separate jobs!" Jenkins jobs introduced more complexity than clarity. More jobs meant greater uncertainty and longer turnaround times. Given our use case, we were running into recurr

## Expanding Chainguard VMs: Zero-CVE Application & Base Virtual Machine Images for Cloud and On-Prem

DevFeed: [Expanding Chainguard VMs: Zero-CVE Application & Base Virtual Machine Images for Cloud and On-Prem](<https://devfeed.tech/articles/expanding-chainguard-vms-zero-cve-application-base-virtual-machine-images-for-cloud-and-on-prem-13035.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/expanding-chainguard-vms-zero-cve-application-base-virtual-machine-images-for-cloud-and-on-prem>)

Published: 2025-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [on-prem](<https://devfeed.tech/topics/on-prem.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [Java](<https://devfeed.tech/topics/java.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [Python](<https://devfeed.tech/topics/python.md>)

Tags: [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-virtual-machines](<https://devfeed.tech/tags/cloud-virtual-machines.md>), [cve](<https://devfeed.tech/tags/cve.md>), [java](<https://devfeed.tech/tags/java.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [os](<https://devfeed.tech/tags/os.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [rebuilds](<https://devfeed.tech/tags/rebuilds.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security-vm-images](<https://devfeed.tech/tags/security-vm-images.md>), [virtual-machine-images](<https://devfeed.tech/tags/virtual-machine-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard VMs is expanding with zero-CVE application images for Jenkins, Nginx, and Squid Proxy, plus base images for Chainguard OS, Java, and Python. The virtual machine images support cloud and on-premises deployments and are continuously rebuilt from source with automated updates, CVE remediation, and SBOM-driven provenance attestations.

### Source excerpt

Chainguard VMs is expanding with new Application and Base VM Images -- giving teams a secure, zero-CVE foundation to build and innovate faster.

## Watch the on-demand webinar: Shift left without the strain

DevFeed: [Watch the on-demand webinar: Shift left without the strain](<https://devfeed.tech/articles/watch-the-on-demand-webinar-shift-left-without-the-strain-7749.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/watch-the-on-demand-webinar-shift-left-without-the-strain>)

Author: Rob Samuels

Published: 2025-07-14T13:00:00Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [ci-cd-workflows](<https://devfeed.tech/tags/ci-cd-workflows.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [containers](<https://devfeed.tech/tags/containers.md>), [docker](<https://devfeed.tech/tags/docker.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-delivery](<https://devfeed.tech/tags/software-delivery.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article promotes an on-demand webinar about shifting application security left without slowing software delivery. It discusses the challenges of integrating DAST into CI/CD workflows, including slow scans, false positives, and workflow friction, and presents Burp Suite DAST as a fast, configurable, Docker-based solution that integrates with common pipeline tools.

### Source excerpt

Shifting security left promises faster, safer software delivery - but for many teams, that promise is undercut by painful scan performance, false positives, and pipeline friction. In our recent webina

## Node.js Test CI Security Incident

DevFeed: [Node.js Test CI Security Incident](<https://devfeed.tech/articles/node-js-test-ci-security-incident-2894.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/vulnerability/march-2025-ci-incident>)

Published: 2025-04-23T16:30:00Z

Content type: article

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Security](<https://devfeed.tech/topics/security.md>), [Git](<https://devfeed.tech/topics/git.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ci](<https://devfeed.tech/tags/ci.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [incident](<https://devfeed.tech/tags/incident.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Node.js reported a successful compromise of several test CI hosts after an attacker used a pull request and an outdated Git commit timestamp to cause Jenkins pipelines to execute altered fork code. The incident exposed a Time-of-Check-Time-of-Use vulnerability involving mutable Git references. The team restricted CI runs, rebuilt 24 compromised hosts, enforced commit SHA validation, audited 140 Jenkins jobs, and patched vulnerable GitHub workflows.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## The Three Stages of Software Maturity: From Hype to Abandonment

DevFeed: [The Three Stages of Software Maturity: From Hype to Abandonment](<https://devfeed.tech/articles/the-3-stages-software-maturity-39843.md>)

Original publisher: [Read original article](<https://www.thinkingintech.com/p/the-3-stages-software-maturity>)

