Digest #227: Terabytes of credentials leaked in a supply chain attack, Figma's security agents, Kubernetes validation cut to 2 minutes and Docker's win that killed the company
Also inside: a Lambda that spiked an AWS bill 1,200% in one weekend, and why cloning a coding-agent repo runs code before your first prompt.
This week’s supply chain attack didn’t drain one company’s secrets, it dumped terabytes of credentials scraped from thousands of repositories into the open. Figma’s answer to that class of noise is a fleet of agents that triage alerts, query security data and write the fix, which cut their resolution time by 71%. One SRE team applied the same instinct to Kubernetes and pulled release validation from 45 minutes down to 2, and if you want a reminder that owning the tech is not the same as winning, the Docker video below is the best bedtime story of the year.
See how PayFit promotes infra and app releases through one pipeline
Join us on September 2 (Wed) to learn how PayFit’s platform team promotes every release the same way, Kubernetes services and Lambda functions alike. One path for app and infrastructure changes, so a release candidate proves itself before the next environment. It’s how PayFit ships payroll for 22,000+ businesses - Save your seat
If you’re interested in sponsoring this newsletter, feel free to reach out via LinkedIn or simply reply to this email.
Newsworthy stories
Tutorials of the week
Track generative AI costs with Amazon Bedrock inference profiles
Pulling multi-gigabyte container images in seconds on Amazon EKS
Before the first prompt: code execution paths in trusted coding-agent projects
Videos of the week
Projects of the week
OpenCodeReview reviews pull requests from the command line and leaves line-level comments.
sqlfmt formats PostgreSQL queries the way gofmt formats code, aligning clause keywords on a single column.
GoAccess analyzes web server logs in real time from your terminal or the browser.
git-knife edits every commit’s message, author, and dates in a table you can click through.
bsdkrun boots BSD guests, Linux OCI images, and unikernels as microVMs on macOS and Linux, with no daemon running underneath.
Cloudflare Computer provides agents with a virtual filesystem and swappable execution backends within a Durable Object.
Meme of the week
Terabytes of credentials are now public, so I am curious where you actually stand: do you rotate CI tokens every deploy, every quarter, or only after an incident?






