dice.camp is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon server for RPG folks to hang out and talk. Not owned by a billionaire.

Administered by:

Server stats:

1.5K
active users

#developer

23 posts20 participants1 post today
heise Developer<p>Docker Image Security – Teil 1: Die größten Irrtümer über Image-Scanner</p><p>Image-Scanner wie Trivy und Grype sollen Container sicher machen. Doch sie liefern oft ungenaue Ergebnisse – mit riskanten Folgen für die IT-Sicherheit.</p><p><a href="https://www.heise.de/hintergrund/Docker-Image-Security-Teil-1-Die-groessten-Irrtuemer-ueber-Image-Scanner-10497655.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/hintergrund/Docker-Im</span><span class="invisible">age-Security-Teil-1-Die-groessten-Irrtuemer-ueber-Image-Scanner-10497655.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon</span></a></p><p><a href="https://social.heise.de/tags/Containerisierung" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Containerisierung</span></a> <a href="https://social.heise.de/tags/Developer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Developer</span></a> <a href="https://social.heise.de/tags/Docker" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Docker</span></a> <a href="https://social.heise.de/tags/IT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IT</span></a> <a href="https://social.heise.de/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://social.heise.de/tags/news" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>news</span></a></p>

Supply-chain attacks on open source software are getting out of hand

It has been a busy week for supply-chain attacks targeting open source software available in public repositories, with successful #breaches of multiple #developer accounts that resulted in malicious packages being pushed to unsuspecting users.
#security #supplychain #opensource

arstechnica.com/security/2025/

Gloved hands manipulate a laptop with a skull and crossbones on the display.
Ars Technica · Supply-chain attacks on open source software are getting out of handBy Dan Goodin

curious to hear from everyone's structure: do you and the teams in your company actively use or follow #devops principles or is it more the traditional "here are some #developer​s'" and "there's operations" workflow?

also, do you actively measure #dora metrics? do the dev teams work in #silos? is there a dedicated #SRE team?

(Alte) eigene Apps im Store …
Apple:
- 👼könntest Du mal schauen? Neue Einstufungen und Regeln. Wir haben alles automatisch für Dich angepasst aber sag mal was zu diesen Punkten dann können wir das ggf. korrigieren wenn nötig.

- Google: 👿😡letzte Warnung! Mach ein F*ing Update und halte dich an unsere Vorgaben sonst schmeißen wir dich und all dein Zeug raus! Solche faulen Loser dulden wir hier nicht! Zum Schutz unserer(!) User natürlich. KAPISCH?

Continued thread

#apple #LiquidGlas

As a #developer you have to know your users! Sure, a Mastodon Client is used by a different group of people. Those people might like to see the latest features included just because. Maybe it’s helpful, maybe it just looks cool.
In a business world it sure should look good but that doesn’t mean „shiny“ or „sparkling“. It means good readability, easy to use with big touch targets and designed to get things done without „scanning“ the UI to much (2/2)