# sensitive data

Sensitive data is personal data belonging to special categories that receive enhanced protection, including information about health, sexual life or orientation, racial or ethnic origin, political or religious beliefs, biometric or genetic data, and trade union membership.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CrowdStrike Accelerates Real-Time Data Classification with On-Device AI

DevFeed: [CrowdStrike Accelerates Real-Time Data Classification with On-Device AI](<https://devfeed.tech/articles/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai-31503.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai/>)

Author: Lior Ribak

Published: 2026-09-17T01:38:53.400452Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [On-device AI](<https://devfeed.tech/topics/on-device-ai.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Language models](<https://devfeed.tech/topics/language-models.md>), [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [intel](<https://devfeed.tech/topics/intel.md>)

Tags: [data-security](<https://devfeed.tech/tags/data-security.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [intel](<https://devfeed.tech/tags/intel.md>), [language-models](<https://devfeed.tech/tags/language-models.md>), [npu](<https://devfeed.tech/tags/npu.md>), [on-device-ai](<https://devfeed.tech/tags/on-device-ai.md>)

### AI overview

CrowdStrike and Intel introduced a Falcon Data Security capability that uses language models running on-device on dedicated AI hardware to classify sensitive data. The article explains that local inference is intended to avoid cloud latency and keep sensitive customer data on the endpoint while meeting real-time protection requirements.

### Source excerpt

CrowdStrike worked closely with Intel to introduce a new capability in Falcon Data Security that classifies sensitive data using language models that run on-device using dedicated hardware for AI. Learn more!

## Native Splunk brings real-time insights to Cisco Nexus One

DevFeed: [Native Splunk brings real-time insights to Cisco Nexus One](<https://devfeed.tech/articles/native-splunk-brings-real-time-insights-to-cisco-nexus-one-31399.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/datacenter/native-splunk-brings-real-time-insights-to-cisco-nexus-one>)

Author: David Keith

Published: 2026-09-16T15:00:59Z

Content type: release

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Nexus Dashboard](<https://devfeed.tech/topics/nexus-dashboard.md>), [observability](<https://devfeed.tech/topics/observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [datacenter](<https://devfeed.tech/topics/datacenter.md>), [Security](<https://devfeed.tech/topics/security.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [audit](<https://devfeed.tech/topics/audit.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [audit](<https://devfeed.tech/tags/audit.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-nexus-dashboard](<https://devfeed.tech/tags/cisco-nexus-dashboard.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [data-center](<https://devfeed.tech/tags/data-center.md>), [data-center-networking](<https://devfeed.tech/tags/data-center-networking.md>), [network](<https://devfeed.tech/tags/network.md>), [nexus-one](<https://devfeed.tech/tags/nexus-one.md>), [observability](<https://devfeed.tech/tags/observability.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [splunk](<https://devfeed.tech/tags/splunk.md>), [troubleshooting](<https://devfeed.tech/tags/troubleshooting.md>)

### AI overview

Cisco describes native Splunk embedded in Cisco Nexus Dashboard as an on-premises analytics and observability capability for data center and AI workloads. It processes telemetry locally, correlates network, security, configuration, and audit data, and provides dashboards, searches, and alerts for troubleshooting, data sovereignty, compliance, and cost efficiency.

### Source excerpt

Discover how native Splunk embedded in Cisco Nexus Dashboard delivers real-time analytics, faster troubleshooting, and on-premises data sovereignty for modern data center and AI workloads.

## Atomic macOS (AMOS) Stealer Activity

DevFeed: [Atomic macOS (AMOS) Stealer Activity](<https://devfeed.tech/articles/atomic-macos-amos-stealer-activity-30906.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/>)

Author: Bradley Duncan

Published: 2026-09-16T10:00:06Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Aeternum](<https://devfeed.tech/topics/aeternum.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Zsh](<https://devfeed.tech/topics/zsh.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [ads](<https://devfeed.tech/tags/ads.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [curl](<https://devfeed.tech/tags/curl.md>), [general](<https://devfeed.tech/tags/general.md>), [insights](<https://devfeed.tech/tags/insights.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [unit-42](<https://devfeed.tech/tags/unit-42.md>), [zsh](<https://devfeed.tech/tags/zsh.md>)

### AI overview

This article analyzes a laboratory-generated Atomic macOS (AMOS) stealer infection observed on Aug. 5, 2026. It describes a deceptive macOS toolkit installation page that led users to paste a command into Terminal, retrieving a Zsh script containing an encoded compressed payload and a follow-up script designed to run a Mach-O binary. AMOS targets macOS and can exfiltrate system information, login credentials, and sensitive data from applications including browsers and cryptocurrency wallets.

