Tracy Ragan, CEO DeployHub's Avatar

Tracy Ragan, CEO DeployHub

@tracyragan

Tracy is a recognized authority in software supply chain security and DevSecOps, with expertise in managing complex, decoupled architectures. She serves on the OpenSSF Governing Board and the Technology Oversight Committee.

13
Followers
25
Following
133
Posts
13.01.2025
Joined
Posts Following

Latest posts by Tracy Ragan, CEO DeployHub @tracyragan

Post image

The CDF Awards are open - Nominate or self-nominate in general CDF categories, and for each project. @cdeliveryfdn.bsky.social Learn more at https://cstu.io/479549

10.03.2026 15:04 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity A week-long automated attack campaign targeted CI/CD pipelines across major open source repositories, achieving remote code execution in at least 4 out of 5 targets. The attacker, an autonomous bot called hackerbot-claw, used 5 different ex...

Check your repos! @openssf published their first security alert, and it is big. hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity https://share.google/nTL8rigasYgm2FA2b

04.03.2026 15:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

It was a pleasure chatting with Steve on the topic of vulnerabilities, and how we can cut the constant noise by focusing on addressing the ones that impact our live systems - post deployment. https://www.techleadertalk.com/managing-software-vulnerabilities-tracy-ragan/

03.03.2026 15:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AWS's Crosier Talks Accelerating Intelligence With the Space-Based Cloud Clint Crosier explains the evolution of the space-based cloud, and how AWS worked for nearly a decade to solve one of the most important operational challenges of the modern, connected age – getting a firm grasp on big data.

Satellite technology will become our future data centers. Learn about the #Space-Based-Cloud {(urn:li:organization:2382910)[Amazon Web Services (AWS)]} https://cstu.io/b2cf1b

10.02.2026 18:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Why β€œDigital Twins” Matter, and What They Offer to DevSecOps and Platform Engineers Software continues to become more complex and vulnerable, with microservices, Agentic AI, orchestration, infrastructure as code, dynamic configurations, and fluid environments adding to the heap. Keeping track of software security and syste...

Digital Twins in #DevSecOps and #PlatformEngineering can be the future of rapid response to vulnerabilities running in production. #supplychainsecurity #CICD @cdeliveryfdn.bsky.sociald https://cstu.io/99cb03

04.02.2026 18:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AWS's Crosier Talks Accelerating Intelligence With the Space-Based Cloud Clint Crosier explains the evolution of the space-based cloud, and how AWS worked for nearly a decade to solve one of the most important operational challenges of the modern, connected age – getting a firm grasp on big data.

Satellite technology will become our future data centers. Learn about the #Space-Based-Cloud {(urn:li:organization:2382910)[Amazon Web Services (AWS)]} https://cstu.io/b2cf1b

29.01.2026 21:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AI agents 2026's biggest insider threat: PANW security boss interview: Lock 'em down

If you follow me, you know I've been talking about #AIAgent security A LOT over the last year. Here are points on the topic from Wendi Whitmore, Chief Security Intel Officer @paloaltonetworks.com https://cstu.io/39f4d8

29.01.2026 06:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Why β€œDigital Twins” Matter, and What They Offer to DevSecOps and Platform Engineers Software continues to become more complex and vulnerable, with microservices, Agentic AI, orchestration, infrastructure as code, dynamic configurations, and fluid environments adding to the heap. Keeping track of software security and syste...

Digital Twins in #DevSecOps and #PlatformEngineering can be the future of rapid response to vulnerabilities running in production. #supplychainsecurity #CICD @cdeliveryfdn.bsky.sociald https://cstu.io/99cb03

27.01.2026 20:06 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Personal Details of Thousands of Border Patrol and ICE Goons Allegedly Leaked in Huge Data Breach A DHS whistleblower appears to have exposed data on federal immigration workers after the shooting of Renee Good.

Well, this does not surprise me. https://cstu.io/d45371

20.01.2026 17:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
New CybersecurityΒ Rules for Pentagon’s Satellite Vendors The Pentagon recently issued new rules on cybersecurity measures that commercial satellite operators must employ.

I think the Pentagon may have heard our DeployHub pitch - their new rules include: Implement security patch management for on-board and ground segment software, yes, Post-Deployment detection required #cybersecurity #satelliteoperators https://cstu.io/181ecd

14.01.2026 19:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Why β€œDigital Twins” Matter, and What They Offer to DevSecOps and Platform Engineers Software continues to become more complex and vulnerable, with microservices, Agentic AI, orchestration, infrastructure as code, dynamic configurations, and fluid environments adding to the heap. Keeping track of software security and syste...

Digital Twins in #DevSecOps and #PlatformEngineering can be the future of rapid response to vulnerabilities running in production. #supplychainsecurity #CICD @cdeliveryfdn.bsky.sociald https://cstu.io/99cb03

08.01.2026 16:03 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
AI agents 2026's biggest insider threat: PANW security boss interview: Lock 'em down

If you follow me, you know I've been talking about #AIAgent security A LOT over the last year. Here are points on the topic from Wendi Whitmore, Chief Security Intel Officer @paloaltonetworks.com https://cstu.io/39f4d8

07.01.2026 16:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AWS's Crosier Talks Accelerating Intelligence With the Space-Based Cloud Clint Crosier explains the evolution of the space-based cloud, and how AWS worked for nearly a decade to solve one of the most important operational challenges of the modern, connected age – getting a firm grasp on big data.

