« Blog Home

Archive for the ‘SDLC’ Category

How HashiCorp Vault Helps Prevent Security Breaches by Protecting Secrets?

hashicorp vault illustration

Executive summary: Most breaches involving “secrets” are not zero‑days – they’re the result of static passwords left in configs, long‑lived cloud keys scattered across systems, or environment variables that get copied into logs and crash dumps. HashiCorp Vault changes that story by replacing secrets‑at‑rest with just‑in‑time delivery and dynamic credentials that expire quickly and can […]

Read more »

The NPM Supply Chain Attack of September 8, 2025

Npm logo

On September 8, 2025, a massive npm supply chain attack compromised 18 foundational JavaScript packages, putting billions of applications at risk. This sophisticated incident began with a phishing campaign targeting a prominent package maintainer, Josh Junon, who was lured into providing his login and two-factor authentication (2FA) credentials on a fake npm website. Attackers then used this access to publish malicious updates containing […]

Read more »

Why Teams Couple SonarQube and GitLab ?

sonarqube gitlab integration

This acticle explanis why software teams couple SonarQube and GitLab. It provides some common use cases and how to integrate both tools

Read more »

    * Full Name

    * Work Email

    * Are you using any AI tools today? What tools?

      * Full Name

      * Work Email

      Are you using any SCA solution? Which one?

        * Full Name

        * Work Email

        * Are you using OpenProject?

        Do you have any questions you'd like to ask before the webinar?

          * Full Name

          * Work Email

          * Are you using any Secrets Management solution? Which one?