CuraDevOps

tag: Ci-Cd · 13 items

2026-08-28 · GitHub Changelog · source ↗ #github-actions#workflow-retention#ci-cd
  • Platform/SRE — Skip
  • CI/CD — Plan: Starting October 1, 2026, GitHub Actions retention settings will also govern checks, workflow runs, and commit statuses — review your current retention configuration to ensure historical build data and compliance audit trails are preserved as expected before the change takes effect.
  • Leader — Skip
2026-08-18 · GitLab Blog · source ↗ #gitlab#security-patch#ci-cd
  • Platform/SRE — Plan: If running a self-managed GitLab instance, upgrade to the patched version in your release line; no public PoC or KEV listing is confirmed from the title alone, so this is urgent-but-scheduled rather than emergency.
  • CI/CD — Act: GitLab CI users on self-managed instances should upgrade to 19.2.4, 19.1.6, 19.0.8, or 18.11.11 promptly — a critical patch to the CI/CD platform itself can directly break or compromise pipelines and should be treated as an outage-level priority.
  • Leader — Skip
  • Signals: major release (19.0)
2026-08-17 · Releases: jenkins · source ↗ #jenkins#ci-cd#plugin-management
  • Platform/SRE — Skip
  • CI/CD — Learn: Jenkins 2.577 removes the last of the detached-plugin bundling from jenkins.war, meaning any plugin previously auto-included must now be explicitly installed; worth noting before a weekly-channel upgrade, but no deadline exists and this is a weekly (non-LTS) build.
  • Leader — Skip
2026-08-10 · Releases: jenkins · source ↗ #jenkins#security#ci-cd
  • Platform/SRE — Skip
  • CI/CD — Plan: Jenkins 2.576 ships multiple security fixes; review the 2026-08-05 security advisory and plan an upgrade of any self-hosted Jenkins controllers to this weekly build or wait for the next LTS incorporating these patches.
  • Leader — Skip
2026-08-10 · Releases: jenkins · source ↗ #jenkins#ci-cd#breaking-change
  • Platform/SRE — Skip
  • CI/CD — Plan: Jenkins 2.568.2 carries a breaking-change flag; review the upgrade guide before updating the Jenkins controller to avoid pipeline regressions.
  • Leader — Skip
  • Signals: Jenkins 2.568 supported · breaking-change flagged
2026-08-07 · CNCF Blog · source ↗ #supply-chain#ai-security#ci-cd
  • Platform/SRE — Learn: Useful framing for understanding how unsanctioned AI tools introduce new attack surfaces into the platform layer, but no specific infrastructure action or deadline is present.
  • CI/CD — Learn: Directly relevant to pipeline security thinking — AI extensions and agents in the build path are an emerging supply-chain risk worth evaluating, but no concrete deprecation, compromise, or deadline anchors an Act or Plan verdict.
  • Leader — Plan: Shadow AI in delivery pipelines is a policy and governance gap that warrants adding AI tool usage to supply-chain standards and acceptable-use policy; schedule a review of which AI integrations teams are using in pipelines before the next security audit cycle.
2026-07-22 · HN (terraform) · source ↗ #ci-cd#terraform#pipeline
  • Platform/SRE — Skip
  • CI/CD — Learn: An early-stage, HCL-native pipeline tool aiming for CI provider agnosticism via Terraform-style modules — worth monitoring if your org is already deep in HCL/Terraform, but no GA stability signals or deadline to act on.
  • Leader — Skip
2026-07-21 · HN (devops) · source ↗ #azure-devops#outage#ci-cd
  • Platform/SRE — Skip
  • CI/CD — Learn: Azure DevOps experienced a global outage affecting pipelines and source control; no remediation action needed post-resolution, but teams dependent on Azure DevOps should review their continuity posture for future incidents.
  • Leader — Skip
Learn archived GitLab 19.2 released
2026-07-17 · GitLab Blog · source ↗ #gitlab#release#ci-cd
  • Platform/SRE — Learn: GitLab 19.2 is a new minor release that may affect self-managed GitLab instances, but no summary or enrichment signals are available to identify breaking changes, security fixes, or upgrade urgency.
  • CI/CD — Learn: A new GitLab minor release typically includes CI/CD pipeline features worth evaluating, but no details are present in this item to determine whether any pipeline changes are warranted.
  • Leader — Skip
2026-07-17 · GitLab Blog · source ↗ #gitlab#agentic-workflows#ci-cd
  • Platform/SRE — Skip
  • CI/CD — Plan: Custom Flows are now GA in GitLab 19.2, enabling event-triggered, AI-driven multi-step pipeline sequences (e.g., analyze failure → generate fix → commit → notify). Teams on GitLab should evaluate whether encoding trusted delivery sequences as Flows reduces manual handoffs and pipeline runbook debt.
  • Leader — Learn: GitLab’s agentic flow model represents a meaningful shift in how AI is integrated into the delivery lifecycle — moving from single-turn chat to orchestrated, human-approved sequences. Worth tracking as input to dev-platform strategy and AI tooling evaluation, but no strategic decision is forced by this release.
  • Signals: GA announcement
2026-07-13 · Releases: jenkins · source ↗ #jenkins#security#ci-cd
  • Platform/SRE — Skip
  • CI/CD — Plan: Two deserialization restrictions (COWL/PersistedList and Object fields by default) are meaningful security hardening in the Jenkins controller; review whether your instance is affected and schedule an upgrade within your normal maintenance window.
  • Leader — Skip
2026-07-13 · Releases: jenkins · source ↗ #jenkins#ci-cd#breaking-change
  • Platform/SRE — Skip
  • CI/CD — Plan: Jenkins 2.568.1 carries a breaking-change flag; review the upgrade guide before updating your Jenkins controller to avoid pipeline or configuration regressions.
  • Leader — Skip
  • Signals: breaking-change flagged
  • Platform/SRE — Learn: Introduces an emerging practice of per-pod and per-pipeline emissions visibility, which could inform infrastructure sizing decisions, but no operational urgency and no signals anchoring an action today.
  • CI/CD — Learn: Eco CI and Carmen are wirable into existing GitLab pipelines today as lightweight integrations, worth evaluating as a team sustainability metric, but no deprecation, supply-chain risk, or deadline makes this actionable now.
  • Leader — Learn: Relevant for teams building ESG or sustainability reporting into engineering KPIs, but no licensing change, cost impact, or vendor risk forces a strategic decision — shapes future golden-path thinking only.