Satellite technology will become our future data centers. Learn about the #Space-Based-Cloud {(urn:li:organization:2382910)[Amazon Web Services (AWS)]} https://cstu.io/b2cf1b

06.01.2026 17:04 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
cdCon Finalist in 2025 DevOps Dozen Award - CD Foundation cdCon is a finalist in the 2025 DevOps Dozen Awards for Best DevOps Event of the Year!

Vote for #CDCon for DevOps Dozen Award - show them some love. {(urn:li:organization:19100461)[Continuous Delivery Foundation]} https://cstu.io/b54cf8

29.12.2025 18:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Ortelius is asking for some GitHub stars from Santa. You can help by visiting the Ortelius GitHub repo and giving it a star. https://cstu.io/237edb

26.12.2025 19:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Ortelius is asking for some GitHub stars from Santa. You can help by visiting the Ortelius GitHub repo and giving it a star. https://cstu.io/237edb

24.12.2025 17:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Attack Surface Visibility for Open-Source Software Security Enhance your security with Attack Surface Visibility to identify vulnerabilities in open-source packages and deployed environments.

For addressing high-risk and critical #CVEs the most important information is your attack surface. #softwaresupplychain #cybersecurity #devsecops https://cstu.io/8f8cdb

23.12.2025 15:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Ortelius is asking for some GitHub stars from Santa. You can help by visiting the Ortelius GitHub repo and giving it a star. https://cstu.io/237edb

22.12.2025 17:53 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
cdCon Finalist in 2025 DevOps Dozen Award - CD Foundation cdCon is a finalist in the 2025 DevOps Dozen Awards for Best DevOps Event of the Year!

Vote for #CDCon for DevOps Dozen Award - show them some love. {(urn:li:organization:19100461)[Continuous Delivery Foundation]} https://cstu.io/b54cf8

22.12.2025 16:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Ortelius is asking for some GitHub stars from Santa. You can help by visiting the Ortelius GitHub repo and giving it a star. https://cstu.io/237edb

19.12.2025 17:53 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
cdCon Finalist in 2025 DevOps Dozen Award - CD Foundation cdCon is a finalist in the 2025 DevOps Dozen Awards for Best DevOps Event of the Year!

Vote for #CDCon for DevOps Dozen Award - show them some love. {(urn:li:organization:19100461)[Continuous Delivery Foundation]} https://cstu.io/b54cf8

19.12.2025 17:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Ortelius is asking for some GitHub stars from Santa. You can help by visiting the Ortelius GitHub repo and giving it a star. https://cstu.io/237edb

17.12.2025 19:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Shai-Hulud 2.0: Aggressive & Automated, One Of Fastest Spreading NPM Supply Chain Attacks Ever Observed Shai-Hulud 2.0 is an aggressive, automated NPM supply chain attack. Get the full analysis on credential theft, GitHub backdoors, and IOCs.

"You gotta watch out for the sandworms" - a really bad #softwaresupplychian attack. Wave 2 of #Shai-Hulud https://cstu.io/700f03

16.12.2025 16:06 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
New CybersecurityΒ Rules for Pentagon’s Satellite Vendors The Pentagon recently issued new rules on cybersecurity measures that commercial satellite operators must employ.

I think the Pentagon may have heard our DeployHub pitch - their new rules include: Implement security patch management for on-board and ground segment software, yes, Post-Deployment detection required #cybersecurity #satelliteoperators https://cstu.io/181ecd

15.12.2025 16:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Attack Surface Visibility for Open-Source Software Security Enhance your security with Attack Surface Visibility to identify vulnerabilities in open-source packages and deployed environments.

For addressing high-risk and critical #CVEs the most important information is your attack surface. #softwaresupplychain #cybersecurity #devsecops https://cstu.io/8f8cdb

12.12.2025 17:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CISA, eyeing China, plans hiring spree to rebuild its depleted ranks The agency will also change some of its workforce policies to avoid driving away talented staff.

It is a shame they gutted CISA in the first place - might be hard to bring that expertise back. CISA hiring in 2026. https://cstu.io/e4a7b5

10.12.2025 19:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
cdCon Finalist in 2025 DevOps Dozen Award - CD Foundation cdCon is a finalist in the 2025 DevOps Dozen Awards for Best DevOps Event of the Year!

Vote for #CDCon for DevOps Dozen Award - show them some love. {(urn:li:organization:19100461)[Continuous Delivery Foundation]} https://cstu.io/b54cf8

08.12.2025 23:19 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Attack Surface Visibility for Open-Source Software Security Enhance your security with Attack Surface Visibility to identify vulnerabilities in open-source packages and deployed environments.

For addressing high-risk and critical #CVEs the most important information is your attack surface. #softwaresupplychain #cybersecurity #devsecops https://cstu.io/8f8cdb

04.12.2025 21:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Understand what is missing in your security stack - a defensive post-deployment approach, pinpointing what #CVEs are impacting live systems now. https://cstu.io/0f65d5

03.12.2025 19:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
cdCon Finalist in 2025 DevOps Dozen Award - CD Foundation cdCon is a finalist in the 2025 DevOps Dozen Awards for Best DevOps Event of the Year!

Vote for #CDCon for DevOps Dozen Award - show them some love. {(urn:li:organization:19100461)[Continuous Delivery Foundation]} https://cstu.io/b54cf8

02.12.2025 17:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0