ci-cd

Tag

Cards List
#ci-cd

Megalodon: Mass GitHub Repo Backdooring via CI Workflows

Lobsters Hottest · 2026-05-22 Cached

A security research reveals a technique named Megalodon for mass backdooring of GitHub repositories by exploiting CI workflows.

0 favorites 0 likes
#ci-cd

Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

Hacker News Top · 2026-05-19 Cached

The npm account 'atool' was compromised, leading to the publication of 637 malicious versions across 317 packages. The payload harvests credentials, establishes persistence via AI coding tools and system services, and exfiltrates data through GitHub.

0 favorites 0 likes
#ci-cd

Your AI agent isn't broken. Your harness is. Here's the system that took mine from "liability" to shipping production code.

Reddit r/AI_Agents · 2026-05-11

The article argues that AI coding agent failures stem from poor system design rather than model limitations, outlining a three-layer 'harness' of knowledge, guardrails, and feedback loops to reliably ship production code.

0 favorites 0 likes
#ci-cd

@so_ainsight: This is seriously insane. The startup "Warp" (an AI-powered terminal app) that has raised a cumulative 11 billion yen h…

X AI KOLs Timeline · 2026-05-08

Warp, an AI-powered terminal startup, has publicly released its production-ready 'oz-skills', featuring 15 automated Agent Skills for tasks like CI failure auto-fixing, GitHub issue triage, and SEO audits.

0 favorites 0 likes
#ci-cd

Improving token efficiency in GitHub Agentic Workflows (12 minute read)

TLDR AI · 2026-05-08 Cached

GitHub improved token efficiency in their agentic workflows by logging token usage via an API proxy and building daily optimization workflows, reducing overhead from unused MCP tool registrations.

0 favorites 0 likes
#ci-cd

GitHub Actions for a Gleam monorepo

Lobsters Hottest · 2026-04-22 Cached

A developer shares their GitHub Actions setup for testing a Gleam monorepo with separate BEAM and JavaScript runtimes, using matrix strategies and strict formatting checks.

0 favorites 0 likes
#ci-cd

Anthropic Claude Code Leak Reveals Critical Command Injection Vulnerabilities

Lobsters Hottest · 2026-04-19 Cached

Critical command injection vulnerabilities (CVE-2026-35022, CVSS 9.8) discovered in Anthropic's Claude Code CLI and SDK allow attackers to execute arbitrary commands and steal credentials through environment variables, file paths, and authentication helpers. The flaws enable poisoned pipeline execution attacks in CI/CD environments, requiring immediate patching and configuration changes.

0 favorites 0 likes
#ci-cd

Rakuten fixes issues twice as fast with Codex

OpenAI Blog · 2026-03-11 Cached

Rakuten has integrated OpenAI's Codex coding agent into its engineering workflows, achieving approximately 50% reduction in mean time to recovery (MTTR) and automating CI/CD code review and vulnerability checks. The company reports compressing quarter-long development efforts into weeks through agentic, autonomous execution.

0 favorites 0 likes
#ci-cd

jenkinsci/jenkins

GitHub Trending (daily) · 2026-07-27 Cached

Jenkins is a leading open-source automation server built with Java, used for CI/CD, testing, deployment, and automating development workflows.

0 favorites 0 likes
#ci-cd

oblien/openship

GitHub Trending (daily) · 2026-07-20 Cached

Openship is an open-source, self-hostable deployment platform with built-in CI/CD, supporting any stack, databases, domains, SSL, and more, accessible via desktop app, web dashboard, or CLI.

0 favorites 0 likes
#ci-cd

actions/checkout

GitHub Trending (daily) · 2026-07-02

A GitHub Action for checking out a repository, enabling workflows to access code.

0 favorites 0 likes
← Previous
← Back to home

Submit Feedback