<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
  xmlns:atom="http://www.w3.org/2005/Atom"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DevSecOps Documentation (English)</title>
    <link>https://blog.stephane-robert.info/en/</link>
    <description>Selected articles in English on DevSecOps, supply chain security, CI/CD and infrastructure.</description>
    <language>en</language>
    <lastBuildDate>Tue, 28 Jul 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://blog.stephane-robert.info/en/rss.xml" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://blog.stephane-robert.info/favicon.svg</url>
      <title>DevSecOps Documentation (English)</title>
      <link>https://blog.stephane-robert.info/en/</link>
    </image>
    <copyright>(c) 2026 Stephane Robert</copyright>
    <managingEditor>contact@stephane-robert.info (Stephane Robert)</managingEditor>
    <webMaster>contact@stephane-robert.info (Stephane Robert)</webMaster>
    <ttl>60</ttl>
    <item>
      <title>AWX has had no release for two years: the risk and the fix</title>
      <link>https://blog.stephane-robert.info/en/post/awx-no-release-for-two-years/</link>
      <guid isPermaLink="true">https://blog.stephane-robert.info/en/post/awx-no-release-for-two-years/</guid>
      <description>AWX has shipped no release since July 2024. I scanned the official image: 45 CVEs, 3 critical. Why it happened, what I tested, and the option I settled on.</description>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <author>contact@stephane-robert.info (Stephane Robert)</author>
      <category>ansible</category>
        <category>awx</category>
        <category>securite</category>
        <category>supply-chain</category>
        <category>devsecops</category>
    </item>
    <item>
      <title>Chainguard Actions: hardening the GitHub Actions you did not write</title>
      <link>https://blog.stephane-robert.info/en/post/chainguard-actions-hardened-github-actions/</link>
      <guid isPermaLink="true">https://blog.stephane-robert.info/en/post/chainguard-actions-hardened-github-actions/</guid>
      <description>Chainguard Actions rebuilds and hardens GitHub Actions from source. What it fixes, what the community pushed back on, and why a pipeline scanner still matters.</description>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <author>contact@stephane-robert.info (Stephane Robert)</author>
      <category>github-actions</category>
        <category>supply-chain</category>
        <category>devsecops</category>
        <category>securite</category>
        <category>ci-cd</category>
    </item>
    <item>
      <title>Incus OS: I built a cluster without ever opening the UI</title>
      <link>https://blog.stephane-robert.info/en/post/incus-os-cluster-without-a-shell/</link>
      <guid isPermaLink="true">https://blog.stephane-robert.info/en/post/incus-os-cluster-without-a-shell/</guid>
      <description>Hands-on with Incus OS, the shell-less immutable OS announced late 2025. A 3-node cluster built through the API, the real pitfalls, and where the project stands.</description>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <author>contact@stephane-robert.info (Stephane Robert)</author>
      <category>incus</category>
        <category>virtualisation</category>
        <category>immuable</category>
        <category>retour-experience</category>
    </item>
    <item>
      <title>npm no longer runs install scripts: pnpm did it first</title>
      <link>https://blog.stephane-robert.info/en/post/npm-no-longer-runs-install-scripts/</link>
      <guid isPermaLink="true">https://blog.stephane-robert.info/en/post/npm-no-longer-runs-install-scripts/</guid>
      <description>npm v12 blocks dependency install scripts since 8 July 2026. pnpm shipped the same change in January 2025. What actually changes for your projects.</description>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <author>contact@stephane-robert.info (Stephane Robert)</author>
      <category>supply-chain</category>
        <category>npm</category>
        <category>devsecops</category>
        <category>securite</category>
        <category>veille</category>
    </item>
  </channel>
</rss>