Automating compliance and security in pipelines
Compliance and security in line with multiple standards are required in many lines of business. The progression of compliance and security scanning has been a natural progression of the rise in popularity of pipelines, given their versatility, extensibility, and proximity to code. A rockstar SRE isn’t particularly interested in the scans themselves; however, the generated report can provide insight not only into the age of the code but also into the quality of its upkeep.
Library age
When SREs look at a code base, the age of the libraries being used can be an indicator of the upkeep of the code. As time progresses, often, operating systems, including those that are serverless, and containers are updated. I have witnessed libraries in production applications that were 5 or even 10 years old – and had lost compatibility with newer versions of operating systems and container images. In fact, if the container image version...