Bret Fisher's Avatar

Bret Fisher

@bretfisher.com

Docker Captain 🐳 & Cloud Native Ambassador ⎈ Maker of best selling courses πŸ‘¨β€πŸ« Beach life πŸ– | Navy vet βš“οΈ AI in CI https://agenticdevops.pro Stream https://bret.live Discord https://devops.fan Newsletter https://bret.news Links https://bretfisher.com/start

1,336
Followers
523
Following
416
Posts
08.05.2023
Joined
Posts Following

Latest posts by Bret Fisher @bretfisher.com

Sorry if I spoiled the plot of Dune 3

06.03.2026 05:49 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

It seems right now that the deadliest combo is in npm plus Actions on open source repos. S1ngularity used this 1/2 combo as well

06.03.2026 05:32 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Shai Hulud Attacks Continue Through GitHub Actions Security Gaps Shai Hulud threat actors are leveraging GitHub Actions vulnerabilities in an ongoing exploitation campaign. Discover the impact and recommended security measures.

In autumn Shai Hulud took at least 100k dev accounts after people installed an npm package with the exact same pre-install hook, which did exfiltration local secrets into a Fresh GitHub repo in the victims account www.aikido.dev/blog/github-...

06.03.2026 05:32 πŸ‘ 10 πŸ” 1 πŸ’¬ 3 πŸ“Œ 0
Preview
Hackerbot-Claw Bot Exploits GitHub Actions CI/CD Flaw to Attack Microsoft and DataDog Hackerbot-claw, an autonomous AI bot, has launched a week-long campaign abusing GitHub Actions misconfigurations to hit CI/CD pipelines at Microsoft, DataDog.

The problem is bigger than prompts in GHA. Actions might now be the biggest attack vector for OSS. We just had major repos like Trivy get deleted because of workflows using the deadly pull_request_target event. gbhackers.com/hackerbot-cl...

06.03.2026 05:32 πŸ‘ 6 πŸ” 7 πŸ’¬ 1 πŸ“Œ 0
Preview
On Stream: Prevent GitHub Actions Attacks YouTube video by Bret Fisher

gonna talk more about this weeks GitHub Actions attack on Trivy and other open source projects youtube.com/live/zkT-Bg8...

05.03.2026 20:00 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Your Images are Out of Date (probably) - The Silent Rebuilds problem Container base images (like Official Docker Hub images) are often...

πŸŽ™οΈ Just published podcast episode 191: Your Images are Out of Date (probably) - The Silent Rebuilds problem

04.03.2026 19:24 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
On Stream: Opencode with GitHub Copilot YouTube video by Bret Fisher

Gonna talk about my #Opencode and #GitHub #Copilot setup in a few youtube.com/live/LrBoWZ2...

26.02.2026 18:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AI Wins and Misses for 2025 I'm joined by Nirmal Mehta of AWS and Viktor Farcic from Upbound, to go...

πŸŽ™οΈ Just published podcast episode 190: AI Wins and Misses for 2025

17.02.2026 02:40 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

I love learning the origin of metaphors and slang. I'll use a metaphor for years, like "balls out" or "table stakes," and while I know its meaning, I'm not sure of its origins. I've also looked up metaphors that are NOT what I thought, and I had to remove them from my repertoire 🀦

02.02.2026 13:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Years ago, internet told me "balls out" was a sailor metaphor for fully stocked cannon balls, but ChatGPT says that's folklore and it likely came from pilots referring to full throttle because the "balls" on their control sticks were fully "out"

02.02.2026 13:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Find your K8s happy path with RawKode Academy I talk with David Flanagan, aka Rawkode, about his new opinionated Tech...

πŸŽ™οΈ Just published podcast episode 189: Find your K8s happy path with RawKode Academy

23.01.2026 19:16 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
On Stream: AI in my CI YouTube video by Bret Fisher

Streaming some CI testing of AI #GitHub Actions youtube.com/live/UIklvek...

22.01.2026 18:08 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Build software better, together GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

#GitHub Copilot Pro Tipβ„’. Copilot has lots of features/models, including the new Copilot Memory, but many are disabled by default. Check your settings: github.com/settings/cop...

