Sorry if I spoiled the plot of Dune 3
@bretfisher.com
Docker Captain π³ & Cloud Native Ambassador β Maker of best selling courses π¨βπ« Beach life π | Navy vet βοΈ AI in CI https://agenticdevops.pro Stream https://bret.live Discord https://devops.fan Newsletter https://bret.news Links https://bretfisher.com/start
Sorry if I spoiled the plot of Dune 3
It seems right now that the deadliest combo is in npm plus Actions on open source repos. S1ngularity used this 1/2 combo as well
In autumn Shai Hulud took at least 100k dev accounts after people installed an npm package with the exact same pre-install hook, which did exfiltration local secrets into a Fresh GitHub repo in the victims account www.aikido.dev/blog/github-...
The problem is bigger than prompts in GHA. Actions might now be the biggest attack vector for OSS. We just had major repos like Trivy get deleted because of workflows using the deadly pull_request_target event. gbhackers.com/hackerbot-cl...
gonna talk more about this weeks GitHub Actions attack on Trivy and other open source projects youtube.com/live/zkT-Bg8...
ποΈ Just published podcast episode 191: Your Images are Out of Date (probably) - The Silent Rebuilds problem
Gonna talk about my #Opencode and #GitHub #Copilot setup in a few youtube.com/live/LrBoWZ2...
ποΈ Just published podcast episode 190: AI Wins and Misses for 2025
I love learning the origin of metaphors and slang. I'll use a metaphor for years, like "balls out" or "table stakes," and while I know its meaning, I'm not sure of its origins. I've also looked up metaphors that are NOT what I thought, and I had to remove them from my repertoire π€¦
Years ago, internet told me "balls out" was a sailor metaphor for fully stocked cannon balls, but ChatGPT says that's folklore and it likely came from pilots referring to full throttle because the "balls" on their control sticks were fully "out"
ποΈ Just published podcast episode 189: Find your K8s happy path with RawKode Academy
Streaming some CI testing of AI #GitHub Actions youtube.com/live/UIklvek...
#GitHub Copilot Pro Tipβ’. Copilot has lots of features/models, including the new Copilot Memory, but many are disabled by default. Check your settings: github.com/settings/cop...
Aaron is so good at getting to the heart of why we are devs, and it's why his content and courses stand out as something I always read and watch.
Paul is a national treasure www.youtube.com/shorts/VhzJx...
I thought maybe you were putting clusters in cars, but this makes more sense!
My stream/podcast is back in 2026! On Thursday's stream, the founders of @plakarkorp.bsky.social join me to walk us through their open-source cloud backup solution. #DevOpsandDockerTalk
www.youtube.com/watch?v=Qpt4...
How bad actors are getting through, I'm not sure. Part might be account takeovers, part might be real humans who are just good at scamming while not getting detected, but the fact that phone number verification hasn't had an effect over months makes me wonder what's really going on.
I now spend nearly as much time protecting my Server and community that I do enjoying the conversation. I don't see how AI chatbots can save me. Ideas?
Being a Discord Server admin of a popular non-gaming topic has gotten so bad in the last few years, with daily spammers and scammers getting through *even with the highest level of protection -> phone number verification* I'm thinking of moving any paid community off the platform
With what? I had it all. Thermostats, cameras, protects, lock, alarm, and home screen. I'm planning on Ecobee.
Google ruined Nest (not a secret) and they keep giving me new reasons to leave. After 4 years of bugging me to migrate my Nest acct to a Google "personal" one, I had to create a Gmail, add a cc, buy a plan, migrate devices, and then Google promptly locked me out saying it's a bot account. Awesome
we're liveeeeeeeee!
My last stream of the year is Thursday! @mehtaverse-hq.bsky.social and @vfarcic.bsky.social join me to rant about our AI tools and what we'll still be using in 2026 and what we're leaving to gather dust in 2025.
What AI dev tools are you still using vs. quiting?
www.youtube.com/live/BX9lPK1...
Do you manage container image builds? I've wrapped up a major edit on my Silent Rebuilds tutorial and repo. Weeks of work! New blog and video content. #Docker #GitHub #GitHubActions www.bretfisher.com/silent-rebui...
A Screenshot of amazon.com showing a book I purchased in 2000 named "Windows 2000 Complete, First Edition"
My bank can't keep statements after a year, but Amazon still remembers what I purchased in 2000, including this banger. Only 1.8 stars? They must have hated the ending.
I need to tell you once again, how to secure your #GitHub Actions, on stream rn youtube.com/live/jvcoH7A...
If you saw my video introducing "Cool Bret" for #KubeCon ( watch it first, below), you might not realize how many takes are needed during recording...
#GPT 5.1 is wild with how it talks to me. It just gave me a guide for implementing some #GitHub security features and titled it "Putting it together like a DevOps adult".... I want to be a #DevOps adult. How can I be that?
#npm is not having a good year.