Using Git for a compliance audit trailKosli is a DevOps change management platform for storing a record of compliance controls. It helps financial institutions, medical device manufacturers, automotive and other mission-critical development teams to prove conformance to their software pr...Jan 27, 2023·4 min read
How to secure your software supply chain with Artifact Binary ProvenanceIn Kosli, we use Artifact Binary Provenance as the foundation for our audit trails. Artifact Binary Provenance is a fancy term, but the idea behind it is really quite simple. All it means is that we can identify the software we have running in produc...Jan 27, 2023·3 min read
How to design a DevOps Compliance System of RecordIf you deliver software in a regulated industry you have to be able to show that you are following a defined process. And that means being able to produce a record of what’s going on in your DevOps workflows. When we have conversations about DevOps c...Jan 27, 2023·4 min read
5 reasons why your CI system is a terrible Compliance System of Record“Why can’t we use our CI system for our Compliance System of Record (CSoR)?” This is a question we get asked a lot when we’re talking about compliance with regulated DevOps teams. And it’s a perfectly reasonable question to ask. If Jenkins, GitLab, G...Jan 27, 2023·4 min read
Why developers need a DevOps databaseCan you imagine developing software without version control? What if I told you that we were doing exactly the same thing with DevOps? In this article I’ll explain why developers need a database for DevOps, and make the case that it should have simil...Jan 27, 2023·6 min read
Git and the benefits and challenges of everything-as-codeGit has been a central part of the DevOps story. Our continuous integration systems run builds, produce artifacts, execute tests, and ultimately deploy systems defined as code in our git repositories. More recently, GitOps has extended the reach of g...Jan 27, 2023·5 min read
Review: Investments Unlimited - A Novel about DevOps, Security, Audit Compliance, and Thriving in the Digital Age“You know, it may feel like regulators are out to get us, but they’re really there to help us and help protect our customers.” If you’re into DevOps there’s a pretty good chance at least one book from IT Revolution sits on your shelf. Headed up by Ge...Jan 27, 2023·3 min read