Digest #208: Axios Supply Chain Attack, Agentic Incident Response, LLMs on Kubernetes and VSCode Malwares
A critical axios npm compromise affecting millions of downloads, while teams began automating incident response with AI agents.
Welcome to this week’s edition of the DevOps Bulletin.
The Axios npm library was compromised through a targeted attack on the maintainer’s computer, exposing how vulnerable open-source projects can be. At the same time, developers are switching from traditional SSH keys to certificates for better security, and attackers are using fake VS Code alerts on GitHub to trick developers into clicking malicious links.
On the practical side, teams are using AI agents to automatically respond to incidents, securing LLM running on Kubernetes against injection attacks and model tampering, and learning how to use AWS KMS to mitigate ransomware attacks. Plus guides on running Terraform generation locally with open source tools, using Atlantis and GitHub Actions together for infrastructure changes, and securing Kubernetes clusters for payment compliance.
This week’s open source picks include SQLite with built-in JSON and search features; rpg, a Postgres client with AI built in; zerobox, a tool to safely run untrusted code; and argo-rollouts for smoother Kubernetes deployments. Plus coasts for running isolated development environments, databend for analytics and AI, and nushell for a better shell.
All this and more in this week’s DevOps Bulletin, don’t miss out!
Is your infrastructure keeping pace with AI?
IaCConf 2026 is the annual virtual event for all things infrastructure-as-code. This year's theme: keeping pace. Hear real stories from practitioners, demos of what platform teams are building, and discussions from those leading IaC initiatives.
Newsworthy stories
Tutorials of the week
Enjoying the Bulletin? Consider supporting it with a paid subscription. You’ll keep the free Friday issues and get extras like bonus deep-dives, templates, and the full archive.
Videos of the week
Projects of the week
rpg is a PostgreSQL terminal client written in Rust that brings AI diagnostics and schema-aware completion to psql, with 15+ DBA tools built in.
zerobox is a cross-platform process sandbox in Rust that restricts file, network, and credential access for safely running AI-generated code.
argo-rollouts is a Kubernetes controller enabling blue-green, canary, and progressive delivery strategies with automated metric-driven promotion.
agents-anywhere syncs AI agent configs, skills, and instructions across 10+ tools (Claude Code, Cursor, Windsurf, Gemini) from a single git repo.
coasts runs isolated development environments in containerized worktrees on a single machine with a local observability UI, integrating with existing Docker Compose setups.
nushell is a shell written in Rust that treats data as structured objects instead of text streams, enabling more powerful pipelines and type-aware operations.
Meme of the week
If you have feedback to share or are interested in sponsoring this newsletter, feel free to reach out via LinkedIn or simply reply to this email.






