| |  | | DevOpsLinks The Weekly DevOps Newsletter |
| | | ISSUE #547 · 20 SEP 2026 · 27 LINKS | | Cloudflare freed 100TB of RAM with one piece of math |
|
| | | | Hello, we're back! | We took a break for a few weeks this summer. We're back now, with four pieces of news. 1. FAUN.dev has a new look. The layout is simpler and cleaner, and pages are easier to read on your phone. Take a look. 2. A better way to rate tools and write reviews. Picking a tool usually goes like this: you open ten tabs, read three "Top 10" lists (at least one of them written by a vendor), and end up choosing the tool with the nicest homepage. We've done it too. So we built something better. Every tool on FAUN.dev now gets a score out of 100, and we show exactly where that number comes from: - Criteria based on a real standard. They follow ISO/IEC 25010, the international standard for software quality, plus two
things buyers care about: community and cost. Each category also gets its own criteria, because a CI tool isn't judged like a database.
- A reason for every number. Each score comes with a written justification, based on sources you can check: docs, releases, open issues, CVEs and independent benchmarks.
- Your voice next to ours. Your votes make up the Community Score, and it sits right next to our score. When you and our editors disagree, everyone can see it.
- Scores are not for sale. No one can pay to be listed, to be scored or to rank higher. A sponsored tool is always labelled as sponsored.
Here is what it looks like for Terraform: Now it's your turn. You use these tools every day, and we don't. Add the tools you use to your toolbox, then rate each one on what you know and skip the rest. You don't need an opinion on everything. Every vote makes the rankings more useful for the next developer who has ten tabs open. 3. PythonLinks is coming back soon. Our weekly Python newsletter
restarts in the next few weeks. Update your newsletter settings to subscribe. 4. A new look for this newsletter too. You may have noticed that this email looks different. We rebuilt the newsletter template so it's cleaner and easier to read, on a phone and on a big screen. We hope you like it! Just hit reply and tell us what you think. That's all! Enjoy this issue. |
| | | | | | INSIDE THIS ISSUE | If you run JFrog Artifactory, read the Artifactory story before anything else this week. Three flaws are under attack, and in some break-ins the intruders took the key that signs access tokens. That key keeps working
after the upgrade, so patching alone does not lock them out. Self-managed GitLab has its own emergency: a CVSS 10 file-read flaw, already exploited. Also inside: how Cloudflare freed 100TB of RAM with one piece of math, how DuckDB 2.0 cut an S3 scan from 18.8 to 7.7 seconds, and why the Kubernetes DNS policy called "Default" is not the one your Pods get by default. |
| | | | | | NEWS | | GitLab 19.3.2 fixes exploited CVSS 10 file-read flaw CVE-2026-85706 | | An unauthenticated attacker can read any file on a self-managed
GitLab server through the repository commits API, and CISA added the flaw to its exploited list one day after the out-of-band fix. Every CE or EE install from 18.7 onward needs 19.1.8, 19.2.6 or 19.3.2, and the upgrade runs database migrations, so a single-node instance goes down while it applies. The same release closes 17 more bugs, including a second critical one and two that leak protected CI/CD variables. |
| | | | JFrog Artifactory flaws CVE-2026-82329, 42018 and 42016 under attack | | Attackers chained two self-hosted JFrog Artifactory bugs to turn an anonymous token into an admin one, then used a third, critical one to become admin with no credentials at all. Inside, they planted admin accounts, Groovy plugins, web shells and a Rust backdoor, and some copied the key that signs tokens, which keeps working after an upgrade. The safe targets are 7.133.29, 7.146.38 or 7.161.20,
and Wiz says to treat any instance that was reachable while unpatched as compromised. |
| | |
|
|