Author: Dariusz Sadowski

Published: 2025-03-15T12:32:17Z

Content type: opinion

Language: en

Sources: [Thinking in Tech](<https://devfeed.tech/sources/thinking-in-tech.md>)

Topics: [Software](<https://devfeed.tech/topics/software.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ci](<https://devfeed.tech/tags/ci.md>), [docker](<https://devfeed.tech/tags/docker.md>), [java](<https://devfeed.tech/tags/java.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [let-s-encrypt](<https://devfeed.tech/tags/let-s-encrypt.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

This opinion article proposes evaluating software maturity through maintenance activity, commercial support, ecosystem integrations, community knowledge, code quality, and culture. It contrasts Docker Swarm with Kubernetes after finding a Swarm Jenkins extension had not changed in four years and had an unresolved vulnerability.

### Source excerpt

From Hype to Abandonment

## How Indeed Replaced Its CI Platform with Gitlab CI

DevFeed: [How Indeed Replaced Its CI Platform with Gitlab CI](<https://devfeed.tech/articles/how-indeed-replaced-its-ci-platform-with-gitlab-ci-29990.md>)

Original publisher: [Read original article](<https://engineering.indeedblog.com/blog/2024/08/indeed-gitlab-ci-migration/>)

Author: Carl Myers

Published: 2024-08-06T15:03:51Z

Content type: article

Language: en

Sources: [Indeed](<https://devfeed.tech/sources/indeed.md>)

Topics: [GitLab](<https://devfeed.tech/topics/gitlab.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ec2](<https://devfeed.tech/tags/ec2.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [gitlab-ci](<https://devfeed.tech/tags/gitlab-ci.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [unsorted](<https://devfeed.tech/tags/unsorted.md>)

### AI overview

Indeed's engineering platform evolved from Hudson to Jenkins and later encountered architectural and scaling limitations as the company grew and adopted AWS EC2 and Kubernetes. The article discusses replacing that CI platform with GitLab CI.

### Source excerpt

Here at Indeed, our mission is to help people get jobs. Indeed is the #1 job site in the world with over 580M+ Job Seeker Profiles. For Indeed's Engineering Platform teams, we have a slightly different motto: "We help people to help people get jobs". As part of a data-driven engineering culture that has spent [...]

## Using a Portable Monitor for Home-Lab Debugging and Streaming

DevFeed: [Using a Portable Monitor for Home-Lab Debugging and Streaming](<https://devfeed.tech/articles/you-might-need-a-portable-monitor-26649.md>)

Original publisher: [Read original article](<https://blog.alexellis.io/you-might-need-a-portable-monitor/>)

Author: Alex Ellis

Published: 2024-06-12T13:47:26Z

Content type: opinion

Language: en

Sources: [Alex Ellis' Blog](<https://devfeed.tech/sources/alex-ellis-blog.md>)

Topics: [Homelab](<https://devfeed.tech/topics/homelab.md>), [monitor](<https://devfeed.tech/topics/monitor.md>), [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [ci](<https://devfeed.tech/topics/ci.md>)

Tags: [ci](<https://devfeed.tech/tags/ci.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [headless](<https://devfeed.tech/tags/headless.md>), [home-lab](<https://devfeed.tech/tags/home-lab.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [portable](<https://devfeed.tech/tags/portable.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

The article explains why the author prefers a portable monitor for debugging headless home-lab computers, setting up Raspberry Pis, monitoring Jenkins CI pipelines, and managing streaming or product-demo software.

### Source excerpt

I cover why as a one monitor kind of guy, I found a portable monitor essential - both for streaming and for debugging the home lab.

## Bazaarvoice Notification System for Transactional Email Delivery

DevFeed: [Bazaarvoice Notification System for Transactional Email Delivery](<https://devfeed.tech/articles/cloud-native-marvel-driving-6-million-daily-notifications-38724.md>)

Original publisher: [Read original article](<https://blog.developer.bazaarvoice.com/2024/04/24/cloud-native-marvel-driving-6-million-daily-notifications/>)

Author: Someswar Bhowmick

Published: 2024-04-24T10:24:56Z

Content type: article

Language: en

Sources: [Bazaarvoice](<https://devfeed.tech/sources/bazaarvoice.md>)

Topics: [notifications](<https://devfeed.tech/topics/notifications.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [AWS CloudFormation](<https://devfeed.tech/topics/aws-cloudformation.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloudformation](<https://devfeed.tech/tags/cloudformation.md>), [ec2](<https://devfeed.tech/tags/ec2.md>), [email](<https://devfeed.tech/tags/email.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [notifications](<https://devfeed.tech/tags/notifications.md>), [s3](<https://devfeed.tech/tags/s3.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [software-architecture](<https://devfeed.tech/tags/software-architecture.md>)

### AI overview

Bazaarvoice describes its notification system for sending transactional email on behalf of clients. The article outlines data ingestion and a decision engine for scheduled delivery, then discusses operational challenges in its earlier AWS-based architecture, including EC2 scaling, updates, logging, and prolonged file-processing batch jobs.

### Source excerpt

Bazaarvoice notification system stands as a testament to cutting-edge technology, designed to seamlessly dispatch transactional email messages (post-interaction email or PIE) on behalf of our clients. The heartbeat of our system lies in the constant influx of new content, driven by active content solicitations. Equipped with an array of tools, including email message styling, default [...]

## 8 tips for securing your CI/CD pipeline with Snyk

DevFeed: [8 tips for securing your CI/CD pipeline with Snyk](<https://devfeed.tech/articles/8-tips-for-securing-your-ci-cd-pipeline-with-snyk-8082.md>)

Original publisher: [Read original article](<https://snyk.io/blog/securing-ci-cd-pipeline-with-snyk/>)

Author: Eric Smalling

Published: 2023-07-20T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cheat-sheet](<https://devfeed.tech/tags/cheat-sheet.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [ci-cd-pipeline](<https://devfeed.tech/tags/ci-cd-pipeline.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>)

### AI overview

This cheat sheet presents eight tips for securing CI/CD pipelines with Snyk. It covers dependency and open-source component scanning, vulnerability detection, remediation guidance, and implementation examples for Jenkins and GitHub Actions.

### Source excerpt

In this post, we'll cover using Snyk in your CI/CD pipelines to catch security issues quickly and empower your developers to fix them before they ever get to production.

## Using Teleport to Create and Maintain Shared Demo Environments

DevFeed: [Using Teleport to Create and Maintain Shared Demo Environments](<https://devfeed.tech/articles/using-teleport-to-create-and-maintain-shared-demo-environments-29845.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/shared-demo-environment/>)

Author: info@goteleport.com (Steven Martin)

Published: 2022-02-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Demo](<https://devfeed.tech/topics/demo.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Kubernetes clusters](<https://devfeed.tech/topics/kubernetes-clusters.md>), [Security](<https://devfeed.tech/topics/security.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [demo](<https://devfeed.tech/tags/demo.md>), [devops](<https://devfeed.tech/tags/devops.md>), [ec2](<https://devfeed.tech/tags/ec2.md>), [iam](<https://devfeed.tech/tags/iam.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-clusters](<https://devfeed.tech/tags/kubernetes-clusters.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [solutions](<https://devfeed.tech/tags/solutions.md>)

### AI overview

The Teleport Solutions Engineering team describes building a shared demo environment on Teleport Enterprise. The approach provides each engineer access to demo resources while controlling provisioning costs, supporting distributed Teleport clusters, and using just-in-time requests and auditing for administrative changes.

### Source excerpt

This blog shows how the Teleport Solutions Engineering team uses Teleport to create and maintain shared demo environments.

## 10 Reasons You Need Teleport to Secure Your Apps on AWS

DevFeed: [10 Reasons You Need Teleport to Secure Your Apps on AWS](<https://devfeed.tech/articles/10-reasons-you-need-teleport-to-secure-your-apps-on-aws-29798.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/reinvent-2021/>)

Author: info@goteleport.com (Steven Martin)

Published: 2021-11-29T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [AWS Management Console](<https://devfeed.tech/topics/aws-management-console.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Amazon Elastic Kubernetes Service](<https://devfeed.tech/topics/amazon-elastic-kubernetes-service.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [HashiCorp Vault](<https://devfeed.tech/topics/hashicorp-vault.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [aws-management-console](<https://devfeed.tech/tags/aws-management-console.md>), [cli](<https://devfeed.tech/tags/cli.md>), [devops](<https://devfeed.tech/tags/devops.md>), [ec2](<https://devfeed.tech/tags/ec2.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [hashicorp-vault](<https://devfeed.tech/tags/hashicorp-vault.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-trust-networking](<https://devfeed.tech/tags/zero-trust-networking.md>)

### AI overview

A promotional article presents ten reasons to use Teleport for securing applications and infrastructure access on AWS. The supplied sections describe identity-aware, role-based access controls for the AWS Management Console and CLI, temporary elevated access, access controls for EC2, databases, EKS clusters, and DevOps tools, plus zero-trust networking.

