<description>&lt;p&gt;This episode of &lt;strong&gt;Ship It Weekly&lt;/strong&gt; is about secrets, agents, risky defaults, and follow-up work that never gets done. Brian covers the CISA contractor GitHub leak involving AWS keys, internal docs, Terraform, Kubernetes, Argo CD, and CI/CD context, plus AWS DevOps Agent doing automated RCA across Datadog, Elasticsearch, CloudTrail, and EKS.&lt;/p&gt;&lt;p&gt;Brian also covers MS Copilot Studio computer-using agents, Claude Code in Bitbucket Agentic Pipelines, CVE-2026-46333 and Kubernetes seccomp defaults, GitHub OIDC for Dependabot, Java pods getting OOMKilled, LLM-generated SQL that can be wrong but still run, and why postmortem action items die without ownership.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Sponsored by Guardsquare &lt;/strong&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://hubs.ly/Q04fJgkJ0"&gt;&lt;strong&gt;https://hubs.ly/Q04fJgkJ0&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Links&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;CISA GitHub leak &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.gitguardian.com/how-we-got-a-cisa-github-leak-taken-down-in-26-hours/"&gt;https://blog.gitguardian.com/how-we-got-a-cisa-github-leak-taken-down-in-26-hours/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;AWS DevOps Agent RCA &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://aws.amazon.com/blogs/devops/automate-root-cause-analysis-across-datadog-and-elasticsearch-with-aws-devops-agent/"&gt;https://aws.amazon.com/blogs/devops/automate-root-cause-analysis-across-datadog-and-elasticsearch-with-aws-devops-agent/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Microsoft Copilot Studio computer-using agents &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://techcommunity.microsoft.com/blog/copilot-studio-blog/computer-using-agents-in-microsoft-copilot-studio-are-now-generally-available/4519427"&gt;https://techcommunity.microsoft.com/blog/copilot-studio-blog/computer-using-agents-in-microsoft-copilot-studio-are-now-generally-available/4519427&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Atlassian Agentic Pipelines with Claude Code &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://support.atlassian.com/bitbucket-cloud/docs/agentic-pipelines/"&gt;https://support.atlassian.com/bitbucket-cloud/docs/agentic-pipelines/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;CVE-2026-46333 &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://nvd.nist.gov/vuln/detail/CVE-2026-46333"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-46333&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Kubernetes seccomp &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://kubernetes.io/docs/reference/node/seccomp/"&gt;https://kubernetes.io/docs/reference/node/seccomp/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;GitHub OIDC for Dependabot and code scanning &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://github.blog/changelog/2026-05-19-expanded-oidc-support-for-dependabot-and-code-scanning/"&gt;https://github.blog/changelog/2026-05-19-expanded-oidc-support-for-dependabot-and-code-scanning/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Java pods OOMKilled in Kubernetes &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://dzone.com/articles/java-pod-oomkill-kubernetes"&gt;https://dzone.com/articles/java-pod-oomkill-kubernetes&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LLM-generated SQL risks &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://readyset.io/blog/why-llms-write-incorrect-sql-and-what-that-means-for-your-database"&gt;https://readyset.io/blog/why-llms-write-incorrect-sql-and-what-that-means-for-your-database&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Postmortem action items &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://incident.io/blog/why-do-post-mortem-action-items-fail-how-to-make-incident-follow-ups-actually-get-done"&gt;https://incident.io/blog/why-do-post-mortem-action-items-fail-how-to-make-incident-follow-ups-actually-get-done&lt;/a&gt;&lt;/p&gt;&lt;p&gt;On Call Brief &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://www.tellerstech.com/on-call-brief/2026-W21/"&gt;https://www.tellerstech.com/on-call-brief/2026-W21/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;More episodes + show notes &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://shipitweekly.fm/"&gt;https://shipitweekly.fm/&lt;/a&gt;&lt;/p&gt;</description>

Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News

Teller's Tech - DevOps, SRE and Cloud Podcast

CISA’s GitHub Leak, AI Root Cause Analysis, Copilot Agents, Claude Code in CI/CD, and Kubernetes Seccomp Risk

MAY 22, 202622 MIN
Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News

CISA’s GitHub Leak, AI Root Cause Analysis, Copilot Agents, Claude Code in CI/CD, and Kubernetes Seccomp Risk