### Source excerpt

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.

## Progressive Authentication for Production-Ready RAG Architectures

DevFeed: [Progressive Authentication for Production-Ready RAG Architectures](<https://devfeed.tech/articles/beyond-the-login-wall-32258.md>)

Original publisher: [Read original article](<https://medium.com/data-science-at-microsoft/beyond-the-login-wall-c7c5dd13a452?source=rss----a6e43238cdaf---4>)

Author: Aishwarya Murali Padikkal

Published: 2026-09-08T07:16:00Z

Content type: article

Language: en

Sources: [Data Science at Microsoft](<https://devfeed.tech/sources/data-science-at-microsoft.md>)

Topics: [Authentication](<https://devfeed.tech/topics/authentication.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [User Experience](<https://devfeed.tech/topics/user-experience.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [data-science](<https://devfeed.tech/tags/data-science.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [rag](<https://devfeed.tech/tags/rag.md>), [retrieval](<https://devfeed.tech/tags/retrieval.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [user-experience](<https://devfeed.tech/tags/user-experience.md>)

### AI overview

The article presents progressive authentication for RAG systems: answer public questions without sign-in, then authenticate within the conversation when a request requires access to sensitive personal data. It argues that static, upfront authentication does not fit conversations that shift between public and private contexts.

### Source excerpt

Designing a production-ready RAG architecture where authentication becomes part of the conversation, not a prerequisite for it. By Aishwarya Murali Padikkal & Priyank Solanki From understanding to retrieval, grounding, and response, authentication enters only when the conversation requires access to sensitive data- illustrating the core idea of progressive authentication. Illustration generated using ChatGPT and refined by the authors. Two questions, one help line Imagine two taxpayers opening the same AI-powered tax assistant. The first asks, "When is the filing deadline this year?" The second asks, "What was my refund last year?" Both questions are valid. Both deserve fast, helpful answers. Yet they represent fundamentally different types of requests. Figure 1. The same assistant, two different journeys. Requests are routed according to the type of information being accessed. Illustration generated by AI (ChatGPT) and refined by the authors. The answer to the first lives in a public handbook. Anyone should be able to access it instantly- no sign-in, no friction. The answer to the second is within an individual's private tax records. Before revealing a single detail, the assistant must be certain it is interacting with the right person. Making public information instantly accessible while ensuring private information is revealed only to the right person, all within the same conversation, is the challenge we set out to solve. It is also where conventional RAG systems quietly fall apart. Traditional RAG architectures assume a much simpler interaction model: a user asks a question, the system retrieves relevant documents, and the model generates an answer. Authentication, if it exists at all, is treated as a one-time checkpoint at the start of the interaction. Real conversations are far less predictable. Users naturally shift contexts, starting with a public question, moving to a personal one, and then asking follow-up questions that rely on both. The conversation evo

## From one switch to a control panel: meet \`dataCollection\`

DevFeed: [From one switch to a control panel: meet \`dataCollection\`](<https://devfeed.tech/articles/from-one-switch-to-a-control-panel-meet-datacollection-24094.md>)

Original publisher: [Read original article](<https://blog.sentry.io/datacollection-control-panel/>)

Author: Sigrid Huemer

Published: 2026-08-28T09:00:00Z

Content type: release

Language: en

Sources: [Sentry Blog](<https://devfeed.tech/sources/sentry-blog.md>)

Topics: [SDKs](<https://devfeed.tech/topics/sdks.md>), [data](<https://devfeed.tech/topics/data.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [api-keys](<https://devfeed.tech/tags/api-keys.md>), [data](<https://devfeed.tech/tags/data.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>), [sdks](<https://devfeed.tech/tags/sdks.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

Sentry is replacing the all-or-nothing `sendDefaultPii` setting with `dataCollection`, which provides granular control over automatically collected data such as user information, headers, request bodies, and GenAI data. The change is rolling out across Sentry SDKs, with JavaScript SDK v11 making it the default and collecting more data than v10 by default.

### Source excerpt

Sentry SDKs replace the `sendDefaultPii` boolean with `dataCollection`, granular options for user data, headers, bodies, GenAI data, and more.

