DevSecOps Podcast
Security used to be the team that said no at the end; DevSecOps is the bet that you can move fast and not get owned, by building the guardrails into the pipeline instead of bolting them on afterward. The episodes here dig into the supply chain you didn't know you had: dependency and build-system attacks, leaked credentials, and the CVEs that turn a quiet Tuesday into an all-hands.
We focus on the operational reality of shipping secure software — scanning that surfaces real issues instead of drowning teams in noise, secrets management that survives contact with developers, and zero-trust and SBOM work that's more than a compliance checkbox. If you're trying to make security a property of how you deploy rather than a gate sitting in front of it, start here.
Episodes on DevSecOps
This episode of Ship It Weekly is about automation’s hidden boundaries. Brian covers Kiro CLI CVE-2026-9255, where piped stdin could act like user approval, Amazon Braket SDK CVE-2026-9291…
This episode of Ship It Weekly is about trusted tools becoming production dependencies. Brian covers a rough GitHub supply chain week, including the compromised Nx Console VS Code…
This is a guest conversation episode of Ship It Weekly, separate from the weekly news recaps.In this Ship It: Conversations episode, I talk with Jake Warner, founder and…
This episode of Ship It Weekly is about secrets, agents, risky defaults, and follow-up work that never gets done. Brian covers the CISA contractor GitHub leak involving AWS…
This episode of Ship It Weekly is about AI agents moving from helpful coding assistants into real operational actors. Brian covers GitHub making Copilot cloud agent tasks available…
This episode of Ship It Weekly is about modern reliability getting squeezed from both directions. Old-school failures still hit hard, like broken DNSSEC, kernel privilege escalation bugs, and…
This is a guest conversation episode of Ship It Weekly, separate from the weekly news recaps.This episode is not sponsored. I wanted to cover IaCConf because the theme…
This episode of Ship It Weekly is about the developer toolchain becoming part of production. Brian covers GitHub’s critical git push RCE, AI-assisted reverse engineering, prompt injection against…
This episode of Ship It Weekly is about platforms getting sharper about defaults, ownership, and the old paths they are no longer willing to quietly carry forever. Brian…
This episode of Ship It Weekly is about networking, ingress, and private access moving further up into the platform layer. Brian covers AWS Interconnect going generally available, Cloudflare…
In this Ship It Weekly special, Brian breaks down Claude Mythos Preview and Project Glasswing, and why this story matters beyond normal AI launch hype.Anthropic is treating Mythos…
This episode of Ship It Weekly is about the interface layer becoming the story. Brian covers Amazon S3 Files and why it feels more like a managed filesystem…
This episode of Ship It Weekly is about the quiet platform work that keeps things safe before they break. Brian covers GitHub Actions hardening in Kubernetes-related repos, Airbnb’s…
This episode of Ship It Weekly is about the places where convenience quietly turns into trust.Brian revisits the Trivy story by zooming out to the bigger hackerbot-claw GitHub…
This week on Ship It Weekly, Brian looks at what happens when new interfaces create old responsibilities.McKinsey patched a vulnerability in its internal AI tool Lilli, Kafka contributors…
This week on Ship It Weekly, Brian covers five “AI meets reality” stories that every DevOps, SRE, security, and platform team can learn from.Block’s AI layoff story is…
This is a guest conversation episode of Ship It Weekly (separate from the weekly news recaps).In this Ship It: Conversations episode I talk with Yvonne Young, a cloud…
This week on Ship It Weekly, Brian looks at how the boundary of ops keeps expanding.We cover AWS flagging issues in Bahrain/UAE amid Iran strikes, ArgoCD vs Flux…
This week on Ship It Weekly, Brian looks at how the boundary of ops keeps expanding.We cover AWS flagging issues in Bahrain/UAE amid Iran strikes, ArgoCD vs Flux…
In this Ship It Weekly special, Brian breaks down the OpenClaw situation and why it’s bigger than “another CVE.”OpenClaw is a preview of what platform teams are about…
This week on Ship It Weekly, Brian hits four stories where the guardrails become the incident.GitHub had “Too Many Requests” caused by legacy abuse protections that outlived their…
This week on Ship It Weekly, Brian hits four “control plane + trust boundary” stories where the glue layer becomes the incident.Azure had a platform incident that impacted…
This week on Ship It Weekly, Brian looks at four “glue failures” that can turn into real outages and real security risk.We start with CodeBreach: AWS disclosed a…
This week on Ship It Weekly, Brian looks at three different versions of the same problem: systems are getting faster, but human attention is still the bottleneck.We start…
This week on Ship It Weekly, the theme is simple: the automation layer has become a control plane, and that changes how you should think about risk.We start…
This week on Ship It Weekly, Brian’s theme is basically: the “automation layer” is not a side tool anymore. It’s part of your perimeter, part of your reliability…
This is a guest conversation episode of Ship It Weekly (separate from the weekly news recaps).I sat down with Eric Paatey, a Cloud & DevOps Engineer who’s been…
This is a Ship It Weekly conversation episode. The weekly news recaps are still weekly. These interviews drop in between when I find someone worth talking to and…
This week on Ship It Weekly, Brian looks at how the “platform tax” is showing up everywhere: pricing model shifts, CI dependencies, and new security boundaries thanks to…
In this episode of Ship It Weekly, Brian powers through a cold and digs into a very “infra grown-up” week in DevOps.First up, IBM is buying Confluent for…
In this episode of Ship It Weekly, Brian digs into what’s new for people actually running infra: Kubernetes config, EKS control planes and networking, and GitHub’s latest CI/CD…
In this special kickoff episode of Ship It Weekly, Brian walks through three major outages from the last few weeks and what they actually mean for DevOps, SRE,…
Subscribe to Ship It Weekly
New episodes weekly on every major platform
From the newsroom
Prefer to read? On Call Brief is our weekly operator news digest.
Frequently asked questions
What does the DevSecOps podcast hub cover?
Building security guardrails into the pipeline instead of bolting them on — the software supply chain you didn't know you had, dependency and build-system attacks, leaked credentials, and the CVEs that turn a quiet Tuesday into an all-hands.
What practices does it focus on?
Scanning that surfaces real issues instead of noise, secrets management that survives contact with developers, and zero-trust and SBOM work that's more than a compliance checkbox.
Who is it for?
Engineers trying to make security a property of how they deploy rather than a gate sitting in front of it.
How are episodes selected?
They are auto-matched on DevSecOps topics — supply chain, vulnerabilities, SAST/DAST, secrets management, zero trust, SBOM, and CVEs — so the list reflects recent relevant episodes.
Is there a written security digest?
Yes — On Call Brief's DevOps Security News, linked from this page, covers actively-exploited CVEs and supply-chain advisories each week.