17.01.2026 23:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Aaron is so good at getting to the heart of why we are devs, and it's why his content and courses stand out as something I always read and watch.

14.01.2026 23:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Paul Rudd's Hollywood Beefs
Paul Rudd's Hollywood Beefs YouTube video by Rick Glassman

Paul is a national treasure www.youtube.com/shorts/VhzJx...

14.01.2026 23:33 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I thought maybe you were putting clusters in cars, but this makes more sense!

14.01.2026 19:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
On Stream: Backup S3, Google Drive, iCloud, Notion with Plakar
On Stream: Backup S3, Google Drive, iCloud, Notion with Plakar YouTube video by Bret Fisher

My stream/podcast is back in 2026! On Thursday's stream, the founders of @plakarkorp.bsky.social join me to walk us through their open-source cloud backup solution. #DevOpsandDockerTalk
www.youtube.com/watch?v=Qpt4...

14.01.2026 19:16 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

How bad actors are getting through, I'm not sure. Part might be account takeovers, part might be real humans who are just good at scamming while not getting detected, but the fact that phone number verification hasn't had an effect over months makes me wonder what's really going on.

12.01.2026 03:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I now spend nearly as much time protecting my Server and community that I do enjoying the conversation. I don't see how AI chatbots can save me. Ideas?

12.01.2026 03:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Being a Discord Server admin of a popular non-gaming topic has gotten so bad in the last few years, with daily spammers and scammers getting through *even with the highest level of protection -> phone number verification* I'm thinking of moving any paid community off the platform

12.01.2026 03:39 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

With what? I had it all. Thermostats, cameras, protects, lock, alarm, and home screen. I'm planning on Ecobee.

20.12.2025 22:59 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Google ruined Nest (not a secret) and they keep giving me new reasons to leave. After 4 years of bugging me to migrate my Nest acct to a Google "personal" one, I had to create a Gmail, add a cc, buy a plan, migrate devices, and then Google promptly locked me out saying it's a bot account. Awesome

20.12.2025 22:36 πŸ‘ 1 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

we're liveeeeeeeee!

18.12.2025 18:02 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
On Stream: Best and Worst AI Dev Tools of 2025 YouTube video by Bret Fisher

My last stream of the year is Thursday! @mehtaverse-hq.bsky.social and @vfarcic.bsky.social join me to rant about our AI tools and what we'll still be using in 2026 and what we're leaving to gather dust in 2025.

What AI dev tools are you still using vs. quiting?

www.youtube.com/live/BX9lPK1...

17.12.2025 20:59 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Preview
Silent Rebuilds: Keeping Container CVE Counts Near-Zero Starting with a slim/distroless container image is necessary today, but it isn't enough. You need daily automation to trigger rebuilds for dependencies and base image digest updates.

Do you manage container image builds? I've wrapped up a major edit on my Silent Rebuilds tutorial and repo. Weeks of work! New blog and video content. #Docker #GitHub #GitHubActions www.bretfisher.com/silent-rebui...

16.12.2025 19:14 πŸ‘ 7 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
A Screenshot of amazon.com showing a book I purchased in 2000 named "Windows 2000 Complete, First Edition"

A Screenshot of amazon.com showing a book I purchased in 2000 named "Windows 2000 Complete, First Edition"

My bank can't keep statements after a year, but Amazon still remembers what I purchased in 2000, including this banger. Only 1.8 stars? They must have hated the ending.

16.12.2025 18:12 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
On Stream: Defend Against S1ngularity and Shai Hulud Attacks YouTube video by Bret Fisher

I need to tell you once again, how to secure your #GitHub Actions, on stream rn youtube.com/live/jvcoH7A...

11.12.2025 18:47 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you saw my video introducing "Cool Bret" for #KubeCon ( watch it first, below), you might not realize how many takes are needed during recording...

25.11.2025 21:04 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

#GPT 5.1 is wild with how it talks to me. It just gave me a guide for implementing some #GitHub security features and titled it "Putting it together like a DevOps adult".... I want to be a #DevOps adult. How can I be that?

25.11.2025 20:00 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

#npm is not having a good year.

25.11.2025 19:58 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0