## How to evaluate session replay software: a developer's guide

DevFeed: [How to evaluate session replay software: a developer's guide](<https://devfeed.tech/articles/how-to-evaluate-session-replay-software-a-developer-s-guide-24098.md>)

Original publisher: [Read original article](<https://blog.sentry.io/evaluate-session-replay-software/>)

Author: Lindsay Piper

Published: 2026-08-26T09:00:00Z

Content type: tutorial

Language: en

Sources: [Sentry Blog](<https://devfeed.tech/sources/sentry-blog.md>)

Topics: [session replay](<https://devfeed.tech/topics/session-replay.md>), [Playback](<https://devfeed.tech/topics/playback.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [debugging](<https://devfeed.tech/topics/debugging.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>)

Tags: [debug](<https://devfeed.tech/tags/debug.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [developer](<https://devfeed.tech/tags/developer.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [guide](<https://devfeed.tech/tags/guide.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [mutation](<https://devfeed.tech/tags/mutation.md>), [playback](<https://devfeed.tech/tags/playback.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [sdk](<https://devfeed.tech/tags/sdk.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [session-replay](<https://devfeed.tech/tags/session-replay.md>), [tool](<https://devfeed.tech/tags/tool.md>), [ux](<https://devfeed.tech/tags/ux.md>)

### AI overview

A developer guide to evaluating session replay software by comparing recording methods, privacy architecture, error-monitoring integration, overhead, AI debugging compatibility, and mobile support. It distinguishes UX analytics tools from developer debugging tools and explains the tradeoffs between DOM snapshot recording and pixel capture.

### Source excerpt

Compare session replay tools on recording methodology, privacy architecture, integration depth, overhead, AI-readability, and mobile support

## Migrating to Auth0 for Startups from Another Auth Solution

DevFeed: [Migrating to Auth0 for Startups from Another Auth Solution](<https://devfeed.tech/articles/migrating-to-auth0-for-startups-from-another-auth-solution-15647.md>)

Original publisher: [Read original article](<https://auth0.com/blog/migrating-to-auth0-for-startups/>)

Author: Shreya Gupta

Published: 2026-08-26T00:00:00Z

Content type: article

Language: en

Sources: [Auth0 Blog](<https://devfeed.tech/sources/auth0-blog.md>)

Topics: [Auth0](<https://devfeed.tech/topics/auth0.md>), [Security](<https://devfeed.tech/topics/security.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>)

Tags: [auth0](<https://devfeed.tech/tags/auth0.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [startups](<https://devfeed.tech/tags/startups.md>)

### AI overview

An interview with Evenpay's CTO describes the startup's migration from another authentication provider to Auth0 after Finnish customers required EU data residency controls and compliance configuration. The article discusses securing sensitive salary data and says the customer migration took a few weeks with support materials and AI assistance.

### Source excerpt

Interviewing Evenpay on building trust from day one.

## How to Use GitHub Actions to Deploy to Kubernetes Without Shared Secrets

DevFeed: [How to Use GitHub Actions to Deploy to Kubernetes Without Shared Secrets](<https://devfeed.tech/articles/how-to-use-github-actions-to-deploy-to-kubernetes-without-shared-secrets-29816.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/secretless-github-actions-for-kubernetes/>)

Author: info@goteleport.com (Noah Stride)

Published: 2026-08-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This tutorial explains how to use Teleport and GitHub Actions to deploy applications to Kubernetes without shared, long-lived credentials. It covers short-lived identities, Kubernetes RBAC, Teleport roles, and join tokens, and discusses extending the approach to database connections and internal APIs.

### Source excerpt

Learn how use GitHub Actions to deploy to Kubernetes using short-lived, verifiable identities.

## Lambda-powered functions land in OTTL

DevFeed: [Lambda-powered functions land in OTTL](<https://devfeed.tech/articles/lambda-powered-functions-land-in-ottl-32577.md>)

Original publisher: [Read original article](<https://opentelemetry.io/blog/2026/lambda-powered-function-land-in-ottl/>)

Author: OpenTelemetry Authors; Docs CC BY

Published: 2026-07-22T20:04:49Z

Content type: release

Language: en

Sources: [Blog on OpenTelemetry](<https://devfeed.tech/sources/blog-on-opentelemetry.md>)

Topics: [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [collection-operations](<https://devfeed.tech/tags/collection-operations.md>), [experimental](<https://devfeed.tech/tags/experimental.md>), [functions](<https://devfeed.tech/tags/functions.md>), [lambda](<https://devfeed.tech/tags/lambda.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [release](<https://devfeed.tech/tags/release.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [transformation](<https://devfeed.tech/tags/transformation.md>)

### AI overview

OpenTelemetry Collector Contrib v0.157.0 introduces lambda expressions to OTTL, enabling reusable inline logic in generic higher-order functions. The release adds eight experimental functions for collection transformations, including filtering, mapping, finding, reducing, and conditional operations.

