🚨 ALERT! 🚨 Yet another "critical vulnerability" discovered by Wiz Kids who somehow managed to "infiltrate" #AWS via a misconfiguration in #CodeBuild. 🤔 Meanwhile, AWS is still wondering what GitHub is for... debugging? 😜
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild #criticalvulnerability #WizKids #cybersecurity #HackerNews #ngated
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog

Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.

wiz.io
@kolaente @pluralistic

Honestly, my company has shit spread out across Git service-providers (
#GitHub, #GitLab, #CodeCommit & #CodeBuild, etc.).

We'd switched to GitHub Actions because ones we'd previously used (e.g.,
#TravisCI) went from being free to being for pay …and there were still free alternatives (that, bonus, worked more-reliably).

This is just going to push more people towards running self-hosted GitLab with self-hosted runners.
DBスキーマ管理をシンプルに保つsqldefという選択肢 - Qiita

はじめに SapeetでSWEをやっている久保田です。 今回はプロダクトの立ち上げに際してDBスキーマ管理にsqldefを採用した経緯と、sqldefをCIへ統合し、RDSへのマイグレーションを簡単に適用するプラクティスを紹介します。 sqldefを使うことで得ることが...

Qiita

My latest blog post is now live! I've taken the content from my presentation on test automation and AWS (ŚlonzaczQA 2024) and created a comprehensive guide on building efficient CI/CD pipelines.

The article explores how to use AWS #CodeBuild and AWS #CodePipeline to overcome the challenges of local testing and streamline your QA process.

Read the full article to learn how to:

👉Automate your testing and deployments.

👉Reduce costs by leveraging cloud resources.

👉Implement Infrastructure as Code (IaC) for consistent environments.

https://tomisoft.dev/blog/03_cicd/

#AWS #DevOps #CI/CD #TestAutomation #CodePipeline #CodeBuild

コンテナイメージをGitHub Actions+CodeBuildでビルドする - Qiita

tl;dr GitHub Actionsのプライベートリポジトリでarm64ランナーを使うためにはSelf-Hosted Runnerの設定が必要(2025年6月現在) AWSの場合は、CodeBuildがSelf-Hosted Runner向けの設定をサポートしている...

Qiita

CodeBuild supports custom keys for S3 caching
https://aws.amazon.com/about-aws/whats-new/2025/03/aws-codebuild-custom-cache-keys-s3-caching/
You can define custom cache keys for granular cache management and better cache persistence. You can also share the keys across projects to use a common dependency cache to speed up your builds.

Also, it added support for fallback keys, which allows partial matches when an exact key is not found. This capability enables efficient caching sharing between similar builds, such as builds with common dependencies.
#AWS #CodeBuild

AWS CodeBuild now supports custom cache keys for S3 caching - AWS

Discover more about what's new at AWS with AWS CodeBuild now supports custom cache keys for S3 caching

Amazon Web Services, Inc.

AWS CodeBuild now supports parallel test execution!

🚀 Speed up CI pipelines by running tests in parallel—less waiting, faster feedback.

Details here:
🔗 https://aws.amazon.com/blogs/aws/accelerating-ci-with-aws-codebuild-parallel-test-execution-now-available/?trk=4b29643c-e00f-4ab6-ab9c-b1fb47aa1708&sc_channel=sm

#AWS #CodeBuild #CI #DevOps #Testing

Accelerating CI with AWS CodeBuild: Parallel test execution now available | Amazon Web Services

Speed up build times on CodeBuild with test splitting across multiple parallel build environments. Read how test splitting with CodeBuild works and how to get started.

Amazon Web Services

#AWS #CodeBuild now supports parallel test execution, so you can run your test suites concurrently and reduce build times significantly

https://aws.amazon.com/blogs/aws/accelerating-ci-with-aws-codebuild-parallel-test-execution-now-available/

Accelerating CI with AWS CodeBuild: Parallel test execution now available | Amazon Web Services

Speed up build times on CodeBuild with test splitting across multiple parallel build environments. Read how test splitting with CodeBuild works and how to get started.

Amazon Web Services

After many failed attempts, we finally have something working. The documentation around this is terrible, and trying to work things out from other example posts on the internet that aren't quite the same.

Planning to write up something more concrete with actual terraform for both sides.

Kudos to my colleague William Grant who helped push this through with is code diving into the google cloud client libraries.

#aws #gcp #wif #codebuild

Some more new goodies on AWS CodePipeline/CodeBuild
• New CodePipeline console experience for viewing pipeline releases https://aws.amazon.com/about-aws/whats-new/2025/02/aws-codepipeline-console-experience-viewing-pipeline-releases/
• CodeBuild supports merging parallel test reports and new compute options https://aws.amazon.com/about-aws/whats-new/2025/02/aws-codebuild-merging-parallel-test-reports-compute-options/
• CodeBuild supports managed webhooks in GitHub Enterprise https://aws.amazon.com/about-aws/whats-new/2025/02/aws-codebuild-managed-webhooks-github-enterprise/
• CodeBuild supports managed runners for GitLab Self-Managed https://aws.amazon.com/about-aws/whats-new/2025/02/aws-codebuild-managed-runners-gitlab-self-managed/
#AWS #CodePipeline #CodeBuild
AWS CodePipeline introduces new console experience for viewing pipeline releases - AWS

Discover more about what's new at AWS with AWS CodePipeline introduces new console experience for viewing pipeline releases

Amazon Web Services, Inc.