### Source excerpt

Just in time for re:Invent 2021, here is the list of top 10 things you should know about AWS and Teleport.

## Setting Up CI / CD with Jenkins, Blue Ocean, Github for a Rust Program

DevFeed: [Setting Up CI / CD with Jenkins, Blue Ocean, Github for a Rust Program](<https://devfeed.tech/articles/setting-up-ci-cd-with-jenkins-blue-ocean-github-for-a-rust-program-28137.md>)

Original publisher: [Read original article](<http://fuzzyblog.io/blog/cicd/2020/06/05/setting-up-ci-cd-with-jenkins-blue-ocean-github-for-a-rust-program.html>)

Author: Fuzzygroup

Published: 2020-06-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Scott Johnson](<https://devfeed.tech/sources/scott-johnson.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [Git](<https://devfeed.tech/topics/git.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [branch protection rules](<https://devfeed.tech/topics/branch-protection-rules.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Ansible](<https://devfeed.tech/topics/ansible.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [blue-ocean](<https://devfeed.tech/tags/blue-ocean.md>), [branch-protection-rules](<https://devfeed.tech/tags/branch-protection-rules.md>), [cd](<https://devfeed.tech/tags/cd.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cicd](<https://devfeed.tech/tags/cicd.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [rust](<https://devfeed.tech/tags/rust.md>)

### AI overview

A tutorial for setting up CI/CD for a Rust codebase with Jenkins and the Blue Ocean plugin. It covers a Git workflow using feature, develop, and master branches, GitHub branch protection and pull requests, Jenkins deployment behind Nginx, and adding a Jenkinsfile.

### Source excerpt

CI / CD or "Continuous Integration / Continuous Deployment" is the process of: taking a source code base running tests against it compiling it (if applicable) deploying it CI / CD is an ongoing process that runs continuously and responds to pull requests on your source code repo. In this blog post we are going to: Take a git repo with a Rust code base Run it thru CI / CD using Jenkins with the Blue Ocean plugin Compile it Deploy it I'm not using Circle CI or another hosted CI / CD system as our overall deploy strategy is complex and Ansible based. Step 1: Correct Git Work Flow The git workflow we are using is: master branch develop branch feature branch All work happens in feature branches. Feature branches are then merged into develop and develop is merged into master. The goal here is that the master branch is always kept pristine. This means that you need to make some change to your github settings: Github Settings / Branches / Default branch - needs to be set to develop Github Settings / Branches / Branch protection rules - develop needs to be protected Here's what you need to do: Create a git repo. Push the code base to it. Create a develop branch in the code base. Change into that branch. Push that branch also. Go to settings for the repo. Click on branches. Set develop as the default branch. Click on branch protection rules. Add develop as a protected branch. This will turn on require pull requests before merging and you can set the number of people who have to approve pull requests before the merge. Add master as a protected branch. For this one you don't want pull requests on; you just want master protected. Step 2: Test the Git Work Flow Now you want to go into your repo and: Create a feature branch, call it "readme", and create / update the readme for the repo. Then you want to push the branch Then you want to follow the pull request url on the branch and submit it by clicking Create Pull Request Step 3: Get Jenkins Setup Traditionally with Blue Ocean Set

## Installing Jenkins on Ubuntu 18 on AWS

DevFeed: [Installing Jenkins on Ubuntu 18 on AWS](<https://devfeed.tech/articles/installing-jenkins-on-ubuntu-18-on-aws-28183.md>)

Original publisher: [Read original article](<http://fuzzyblog.io/blog/jenkins/2020/05/12/installing-jenkins-on-ubuntu-18.html>)

Author: Fuzzygroup

Published: 2020-05-12T00:00:00Z

Content type: tutorial

Language: en

Sources: [Scott Johnson](<https://devfeed.tech/sources/scott-johnson.md>)

Topics: [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [aws](<https://devfeed.tech/tags/aws.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [linux](<https://devfeed.tech/tags/linux.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>)

### AI overview

A tutorial explains how to install Jenkins, an open-source CI/CD program, on Ubuntu 18 running on an AWS instance. It provides installation commands and outlines configuration steps including opening port 8080, accessing the Jenkins interface, confirming the password, selecting plugins, and creating an account.