### Source excerpt

As telemetry pipelines become more sophisticated, so do the transformations they need to perform: sanitizing sensitive data, normalizing inconsistent schemas, and enforcing attribute contracts. While OTTL provides a rich set of transformation functions, expressing collection operations has required dedicated functions with hardcoded behavior for each new use case. OpenTelemetry Collector Contrib v0.157.0 changes that by introducing lambda expressions to OTTL. Lambdas let users pass inline logic directly to generic higher-order functions, making complex collection transformations both reusable and concise. The release includes eight new functions that leverage this capability: Filter, MapEach, MapKeys, Any, All, Find, Reduce, and When.

## Kan een Amerikaans bedrijf met encryptie de Amerikaanse overheid buiten de deur houden?

DevFeed: [Kan een Amerikaans bedrijf met encryptie de Amerikaanse overheid buiten de deur houden?](<https://devfeed.tech/articles/kan-een-amerikaans-bedrijf-met-encryptie-de-amerikaanse-overheid-buiten-de-deur-houden-36460.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/kan-een-amerikaans-bedrijf-zo-versleutelen-dat-amerikanen-er-niet-bijkunnen/>)

Published: 2026-07-21T13:20:00Z

Content type: opinion

Language: nl

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Encryption](<https://devfeed.tech/topics/encryption.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [servers](<https://devfeed.tech/topics/servers.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [encryption](<https://devfeed.tech/tags/encryption.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [server](<https://devfeed.tech/tags/server.md>)

### AI overview

This Dutch commentary examines whether encryption can prevent the United States from accessing data held or processed by partly American companies. It argues that services such as Microsoft Double Key Encryption are difficult to use for ordinary data because servers need access to plaintext for searching and other operations, and that administrators ultimately retain significant control over server data.

### Source excerpt

Het is inmiddels duidelijk dat zelfs maar deels Amerikaanse bedrijven met allerhande middelen gedwongen kunnen worden om onze data te overhandigen aan de Amerikaanse overheid. Ook kan de dienstverlening gestaakt worden na een enkel briefje op Whitehouse.gov, wat zonder enige rechterlijke toetsing geplaatst kan worden. Tegen deze beide dingen is met papier niets te doen. Geen speciale afspraak zal je redden uit dit probleem (dit ook volgens de Landsadvocaat). Maar, er is dan soms nog de hoop om de data nog wel privé te houden met speciale encryptie.

## Securing Heroku CLI Credentials with System Keychain Storage

DevFeed: [Securing Heroku CLI Credentials with System Keychain Storage](<https://devfeed.tech/articles/securing-heroku-cli-credentials-with-system-keychain-storage-26493.md>)

Original publisher: [Read original article](<https://www.heroku.com/blog/securing-heroku-cli-credentials-with-system-keychain-storage/>)

Author: Katy Bowman

Published: 2026-07-01T21:11:54Z

Content type: release

Language: en

Sources: [Heroku](<https://devfeed.tech/sources/heroku.md>)

Topics: [Heroku](<https://devfeed.tech/topics/heroku.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Security](<https://devfeed.tech/topics/security.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [cli](<https://devfeed.tech/tags/cli.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [heroku](<https://devfeed.tech/tags/heroku.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [storage](<https://devfeed.tech/tags/storage.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Heroku CLI version 11.8.0 makes system keychain storage the default for authentication credentials. The credential manager uses native secure storage on macOS, Linux, and Windows while preserving netrc compatibility and file-based fallback options.

### Source excerpt

Beginning in version 11.8.0, we will be improving the security of the Heroku CLI by storing authentication credentials in your system keychain by default. The Heroku credential manager makes use of OS-native secure storage tools with interfaces designed for sensitive data while maintaining compatibility with existing developer workflows. We began the transition to our new [...] The post Securing Heroku CLI Credentials with System Keychain Storage appeared first on Heroku.

## How XY builds an AI agent orchestration platform for healthcare with Temporal

DevFeed: [How XY builds an AI agent orchestration platform for healthcare with Temporal](<https://devfeed.tech/articles/how-xy-builds-an-ai-agent-orchestration-platform-for-healthcare-with-temporal-36119.md>)

Original publisher: [Read original article](<https://temporal.io/blog/xy-build-ai-agent-orchestration-platform-healthcare-temporal>)

Author: The XY Engineering Team

Published: 2026-04-23T00:00:00Z

Content type: article

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [agent orchestration](<https://devfeed.tech/topics/agent-orchestration.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [human review](<https://devfeed.tech/topics/human-review.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Structured-data](<https://devfeed.tech/topics/structured-data.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agent-orchestration](<https://devfeed.tech/tags/agent-orchestration.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [automation](<https://devfeed.tech/tags/automation.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [human-review](<https://devfeed.tech/tags/human-review.md>), [long-running](<https://devfeed.tech/tags/long-running.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [temporal](<https://devfeed.tech/tags/temporal.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

XY describes using Temporal as a DSL-driven execution engine for an AI agent orchestration platform serving complex healthcare workflows. The approach uses a YAML-based workflow language and a generic Temporal workflow class to coordinate multiple systems, reliability features, human review, and sensitive healthcare data from prototype to production.

