Cloud-based code hosting platform GitHub has announced that it will now start sending Dependabot alerts for vulnerable GitHub Actions to help developers fix security issues in CI/CD workflows. . "When a security vulnerability is reported in an action, our team of security researchers will create an advisory to document the vulnerability, which will trigger an alert to impacted repositories," GitHub's Brittany O'Shea and Kate Catlin said. GitHub Actions is a continuous integration and continuous delivery (CI/CD) solution that enables users to automate the software build, test, and deployment pipeline. The link for this article located at The Hacker News is no longer available. . GitHub has introduced notifications for developers regarding insecure GitHub Actions, enhancing security measures in CI/CD pipelines and mitigating potential threats.. GitHub Actions, CI/CD Tools, Developer Security, Automated Alerts. . LinuxSecurity.com Team
Get ready, developers- Microsoft's WSL 2 is getting graphics support! . The Windows Subsystem for Linux (WSL) is an important part of Windows 10. Using a version of Microsoft's Hyper-V virtualisation technology, it lets you run Linux as if it was part of Windows, sharing resources and files. It was originally designed for developers building web and cloud applications, but it's turned into something a lot more powerful that brings two very different operating systems together. Microsoft originally designed WSL for use with the bash command line, but it has evolved into something much more akin to a traditional Linux distribution. Instead of using Microsoft's original set of shims and translations to convert Linux syscalls to Windows calls, it now uses a Microsoft-compiled and supported Linux kernel, initially using the 4.19 kernel release but now rolling out a more up-to-date 5.4. That change has improved support for Linux applications, with most running without need for any changes. There are some issues: as it's a subsystem it isn't launched at startup, so there's no support for timed jobs or for services using systemd. . Unveiling upgraded GUI capabilities in Windows Subsystem for Linux, improving user experience for developers with enhanced graphical interface features.. Windows Subsystem for Linux, Developer Tools, GUI Features. . LinuxSecurity.com Team
Node.js is wildly popular - but the open-source JavaScript runtime is not easy to learn. Now is the perfect time to pick it up - the Linux Foundation is offering a free online Node.js class. . Node.js isn't a language, framework, or library. It's an open-source JavaScript runtime built on Chrome's V8 JavaScript engine, which lives in the programming intersection of all three. While often used for backend operations, it can be used with such frontend JavaScript frameworks as Angular , React , and Vue . It's also wildly popular. Amazon, Netflix, Reddit, and PayPal, to name a few major corporate users, all work with it. StackOverflow developers love it more than any other developer toolkit . But one thing it's not is easy to learn. . Explore Node.js, the widely-used open-source JavaScript environment, through a complimentary online course offered by the Linux Foundation.. Node.js, Open Source JavaScript, Learn Programming, Linux Foundation Course. . Brittany Day
Learn about ktest, a tool for making Linux kernel programmers' lives easier by automating certain aspects of Linux kernel testing. . In October 2010, Steven Rostedt announced on the LKML that he was working on a script called ktest.pl to automate certain aspects of Linux kernel testing. The script is aimed at individual kernel programmers testing their patch series, and provides an alternative to the Autotest framework, which is powerful but quite involved for one person to set up. This post will cover ktest's capabilities and requirements, and give concrete examples of how to use it in one specific environment, a single physical machine with a qemu VM run under virsh. The link for this article located at Oracle Linux Blog is no longer available. . Explore the ways in which ktest simplifies the process of testing the Linux kernel for developers, boosting effectiveness and output.. Automated Testing,Linux Kernel,Kernel Programmers,ktest,Testing Tool. . LinuxSecurity.com Team
Ready to start development on an open-source OS? Here's a rundown of the best Linux distros for programming. . There are over 600 Linux distros to choose from, so even experienced users may seldom struggle to find their current project's ideal flavor. Linux distributions can vary hugely from one another, even though they are based on the same source. And if you’re looking to learn more about Linux distros, we’ve compiled a list of the 10 best Linux distros for developers. . Discover a vast selection of 600+ Linux distributions, perfect for coding and software development tasks. Check out the leading 10 options today!. Best Linux Distros, Top Developer Platforms, Programming Linux OS. . LinuxSecurity.com Team
Red Hat, Inc. today announced the general availability of Red Hat Enterprise Linux 8.1, the latest version of the world's leading enterprise Linux platform. The first minor release of the Red Hat Enterprise Linux 8 platform, Red Hat Enterprise Linux 8.1 enhances the manageability, security and performance of the operating system underpinning the open hybrid cloud while also adding new capabilities to drive developer innovation. Learn more about Red Hat Enterprise Linux 8.1: . Red Hat Enterprise Linux is the foundation of Red Hat's open hybrid cloud portfolio, providing the underlying engine that allows complex workloads to be developed and deployed across physical, virtual, private and public cloud environments with greater confidence and control. As the backbone of the hybrid cloud, the world's leading enterprise Linux platform provides a consistent user experience across on premise deployments and all major public cloud infrastructures. At the same time, it supports key production workloads like Microsoft SQL Server and SAP HANA while also enabling new workloads like artificial intelligence (AI) and machine-learning (ML). The link for this article located at Light Reading is no longer available. . SUSE Linux Enterprise 15 SP3 enhances reliability, scalability, and efficiency for multicloud environments, driving advancement in application development.. Red Hat, Enterprise Linux, Cloud Performance, Developer Tools. . LinuxSecurity.com Team
Find and eliminate vulnerabilities in the data you store in AWS and GitHub. Learn more in a great Opensource.com article: . If your day-to-day as a developer, system administrator, full-stack engineer, or site reliability engineer involves Git pushes, commits, and pulls to and from GitHub and deployments to Amazon Web Services (AWS), security is a persistent concern. Fortunately, open source tools are available to help your team avoid common mistakes that could cost your organization thousands of dollars. This article describes four open source tools that can help improve your security practices when you're developing on GitHub and AWS. Also, in the spirit of open source, I've joined forces with three security expertsâ" Travis McPeak , senior cloud security engineer at Netflix; Rich Monk , senior principal information security analyst at Red Hat; and Alison Naylor, principal information security analyst at Red Hatâ"to contribute to this article. The link for this article located at Opensource.com is no longer available. . Uncover a quartet of open source solutions to bolster the security protocols of GitHub and AWS for software developers and systems engineers.. Open Source Security Tools, Cloud Security Solutions, GitHub Security Practices, AWS Security Enhancement, Vulnerability Management. . Brittany Day
Researchers sponsored by the U.S. government have reportedly tried to defeat the encryption and security of Apple devices for years. . Several presentations given between 2010 and 2012 at a conference sponsored by the U.S. Central Intelligence Agency described attempts to decrypt the firmware in Apple mobile devices or to backdoor Mac OS X and iOS applications by poisoning developer tools.. NSA's efforts to undermine Google security exposed in analysis documents from 2011-2013.. Apple Device Security, CIA Research, Encryption Attempts. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.