### Source excerpt

Jenkins is an Open Source CI / CD software program that you can easily install on an AWS instance. Here is how to install Jenkins: sudo apt install default-jre wget -q -O - http://pkg.jenkins-ci.org/debian/jenkins-ci.org.key | sudo apt-key add - sudo sh -c 'echo deb http://pkg.jenkins-ci.org/debian-stable binary/ > /etc/apt/sources.list.d/jenkins.list' sudo apt update sudo apt install jenkins sudo systemctl start jenkins Here are some additional useful commands: sudo systemctl status jenkins Here are the next steps you need to follow: Open a port in the AWS Security Group for your instance for port 8080 on 0.0.0.0/0 to allow http access to the Jenkins user interface. Go to the instance's IP address at port 8080 to run through the Jenkins installation. Confirm the Jenkins password per the instructions on screen. Select the plugins that you need for your Jenkins installation. Create your account and password. Sources Installing Jenkins Installing Java

## Rails Asset Pipeline Failures and Capistrano

DevFeed: [Rails Asset Pipeline Failures and Capistrano](<https://devfeed.tech/articles/rails-asset-pipeline-failures-and-capistrano-28270.md>)

Original publisher: [Read original article](<http://fuzzyblog.io/blog/rails/2020/04/14/rails-asset-pipeline-failures-and-capistrano.html>)

Author: Fuzzygroup

Published: 2020-04-14T00:00:00Z

Content type: opinion

Language: en

Sources: [Scott Johnson](<https://devfeed.tech/sources/scott-johnson.md>)

Topics: [Rails](<https://devfeed.tech/topics/rails.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Ansible](<https://devfeed.tech/topics/ansible.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [asset-pipeline](<https://devfeed.tech/tags/asset-pipeline.md>), [aws](<https://devfeed.tech/tags/aws.md>), [capistrano](<https://devfeed.tech/tags/capistrano.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [deploy](<https://devfeed.tech/tags/deploy.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [rails](<https://devfeed.tech/tags/rails.md>)

### AI overview

The author describes troubleshooting a Rails application deployment on AWS after HatchBox failed and a Capistrano deployment appeared successful but produced a CSS-related 500 error. The article discusses a planned deployment approach involving Jenkins, Ansible, Capistrano, and other tools, but the supplied text does not include the final diagnosis or resolution.

### Source excerpt

One of the single worst parts of being a one man show on an engineering effort is that when you hit a serious snag, well, you're fscked. I'm at the death march phase of a project, that wonderful stage, where you're so far into it that you can see the end but it seemingly never arrives - like the speed of light, it feels like you can never quite get there. Pro Tip: At this stage being asked by your manager, on a continuous basis, "anything that you can show me" is not helpful. It is actually an antipattern which simply slows the project by making the engineer feel even worse (yes I'm late and I can argue for scope creep, etc but I'll own it and I'm still late). Anyway I recently went through this with respect to getting a complex Rails code base deployed onto AWS. I started with my usual deploy tool of HatchBox but nothing worked and it was in the wee hours, and over a weekend, when I had no right to expect timely technical support so I figured "Ok I'll do a raw deploy with Capistrano" - and then the cluster fsck began in earnest. One of the general rules of technology is that everything is a two edged sword and where you get something, you give something. For example C gives outstanding performance and flexibility but it also can be a source of security issues, pointer bugs, buffer overflows, etc. Similarly Rails, even today, gives you: an unprecedentedly easy way to build web apps (provided you do it the Rails way) but deployment of modern Rails apps can be one of the most cursing laden experiences I've ever had The only easy way I've ever found to deploy Rails apps is HatchBox and HatchBox wasn't actually a good fit for this application due to particularly complex, multi language CI / CD requirements (4 different git repos spanning, today, two languages). The real deployment approach is going to be a combination of Jenkins + Ansible that drive Capistrano plus some other deployment tools. But I digress and have now devolved into a large number of words, more words

## How I gained commit access to Homebrew in 30 minutes

DevFeed: [How I gained commit access to Homebrew in 30 minutes](<https://devfeed.tech/articles/how-i-gained-commit-access-to-homebrew-in-30-minutes-31927.md>)

Original publisher: [Read original article](<http://engineering.remind.com/how-I-gained-commit-access-to-homebrew/>)

Author: Remind

Published: 2018-08-07T00:00:00Z

Content type: article

Language: en

Sources: [Remind](<https://devfeed.tech/sources/remind.md>)

Topics: [Homebrew](<https://devfeed.tech/topics/homebrew.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply chain attacks](<https://devfeed.tech/topics/supply-chain-attacks.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Environment Variables](<https://devfeed.tech/topics/environment-variables.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [GitHub API](<https://devfeed.tech/topics/github-api.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [curl](<https://devfeed.tech/tags/curl.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [github](<https://devfeed.tech/tags/github.md>), [homebrew](<https://devfeed.tech/tags/homebrew.md>), [incident](<https://devfeed.tech/tags/incident.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [npm](<https://devfeed.tech/tags/npm.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [rubygems](<https://devfeed.tech/tags/rubygems.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

### AI overview

A security researcher describes gaining commit access to Homebrew repositories through a GitHub API token exposed in a publicly accessible Jenkins environment. The access was tested and then reported to Homebrew maintainers, highlighting risks to package-manager infrastructure and software supply chains.

### Source excerpt

This issue was publicly disclosed on the Homebrew blog at https://brew.sh/2018/08/05/security-incident-disclosure/ Since the recent NPM, RubyGems, and Gentoo incidents, I've become increasingly interested, and concerned, with the potential for package managers to be used in supply chain attacks to distribute malicious software. Specifically with how the maintainers and infrastructure of these projects can be targeted as an attack vector. On Jun 31st, I went in with the intention of seeing if I could gain access to Homebrew's GitHub repositories. About 30 minutes later, I made my first commit to Homebrew/homebrew-core. Let's get leaky My initial strategy going in was based on credential theft; find if there were any credentials leaked by members of the Homebrew GitHub org. An OSSINT tool from Michael Henriksen called gitrob makes automating this search really easy. I ran it across the Homebrew organization, but ultimately didn't come up with anything interesting. Next, I took a look at previously disclosed issues on https://hackerone.com/Homebrew. From there, I found that Homebrew runs a Jenkins instance that's (intentionally) publicly exposed at https://jenkins.brew.sh. After some digging, I noticed something interesting; builds in the "Homebrew Bottles" project were making authenticated pushes to the BrewTestBot/homebrew-core repo: This got me thinking, "where are the credentials stored?". I noticed the "Environment Variables" link on the left, which led to an exposed GitHub API token: I tested it locally to see what scopes the token had: $ curl https://api.github.com/user/repos -u $GITHUB_API_TOKEN:x-oauth-basic | jq '.[] | {repo: .full_name, permissions: .permissions}' { "repo": "BrewTestBot/homebrew-core", "permissions": { "admin": true, "push": true, "pull": true } } { "repo": "Homebrew/brew", "permissions": { "admin": false, "push": true, "pull": true } } { "repo": "Homebrew/formulae.brew.sh", "permissions": { "admin": false, "push": true, "pull": true } } { "

## Personal Infrastructure

DevFeed: [Personal Infrastructure](<https://devfeed.tech/articles/personal-infrastructure-35183.md>)

Original publisher: [Read original article](<https://blog.jessfraz.com/post/personal-infrastructure/>)

Published: 2017-12-16T15:25:24Z

Content type: article

Language: en

Sources: [Jessie Frazelle](<https://devfeed.tech/sources/jessie-frazelle.md>)

Topics: [Homelab](<https://devfeed.tech/topics/homelab.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [docker registry](<https://devfeed.tech/topics/docker-registry.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [make](<https://devfeed.tech/topics/make.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [automation](<https://devfeed.tech/tags/automation.md>), [bash](<https://devfeed.tech/tags/bash.md>), [ci](<https://devfeed.tech/tags/ci.md>), [continuous-integration](<https://devfeed.tech/tags/continuous-integration.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-registry](<https://devfeed.tech/tags/docker-registry.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [home-lab](<https://devfeed.tech/tags/home-lab.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [make](<https://devfeed.tech/tags/make.md>), [personal](<https://devfeed.tech/tags/personal.md>), [private-registry](<https://devfeed.tech/tags/private-registry.md>)

### AI overview

A personal infrastructure overview describing self-hosted continuous integration with Jenkins, automated Jenkins DSL generation, a Postfix server, and a private Docker registry with image signing, authentication, and vulnerability scanning.