### Source excerpt

One generic Temporal workflow class can provide infinite healthcare automation. See how XY built a DSL-driven AI agent orchestration platform that scales from prototype to production.

## Managing Sensitive Data in jOOQ 3.21+ Logs

DevFeed: [Managing Sensitive Data in jOOQ 3.21+ Logs](<https://devfeed.tech/articles/managing-sensitive-data-in-jooq-3-21-logs-28956.md>)

Original publisher: [Read original article](<https://blog.jooq.org/managing-sensitive-data-in-jooq-3-21-logs/>)

Author: lukaseder

Published: 2026-03-27T12:45:19Z

Content type: tutorial

Language: en

Sources: [jOOQ](<https://devfeed.tech/sources/jooq.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Security](<https://devfeed.tech/topics/security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [configuration](<https://devfeed.tech/tags/configuration.md>), [csv](<https://devfeed.tech/tags/csv.md>), [debug-logging](<https://devfeed.tech/tags/debug-logging.md>), [jooq](<https://devfeed.tech/tags/jooq.md>), [jooq-in-use](<https://devfeed.tech/tags/jooq-in-use.md>), [json](<https://devfeed.tech/tags/json.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [maven](<https://devfeed.tech/tags/maven.md>), [redacted-columns](<https://devfeed.tech/tags/redacted-columns.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [xml](<https://devfeed.tech/tags/xml.md>)

### AI overview

This article explains how jOOQ debug logging can expose query bind values and fetched records in application logs, creating security concerns in production. It describes a code-generation configuration available in commercial jOOQ distributions to mask exported data, including text, HTML, and optionally CSV, JSON, or XML output.

### Source excerpt

One of jOOQ's most popular feature is the out-of-the-box debug logging experience. jOOQ developers find this feature very useful when developing their applications. Assuming you run a jOOQ query and configure your logger to print DEBUG log output: When this query is executed, your log output might contain something like this: Executing query : select ... Continue reading Managing Sensitive Data in jOOQ 3.21+ Logs ->

## Sandbox Your AI Dev Tools: A Practical Guide for VMs and Lima

DevFeed: [Sandbox Your AI Dev Tools: A Practical Guide for VMs and Lima](<https://devfeed.tech/articles/sandbox-your-ai-dev-tools-a-practical-guide-for-vms-and-lima-31868.md>)

Original publisher: [Read original article](<https://www.metachris.dev/2025/11/sandbox-your-ai-dev-tools-a-practical-guide-for-vms-and-lima/>)

Author: Chris Hager

Published: 2025-11-25T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chris Hager](<https://devfeed.tech/sources/chris-hager.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [developer tooling](<https://devfeed.tech/topics/developer-tooling.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [npm](<https://devfeed.tech/topics/npm.md>), [pip](<https://devfeed.tech/topics/pip.md>)

Tags: [ai-assisted-coding](<https://devfeed.tech/tags/ai-assisted-coding.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [dev-tools](<https://devfeed.tech/tags/dev-tools.md>), [npm](<https://devfeed.tech/tags/npm.md>), [python](<https://devfeed.tech/tags/python.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

A practical guide to sandboxing AI coding assistants and other development tools in isolated virtual machines using Lima. It explains how isolation helps protect SSH keys, API tokens, credentials, environment variables, and other sensitive data from arbitrary code, scripts, and package installation behavior.

### Source excerpt

AI coding assistants, npm, pip, and other development tools can run arbitrary code and scripts on your machine, potentially stealing SSH keys, API tokens, wallet keys, sensitive credentials and other private data without you noticing. This guide shows you how to sandbox these tools in isolated VMs using Lima, so you can experiment and develop freely without putting your sensitive data at risk. Jump straight to the guide, or read on for a bit of personal context.

## How to protect sensitive data in a Temporal Application

DevFeed: [How to protect sensitive data in a Temporal Application](<https://devfeed.tech/articles/how-to-protect-sensitive-data-in-a-temporal-application-35869.md>)

Original publisher: [Read original article](<https://temporal.io/blog/how-to-protect-sensitive-data-in-a-temporal-application>)

Author: Joshua Smith

Published: 2025-10-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Security](<https://devfeed.tech/topics/security.md>), [payload](<https://devfeed.tech/topics/payload.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [observability](<https://devfeed.tech/topics/observability.md>), [ui](<https://devfeed.tech/topics/ui.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [cli](<https://devfeed.tech/tags/cli.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [observability](<https://devfeed.tech/tags/observability.md>), [payload](<https://devfeed.tech/tags/payload.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [temporal-concepts](<https://devfeed.tech/tags/temporal-concepts.md>), [tls](<https://devfeed.tech/tags/tls.md>), [ui](<https://devfeed.tech/tags/ui.md>)

### AI overview

This tutorial explains how to protect sensitive data in Temporal applications. It describes Temporal's layered data-security approach, including TLS, Payload Codecs, and a Codec Server, while preserving observability through the Web UI and CLI.

### Source excerpt

Learn how to protect sensitive data in Temporal apps using TLS, Payload Codecs, and a Codec Server without losing Web UI or CLI observability.

## Data Safety Levels Framework: The foundation of how we look at data in Block

DevFeed: [Data Safety Levels Framework: The foundation of how we look at data in Block](<https://devfeed.tech/articles/data-safety-levels-framework-the-foundation-of-how-we-look-at-data-in-block-29009.md>)

Original publisher: [Read original article](<https://code.cash.app/dsl-framework>)

Author: John Rogers

Published: 2025-01-16T00:00:00Z

Content type: article

Language: en

Sources: [Cash App Code Blog](<https://devfeed.tech/sources/cash-app-code-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [pii](<https://devfeed.tech/topics/pii.md>), [context](<https://devfeed.tech/topics/context.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [context](<https://devfeed.tech/tags/context.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [data](<https://devfeed.tech/tags/data.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [pii](<https://devfeed.tech/tags/pii.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security-governance](<https://devfeed.tech/tags/security-governance.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

Block introduces its Data Safety Levels (DSL) Framework, a system for evaluating data sensitivity in context and building scalable, automated data-management policies across Cash App, Square, and TIDAL.

### Source excerpt

Block uses the Data Safety Levels (DSL) Framework to evaluate data sensitivity.

## Detect Hardcoded Secrets Early to Reduce Data Breach Risk

DevFeed: [Detect Hardcoded Secrets Early to Reduce Data Breach Risk](<https://devfeed.tech/articles/want-to-avoid-a-data-breach-employ-secrets-detection-8230.md>)

Original publisher: [Read original article](<https://snyk.io/blog/want-to-avoid-data-breach-employ-secrets-detection/>)

Author: Liran Tal

Published: 2024-09-16T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Security](<https://devfeed.tech/topics/security.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [ide](<https://devfeed.tech/topics/ide.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [breach](<https://devfeed.tech/tags/breach.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

This developer article explains that hardcoded secrets, including API keys, database credentials, passwords, encryption keys, and tokens, can expose applications to unauthorized access and data breaches. It describes using secrets detection during development to identify exposed credentials early, including through the Snyk IntelliJ IDE extension.

### Source excerpt

Concerned about data breaches? Exposed secrets like API keys and passwords are a major culprit. Secure your software development lifecycle, identify and remove hardcoded secrets in code, and leverage Snyk's secrets detection tools to identify secrets early in development in order to prevent breaches and safeguard your applications.

## Mintlify's security improvements after the March 2024 incident

DevFeed: [Mintlify's security improvements after the March 2024 incident](<https://devfeed.tech/articles/how-mintlify-is-improving-security-31085.md>)

Original publisher: [Read original article](<https://www.mintlify.com/blog/security-update>)

Author: Han Wang

Published: 2024-03-22T00:00:00Z

Content type: article

Language: en

Sources: [Mintlify Blog](<https://devfeed.tech/sources/mintlify-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [incident](<https://devfeed.tech/topics/incident.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [incident](<https://devfeed.tech/tags/incident.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>)

### AI overview

Mintlify describes security improvements made in response to a March 2024 security incident, including AES256-GCM encryption at rest, changes to GitHub OAuth token handling, removal of internal admin tokens, and session-based access controls.

### Source excerpt

We at Mintlify are committed to the privacy and security of our customers. Your trust in our ability to safeguard your data is the cornerstone upon which our services are built.

