Operations | Monitoring | ITSM | DevOps | Cloud

How are folks managing CVEs at scale? #itsecurity #opensource #vulnerability #sbom

Dog-walk thoughts on vulnerabilities at scale More CVEs are being found, disclosed and weaponised faster than ever. For a small team with one product, that's manageable: a CVE lands, you fix it. But if you're running thousands of applications across tens of thousands of repos, "the teams will handle it" stops working. It becomes a governance problem.

Building a Control Framework for the AI SDLC

AI coding tools are in use across regulated industries, producing workable code faster than humans can review. It’s a shift that’s raising difficult questions that haven’t been fully answered yet. What does governance look like when AI agents are writing the code, reviewing each other’s work, and fixing their own findings? How do you prove what code is running and whether it passed your checks? Who’s accountable for change approvals, audits, incidents?

Introducing Controls in Kosli

Defining a control in a policy document is easy. Proving that every build was evaluated against it - and that nothing non-compliant ever reached production - is the hard part. Kosli's new Controls feature closes that gap. Every control is defined in Kosli, every build is evaluated against it, and deployments are gated automatically when the evidence isn't there. That means: Every control decision is recorded as evidence, build by build Coverage shows exactly where a control is enforced across your environments.

AI Can't Prove Compliance by Itself

AI is moving fast, and it’s tempting to believe it can automate software governance end to end. But compliance and security aren’t probabilistic problems. They don’t accept “close enough.” They don’t accept summaries. They can’t tolerate hallucinations. Governance depends on facts. Irrefutable, provable evidence of how systems actually changed.

Governance Doesn't Stop at Deploy

Most governance models focus on what happens before production. Approvals. Tickets. Change records. But software delivery doesn’t end at deploy. Runtime is where change management is validated. It’s where systems prove whether controls actually work and where risk becomes real. If governance stops at deployment, you’re not managing change. You’re managing intent. In this video, Mike Long (CEO & Co-founder, Kosli) explains why runtime is the true source of control, why approvals alone don’t reduce risk, and how modern teams build governance that reflects reality, not paperwork.

Evidence, Not Screenshots

In regulated environments, slow change is often blamed on process. In reality, it’s caused by missing, fragmented, or untrusted proof. Screenshots. Tickets. Manual approvals. Evidence assembled after the fact. In this video, we show what changes when compliance policies are embedded directly into release workflows — and when immutable, machine-readable evidence is captured automatically across CI/CD.

ServiceNow Without the Ticket Hell

ServiceNow is the system of record for change and approvals in most regulated enterprises. But when evidence lives elsewhere — scattered across CI tools, scanners, tickets, and screenshots — approvals slow down and audits become painful. Developers waste hours chasing proof. CABs approve changes without confidence. Auditors reconstruct history months later. In this video, Matt Bailey shows what changes when evidence is produced continuously, directly from the delivery pipeline, and linked into ServiceNow workflows.

Why Release Control Takes Weeks

The industry standard for release control is painfully manual: long-form policy documents, ServiceNow forms, human approvals, meetings, and tickets that take days or even weeks to close. In this video, Mike Long (CEO & Co-founder, Kosli) explains the difference between manual release control and an automated, zero-trust model where evidence is collected automatically, provenance identifies the artifact, and approvals can be fully codified.

Evidence as an Input

Evidence isn’t something you produce at the end — it’s something every control generates for the next one. In this video, Mike Long (CEO & Co-founder, Kosli) explains how vulnerability scans produce evidence tied to the artifact fingerprint and the policy file used, and how that evidence becomes an input to downstream controls like release approvals. This is the core of reusable, continuous compliance.