### Source excerpt

This post is kind of like "part two" on my series on all the weird things I do for my personal infrastructure. If you missed "part one", you should check out Home Lab is the Dopest Lab. I run a lot of little things to make my life easier, like a CI, some bots, and a bunch of services just for the lolz. This post will go over all of those. These run scattered across my NUCs and the cloud. Let's start with the most useful. Continuous Integration I host my own continuous integration server. Yes, you guessed it... it's Jenkins. I use the Jenkins DSL plugin to keep everything in sync. You can find all my DSLs in my repo github.com/jessfraz/jenkins-dsl. This has all the configurations for views, keeps forks up to date, mirrors all my repositories to private git (more on this in git), builds all Dockerfiles to push to Docker Hub and my private registry (more on this in private docker registry) and a bunch of maintenance scripts. The Makefile in this repo calls out to bash scripts which generate new DSLs for any new GitHub repos I create. Yep I even generate the automation... There's a bunch of other fun things in there as well that you can discover by poking around yourself. I host my own postfix server alongside Jenkins. You can find the postfix docker image at r.j3ss.co/postfix or the Dockerfile. It's super minimal and less gross than literally every other postfix image in existence. You can run it with: $ docker run --restart always -d \ --name postfix \ --net container:jenkins \ -e "ROOT_ALIAS=root@blah.com" \ -e "RELAY=[smtp-relay.gmail.com]:587" \ -e "TLS=1" \ -e "MY_DESTINATION=...., localhost" \ -e "MAILNAME=blah.com" \ r.j3ss.co/postfix Private Docker Registry I host my own private docker registry with my own notary server and authentication server. Why? Well because about 4 years ago when I started using docker, Docker Hub was super slow and I came to love having my own super fast one. I still push all the images to both Docker Hub and my registry and both are signed

## Automating trivago's Tech Blog Deployment Process

DevFeed: [Automating trivago's Tech Blog Deployment Process](<https://devfeed.tech/articles/automate-and-encourage-the-new-tech-blog-deployment-process-28084.md>)

Original publisher: [Read original article](<https://tech.trivago.com/post/techblog_deployment_process/>)

Author: Busra Koken Software; Backend Engineer; Learning Every Day; Writing Stories

Published: 2017-12-07T00:00:00Z

Content type: article

Language: en

Sources: [Trivago](<https://devfeed.tech/sources/trivago.md>)

Topics: [Deployment](<https://devfeed.tech/topics/deployment.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Hugo](<https://devfeed.tech/topics/hugo.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [GitHub Pages](<https://devfeed.tech/topics/github-pages.md>), [Markdown](<https://devfeed.tech/topics/markdown.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Code review](<https://devfeed.tech/topics/code-review.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [backend](<https://devfeed.tech/tags/backend.md>), [code-review](<https://devfeed.tech/tags/code-review.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [devops](<https://devfeed.tech/tags/devops.md>), [github-pages](<https://devfeed.tech/tags/github-pages.md>), [hugo](<https://devfeed.tech/tags/hugo.md>), [markdown](<https://devfeed.tech/tags/markdown.md>), [release-engineering](<https://devfeed.tech/tags/release-engineering.md>)

### AI overview

This article explains how trivago maintained its Hugo-generated tech blog, hosted it on GitHub Pages, and automated its deployment process. It describes the previous manual workflow, its bottlenecks, and improvements including storing a Jenkins pipeline in the blog repository.

### Source excerpt

We do think that our tech blog is full of interesting things powered by our engineers' great stories. Let us take you on a journey of how we maintain trivago tech blog from the technical perspective and how we recently automated its deployment process.

