Operations | Monitoring | ITSM | DevOps | Cloud

Open Source

Log4j Detection with JFrog OSS Scanning Tools

The discovery of the Log4Shell vulnerability in the ubiquitous Apache Log4j package is a singular event in terms of both its impact and severity. Over 1 million attack attempts exploiting the Log4Shell vulnerability were detected within days after it was exposed, and it may take years before we see its full impact.

Announcement: Pleco - the open-source Kubernetes and Cloud Services garbage collector

TLDR; Pleco is a service that automatically removes Cloud managed services and Kubernetes resources based on tags with TTL. When using cloud provider services, whether using UI or Terraform, you usually have to create many resources (users, VPCs, virtual machines, clusters, etc...) to host and expose an application to the outside world. When using Terraform, sometimes, the deployment will not go as planned.

Open Source FOMO? Not with Tanzu Application Platform

If you are not familiar with the term, FOMO is short for “fear of missing out,” and some developers are feeling it these days. Developers want to be a part of a technical community and stay current by working on, and with, the most innovative technologies. Open source FOMO comes when they witness their peers getting to explore new technologies that help them get ahead, while they’re bogged down with stale technology and monolithic apps.

Yes, Open Source Is Sustainable

Two months ago, we announced our annual investment in open source maintainers, mostly folks whose work we depend on to deliver Sentry to you, plus a few research and hobby projects that our employees put on our radar. Two days ago, six of these maintainers joined us for a one-hour panel called “The Future of Open Source: Is It Sustainable?” I co-hosted with Jessica Lord, Product Manager of GitHub Sponsors.

Log4j gets added to the code "wall of shame."

It seems that every few weeks, we are alerted to a new significant security issue within one of the plethoras of code elements that are widely used. The same pundits discuss the same range of concerns with open-sourced code each time. The list of “usual suspects” is long, and I know I could add at least 20 additional “reasons” to this list without thinking about it too hard. I’m not sure that open-sourced code is riskier than proprietary developed code. There I said it.

The Future of Open Source: Is it Sustainable?

Open Source projects are at the heart of most software that we depend on everyday. Community-supported volunteers work behind the scenes to make open source better for everyone, but it can be a thankless—and penny-pinching—job. Is it sustainable? Join us in a live virtual event with GitHub Sponsors to find out. We’ll showcase leading maintainers in the community and discuss the future of open source sustainability.

Introduction to Aiven for Apache Flink

Aiven for Apache Flink uses the familiar SQL language to support your real-time analytics and ETL needs. The powerful, fully managed platform – deployable in the cloud of your choice – is your fastest way to tap into the benefits of real-time stream processing. Aiven Solution Architect Jason Hepp walks us through the fundamentals of setting up Aiven for Apache Flink for all your real-time stream processing needs.