## Seamlessly integrate with partners to enhance the travel experience

DevFeed: [Seamlessly integrate with partners to enhance the travel experience](<https://devfeed.tech/articles/seamlessly-integrate-with-partners-to-enhance-the-travel-experience-23509.md>)

Original publisher: [Read original article](<https://www.apollographql.com/blog/seamlessly-integrate-with-partners-to-enhance-the-travel-experience>)

Author: Tushar Bhushan

Published: 2023-07-14T12:48:06Z

Content type: tutorial

Language: en

Sources: [Apollo Blog](<https://devfeed.tech/sources/apollo-blog.md>)

Topics: [GraphOS](<https://devfeed.tech/topics/graphos.md>), [GraphQL](<https://devfeed.tech/topics/graphql.md>), [API](<https://devfeed.tech/topics/api.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [graphos](<https://devfeed.tech/tags/graphos.md>), [graphql](<https://devfeed.tech/tags/graphql.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This tutorial explains how travel companies can use Apollo GraphOS to integrate third-party services. It discusses GraphQL and REST integration challenges, schema contracts, demand control, field-level metrics, and selectively excluding sensitive data from third-party APIs.

### Source excerpt

This post is a part of our "How to build connected travel apps with Apollo GraphOS" series. Also in this series: - Delivering personalized travel experiences with GraphQL - Ship products faster with SDUI - Mitigate scraping and bot attacks with GraphOS Travel companies often strive to enhance their services by collaborating with third-party providers through API integrations.

## SiriSpy - iOS bug allowed apps to eavesdrop on your conversations with Siri

DevFeed: [SiriSpy - iOS bug allowed apps to eavesdrop on your conversations with Siri](<https://devfeed.tech/articles/sirispy-ios-bug-allowed-apps-to-eavesdrop-on-your-conversations-with-siri-39526.md>)

Original publisher: [Read original article](<https://rambo.codes/posts/2022-10-25-sirispy-ios-bug-allowed-apps-to-eavesdrop>)

Published: 2022-10-26T16:00:00Z

Content type: article

Language: en

Sources: [Rambo Codes](<https://devfeed.tech/sources/rambo-codes.md>)

Topics: [iOS](<https://devfeed.tech/topics/ios.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Security](<https://devfeed.tech/topics/security.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>)

Tags: [bluetooth](<https://devfeed.tech/tags/bluetooth.md>), [bug](<https://devfeed.tech/tags/bug.md>), [ios](<https://devfeed.tech/tags/ios.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [security](<https://devfeed.tech/tags/security.md>), [security-and-privacy](<https://devfeed.tech/tags/security-and-privacy.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

The article describes an iOS bug that allowed apps with Bluetooth access to record conversations with Siri and audio from keyboard dictation when users wore AirPods or Beats headsets. Recording could occur without microphone permission and without leaving a listening trace.

### Source excerpt

Gui Rambo writes about his coding and reverse engineering adventures.

## An Introduction to Hardware Security Modules (HSMs)

DevFeed: [An Introduction to Hardware Security Modules (HSMs)](<https://devfeed.tech/articles/an-introduction-to-hardware-security-modules-hsms-29961.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/what-is-hsm/>)

Author: info@goteleport.com (Russell Jones)

Published: 2021-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [private key](<https://devfeed.tech/topics/private-key.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [certificates](<https://devfeed.tech/topics/certificates.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This article explains how hardware security modules protect sensitive data such as private keys by exposing cryptographic operations instead of allowing the data to be read. It describes Teleport 7.2 support for HSMs and how they can reduce the risk of private-key theft in remote-access clusters, while noting that HSMs do not mitigate every attack vector.

### Source excerpt

In this blog post we explain how hardware security modules (HSM) help protect sensitive data and how Teleport 7.2 uses HSM to make remote access more secure.

## Apache Airflow 1.10.12

DevFeed: [Apache Airflow 1.10.12](<https://devfeed.tech/articles/apache-airflow-1-10-12-32529.md>)

Original publisher: [Read original article](<https://airflow.apache.org/blog/airflow-1.10.12/>)

Author: Apache Airflow

Published: 2020-08-25T00:00:00Z

Content type: release

Language: en

Sources: [Apache Airflow Blog](<https://devfeed.tech/sources/apache-airflow-blog.md>)

Topics: [airflow](<https://devfeed.tech/topics/airflow.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [HashiCorp Vault](<https://devfeed.tech/topics/hashicorp-vault.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [airflow](<https://devfeed.tech/tags/airflow.md>), [apache](<https://devfeed.tech/tags/apache.md>), [apache-airflow](<https://devfeed.tech/tags/apache-airflow.md>), [bug-fixes](<https://devfeed.tech/tags/bug-fixes.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [class](<https://devfeed.tech/tags/class.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [new-features](<https://devfeed.tech/tags/new-features.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [release](<https://devfeed.tech/tags/release.md>), [s3](<https://devfeed.tech/tags/s3.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vault](<https://devfeed.tech/tags/vault.md>)

### AI overview

Apache Airflow 1.10.12 is a release containing 113 commits since 1.10.11, including new features, improvements, bug fixes, and documentation changes. It adds custom XCom classes, secret-backed configuration for sensitive values, and AirflowClusterPolicyViolation support in local settings. The article recommends upgrading directly to 1.10.12 because Airflow 1.10.11 introduced breaking changes related to KubernetesExecutor and KubernetesPodOperator.