## How (and Why) We Moved to Spinnaker

DevFeed: [How (and Why) We Moved to Spinnaker](<https://devfeed.tech/articles/how-and-why-we-moved-to-spinnaker-20404.md>)

Original publisher: [Read original article](<https://target.github.io/how-and-why-we-moved-to-spinnaker>)

Author: Target Brands, Inc

Published: 2017-04-07T05:00:00Z

Content type: article

Language: en

Sources: [Target](<https://devfeed.tech/sources/target.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Microservices](<https://devfeed.tech/topics/microservices.md>), [Apache Cassandra](<https://devfeed.tech/topics/cassandra.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Cache](<https://devfeed.tech/topics/cache.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [cassandra](<https://devfeed.tech/tags/cassandra.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [git](<https://devfeed.tech/tags/git.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [redis](<https://devfeed.tech/tags/redis.md>), [spinnaker](<https://devfeed.tech/tags/spinnaker.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

Target describes moving portions of target.com from a homegrown cloud deployment platform to Spinnaker after evaluating CI/CD platforms. The team selected Spinnaker for its Jenkins integration, multi-cloud deployment support, and use of immutable images, then adapted its architecture with Terraform, cloud storage, and managed caching to support resilient, highly available operation.

### Source excerpt

Background Just after the middle of last year, Target expanded beyond its on-prem infrastructure and began deploying portions of target.com to the cloud. The deployment platform was homegrown (codename Houston), and was backed wholly by our public cloud provider. While in some aspects that platform was on par with other prominent continuous deployment offerings, the actual method of deploying code was cumbersome and not adherent to cloud best practices. These shortcomings led to a brief internal evaluation of various CI/CD platforms, which in turn led us to Spinnaker. We chose Spinnaker because it integrates with CI tools we already use at scale (Jenkins), supports deploying to all major public cloud providers, and compels software deployment best practices - all deployments are performed via immutable images, a snapshot of config + code. Supporting a Platform The primary goal of Target's cloud platform is to enable product teams to deploy and manage their applications across multiple cloud providers. We provide CI/CD, monitoring, and service discovery as services, and any application deployed via our platform gets those capabilities via a base image that is pre-configured for connectivity to each service's respective endpoint. Since these components are essentially products we provide to internal customers, we had to ensure the new CD platform was operationally supportable and highly-available. So, as soon as we decided on Spinnaker, a handful of engineers from the Cloud Platform group set about making this happen. Default Spinnaker scripts make it easy to standup a single self-contained server with the microservices and persistence layer all together, but that wasn't conducive to doing blue-green deployments - allowing updates of Spinnaker without downtime to our internal customers. We built jobs for building packages based off the master branch of each Spinnaker component's upstream git repository, and wrote Terraform plans to manage the deployment of each stack.

## Keep your stuff up to date

DevFeed: [Keep your stuff up to date](<https://devfeed.tech/articles/keep-your-stuff-up-to-date-27267.md>)

Original publisher: [Read original article](<https://blog.pchudzik.com/201703/how-to-keep-dependencies-up-to-date/>)

Published: 2017-03-30T00:00:00Z

Content type: tutorial

Language: en

Sources: [Paweł Chudzik](<https://devfeed.tech/sources/pawe-chudzik.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [ci](<https://devfeed.tech/topics/ci.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [Development](<https://devfeed.tech/topics/development.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [ci](<https://devfeed.tech/tags/ci.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [external](<https://devfeed.tech/tags/external.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [maven](<https://devfeed.tech/tags/maven.md>), [npm](<https://devfeed.tech/tags/npm.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A practical guide to keeping Maven, Gradle, and npm dependencies up to date using automated CI checks, configurable thresholds, commit hooks, and dependency-reporting tools.

### Source excerpt

Every codebase depends on multiple external libraries. It is a good idea to stay up to date with external dependencies. It is important to update all security related stuff and it might be helpful or fun to use latest features. I'm going to share my way of staying up to date with external dependencies in maven, gradle and npm. Read more

[Next page](<https://devfeed.tech/topics/jenkins.md?cursor=WyIyMDE3LTAzLTMwVDAwOjAwOjAwKzAwOjAwIiwgIjEyZjkzYzg4LTEzNWUtNDdmNi1hZWJkLWZiNWE4ZDFmNzI3ZiJd>)