MAY 22, 202622 MIN

Description

<p>This episode of <strong>Ship It Weekly</strong> is about secrets, agents, risky defaults, and follow-up work that never gets done. Brian covers the CISA contractor GitHub leak involving AWS keys, internal docs, Terraform, Kubernetes, Argo CD, and CI/CD context, plus AWS DevOps Agent doing automated RCA across Datadog, Elasticsearch, CloudTrail, and EKS.</p><p>Brian also covers MS Copilot Studio computer-using agents, Claude Code in Bitbucket Agentic Pipelines, CVE-2026-46333 and Kubernetes seccomp defaults, GitHub OIDC for Dependabot, Java pods getting OOMKilled, LLM-generated SQL that can be wrong but still run, and why postmortem action items die without ownership.</p><p></p><p><strong>Sponsored by Guardsquare </strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://hubs.ly/Q04fJgkJ0"><strong>https://hubs.ly/Q04fJgkJ0</strong></a></p><p></p><p><strong>Links</strong></p><p>CISA GitHub leak <a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.gitguardian.com/how-we-got-a-cisa-github-leak-taken-down-in-26-hours/">https://blog.gitguardian.com/how-we-got-a-cisa-github-leak-taken-down-in-26-hours/</a></p><p>AWS DevOps Agent RCA <a target="_blank" rel="noopener noreferrer nofollow" href="https://aws.amazon.com/blogs/devops/automate-root-cause-analysis-across-datadog-and-elasticsearch-with-aws-devops-agent/">https://aws.amazon.com/blogs/devops/automate-root-cause-analysis-across-datadog-and-elasticsearch-with-aws-devops-agent/</a></p><p>Microsoft Copilot Studio computer-using agents <a target="_blank" rel="noopener noreferrer nofollow" href="https://techcommunity.microsoft.com/blog/copilot-studio-blog/computer-using-agents-in-microsoft-copilot-studio-are-now-generally-available/4519427">https://techcommunity.microsoft.com/blog/copilot-studio-blog/computer-using-agents-in-microsoft-copilot-studio-are-now-generally-available/4519427</a></p><p>Atlassian Agentic Pipelines with Claude Code <a target="_blank" rel="noopener noreferrer nofollow" href="https://support.atlassian.com/bitbucket-cloud/docs/agentic-pipelines/">https://support.atlassian.com/bitbucket-cloud/docs/agentic-pipelines/</a></p><p>CVE-2026-46333 <a target="_blank" rel="noopener noreferrer nofollow" href="https://nvd.nist.gov/vuln/detail/CVE-2026-46333">https://nvd.nist.gov/vuln/detail/CVE-2026-46333</a></p><p>Kubernetes seccomp <a target="_blank" rel="noopener noreferrer nofollow" href="https://kubernetes.io/docs/reference/node/seccomp/">https://kubernetes.io/docs/reference/node/seccomp/</a></p><p>GitHub OIDC for Dependabot and code scanning <a target="_blank" rel="noopener noreferrer nofollow" href="https://github.blog/changelog/2026-05-19-expanded-oidc-support-for-dependabot-and-code-scanning/">https://github.blog/changelog/2026-05-19-expanded-oidc-support-for-dependabot-and-code-scanning/</a></p><p>Java pods OOMKilled in Kubernetes <a target="_blank" rel="noopener noreferrer nofollow" href="https://dzone.com/articles/java-pod-oomkill-kubernetes">https://dzone.com/articles/java-pod-oomkill-kubernetes</a></p><p>LLM-generated SQL risks <a target="_blank" rel="noopener noreferrer nofollow" href="https://readyset.io/blog/why-llms-write-incorrect-sql-and-what-that-means-for-your-database">https://readyset.io/blog/why-llms-write-incorrect-sql-and-what-that-means-for-your-database</a></p><p>Postmortem action items <a target="_blank" rel="noopener noreferrer nofollow" href="https://incident.io/blog/why-do-post-mortem-action-items-fail-how-to-make-incident-follow-ups-actually-get-done">https://incident.io/blog/why-do-post-mortem-action-items-fail-how-to-make-incident-follow-ups-actually-get-done</a></p><p>On Call Brief <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.tellerstech.com/on-call-brief/2026-W21/">https://www.tellerstech.com/on-call-brief/2026-W21/</a></p><p>More episodes + show notes <a target="_blank" rel="noopener noreferrer nofollow" href="https://shipitweekly.fm/">https://shipitweekly.fm/</a></p>