Reflections on trusting VEX (or when humans can improve SBOMs)
What is Vulnerability Exploitability eXchange (VEX)? And can you trust it? We answer those questions and more in this blog.

3862 articles
3862 ARTICLES
What is Vulnerability Exploitability eXchange (VEX)? And can you trust it? We answer those questions and more in this blog.


This hands-on article discusses the environment variables available within GitHub Actions and when we should use them.

In this article, we’ll walk through setup, write, and test your first doctest in Python — giving you all the information you need to get started.

Wiz expands its platform to proactively eliminate attack paths to discovered critical data.

In this post, we’ll learn how to install and use JUnit 5 to write unit tests for some Java code. We’ll use the VSCode integrated development environment (IDE) for writing our tests and Java 11 with Maven to execute them.

This article demonstrates how to configure TLS/SSL certificates with the Ingress controller in Kubernetes. We’ll set up an NGINX Ingress controller, create a self-signed SSL/TLS certificate, create the necessary rules to link the SSL/TLS certificate to the controller, and hook it up to a Kubernetes sample app service.

In this article, you’ll learn what dependency injection is, when you should use it, and what popular JavaScript frameworks it’s implemented in.

Code signing is an important component of keeping your software secure. In this article, we discuss 7 reasons implementing Sigstore is worth your time.

In this article, we’ll explore best practices for Kubernetes Secret management. Check out our Kubernetes security article for more security risks and best practices.

In this post, we’ll recap Walz’s experience using Snyk to detect and remediate Log4Shell at Atlassian, as well as Silverman’s more in-depth talk about the impact of Log4Shell.

In this article, we’ll talk about some opportunities for community participationa few ways you can give back to your community while also developing your career.

Learn best practices for building modern access control for cloud applications, covering RBAC, security and compliace, IAM, access control layers, reducing attack surface area, and more.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy