Operations | Monitoring | ITSM | DevOps | Cloud

The latest News and Information on Continuous Integration and Development, and related technologies.

Cloudsmith By the Numbers 2021

Another amazing year in the books! And even though we’ve done the ‘By the Numbers’ series for a few years now, this year’s numbers are the best (and biggest) yet. But even better than that? The people behind the numbers. Carrying on the growth we saw in 2020, the most important number to highlight this year is the massive increase in awesome Cloudsmithers we added to the team!

Startup Spaces: Technology Due Diligence 101 - Secrets from an Auditor

Hear from an experienced panel of Tech DD auditors, CTO’s and VCs about how you can pass your next Tech DD audit with flying colours. You’ll learn: Johann Romefort, Tech DD consultant and former CTO, MD at Techstars, is joined by special guests Luca Grulla, CTO at Signal AI, Zoé Constantin of Impact Partners, auditor Alyx Baldwin, and Felix Eichler, CTO & Co-Founder at Userlane. Learn what to expect during a technical audit and how to prepare — both logistically and mentally — for the entire process.

How AI and ML will impact the future of software development with Nathan Mellis

Rob sits down with Nathan Mellis, Director of Engineering at Modzy to discuss all things ML and AI in the space of software development. Get answers to questions like, Join this fascinating conversation of where the industry of software development is headed next.

Configuring multiple Docker services with different memory limits

Bitbucket Pipelines provides a feature that enables you to configure memory in Docker services (learn more on that here). We have related highly voted suggestion where customers would like to configure multiple Docker services, each with different memory configurations. Here’s a working example of how you can set memory limits to multiple Docker services and use the appropriate service depending on the step requirements.

Manage complex development projects by triggering pipelines from other pipelines

It is no secret that software development is becoming an increasingly complex process. The individual elements of software like apps, libraries, and services are interconnected and dependent on many other elements. Development teams deal with a whole ecosystem of services that they develop, maintain, or depend on, which in turn are dependent on other software ecosystems, maintained by separate teams. Maintaining this ecosystem is as complex as you might imagine.

Cloudsmith is ISO27001:2013 Certified

When planning our 2021 roadmap this time last year, one of the most prominent themes was security. Although we’re not solely in the security category, as a fully managed service in the heart of our customers’ software supply chains, it was always paramount for what we do and still is. Ensuring the integrity and privacy of customer data is our top priority.

Malicious npm Packages Are After Your Discord Tokens - 17 New Packages Disclosed

The JFrog Security research team continuously monitors popular open source software (OSS) repositories with our automated tooling, and reports any vulnerabilities or malicious packages discovered to repository maintainers and the wider community. Most recently we disclosed 11 malicious packages in the PyPI repository, a discovery that shows attacks are getting more sophisticated in their approach.