### Source excerpt

Airflow 1.10.12 contains 113 commits since 1.10.11 and includes 5 new features, 23 improvements, 23 bug fixes, and several doc changes. Details: PyPI: https://pypi.org/project/apache-airflow/1.10.12/ Docs: https://airflow.apache.org/docs/1.10.12/ Changelog: http://airflow.apache.org/docs/1.10.12/changelog.html Airflow 1.10.11 has breaking changes with respect to KubernetesExecutor & KubernetesPodOperator so I recommend users to directly upgrade to Airflow 1.10.12 instead. Some of the noteworthy new features (user-facing) are: Allow defining custom XCom class Get Airflow configs with sensitive data from Secret Backends Add AirflowClusterPolicyViolation support to Airflow local settings Allow defining Custom XCom class Until Airflow 1.10.11, the XCom data was only stored in Airflow Metadatabase. From Airflow 1.10.12, users would be able to define custom XCom classes. This will allow users to transfer larger data between tasks. An example here would be to store XCom in S3 or GCS Bucket if the size of data that needs to be stored is larger than XCom.MAX_XCOM_SIZE (48 KB). PR: https://github.com/apache/airflow/pull/8560 Get Airflow configs with sensitive data from Secret Backends Users would be able to get the following Airflow configs from Secrets Backend like Hashicorp Vault: sql_alchemy_conn in [core] section fernet_key in [core] section broker_url in [celery] section flower_basic_auth in [celery] section result_backend in [celery] section password in [atlas] section smtp_password in [smtp] section bind_password in [ldap] section git_password in [kubernetes] section Further improving Airflow's Secret Management story, from Airflow 1.10.12, users don't need to hardcode the sensitive config value in airflow.cfg nor then need to use an Environment variable to set this config. For example, the metadata database connection string can either be set in airflow.cfg like this: [core] sql_alchemy_conn_secret = sql_alchemy_conn This will retrieve config option from the set Secre

## Threat Modeling with Questionnaires

DevFeed: [Threat Modeling with Questionnaires](<https://devfeed.tech/articles/threat-modeling-with-questionnaires-37055.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-with-questionnaires/>)

Author: Adam

Published: 2020-03-19T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [self-service](<https://devfeed.tech/topics/self-service.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [security](<https://devfeed.tech/tags/security.md>), [self-service](<https://devfeed.tech/tags/self-service.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

The article examines lightweight threat modeling through self-service security questionnaires. It argues that developers or scrum masters can identify what they are building, what could go wrong, and whether security engineers should focus on the feature based on its risk.

### Source excerpt

This post comes from a conversation I had on Linkedin with Clint Gibler.

## Common pitfalls when using Keychain Sharing on iOS

DevFeed: [Common pitfalls when using Keychain Sharing on iOS](<https://devfeed.tech/articles/common-pitfalls-when-using-keychain-sharing-on-ios-39510.md>)

Original publisher: [Read original article](<https://rambo.codes/posts/2020-01-16-common-pitfalls-when-using-keychain-sharing-on-ios>)

Published: 2020-01-16T14:00:00Z

Content type: tutorial

Language: en

Sources: [Rambo Codes](<https://devfeed.tech/sources/rambo-codes.md>)

Topics: [iOS](<https://devfeed.tech/topics/ios.md>), [Xcode](<https://devfeed.tech/topics/xcode.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [coding](<https://devfeed.tech/topics/coding.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [coding](<https://devfeed.tech/tags/coding.md>), [ios](<https://devfeed.tech/tags/ios.md>), [pitfalls](<https://devfeed.tech/tags/pitfalls.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [xcode](<https://devfeed.tech/tags/xcode.md>)

### AI overview

An article about common Keychain Sharing problems on iOS, including incorrect group names and limitations of using Keychain Sharing in the iOS Simulator. It also discusses checking entitlements in the final binary with jtool.

### Source excerpt

Gui Rambo writes about his coding and reverse engineering adventures.

[Next page](<https://devfeed.tech/topics/sensitive-data.md?cursor=WyIyMDIwLTAxLTE2VDE0OjAwOjAwKzAwOjAwIiwgImQxM2ViNmYwLTRmZmItNDc4Yy05N2Y4LTdkNmZlODg0YjhlMiJd>)