並び順

ブックマーク数

期間指定

  • から
  • まで

1 - 40 件 / 497件

新着順 人気順

environments github apiの検索結果1 - 40 件 / 497件

  • 実務で使っているClaude Codeの開発環境の紹介

    GA technologiesでバックエンドエンジニアをしている中坂です。今回は私が実務で実際に使っているClaude Codeの開発環境について紹介します。 はじめに 弊社には多くのプロダクトが存在します。その中でも私が所属しているチームでは各プロダクトを横断的に扱う必要があり、時には複数のリポジトリを往来しながら開発を進める必要があります。 このような環境でClaude Codeを活用する際、単一リポジトリでの開発とは異なる工夫も必要になります。本記事では、このような環境で約1ヶ月間Claude Codeを業務で使用してきた経験をもとに、複数プロダクト環境で開発を効率的に進めるための開発環境の構築方法を紹介します。 全体構成 まず、私が構築した開発環境の全体像を紹介します。 workspace/ ├── proj_a/ # サービスA ├── proj_b/ # サービスB ├── p

      実務で使っているClaude Codeの開発環境の紹介
    • エンジニア全員が Terraform を安心・安全に触れるような仕組みを整えています - VISASQ Dev Blog

      はじめに こんにちは!DPE(Developer Productivity Engineering)チームの高畑です。 ちょっと前に iPhone 15 Pro に変えてようやく USB-C ケーブルに統一できる!と思っていたら、手元にある Magic Trackpad が Lightning ケーブルでしょんぼりしました。 さて今回は、ビザスクのインフラ周りで利用している Terraform をエンジニア全員が安心・安全に利用できる仕組みづくりを行なっている話をしていきます! これまで ビザスクではインフラの構築・運用に Terraform を利用しており、依頼ベースで DPE のメンバーが Terraform の修正を行なってレビュー&リリースをしていました。 開発メンバーから Terraform の PR をあげてもらうこともありますが、plan / apply の権限を持っていない

        エンジニア全員が Terraform を安心・安全に触れるような仕組みを整えています - VISASQ Dev Blog
      • ついに最強のCI/CDが完成した 〜巨大リポジトリで各チームが独立して・安全に・高速にリリースする〜 - ZOZO TECH BLOG

        こんにちは。SRE部の巣立(@ksudate)です。 我々のチームでは、AWS上で多数のマイクロサービスを構築・運用しています。マイクロサービスが増えるにつれて、CI/CDの長期化やリリース手法の分散など様々な課題に直面しました。 本記事では、それらの課題をどのように解決したのかを紹介します。 目次 目次 はじめに CI/CDのこれまで Release PRによるリリース CI/CD実行時間の長期化 マイクロサービスごとのリリースが難しい リリーサーの制限ができない ドメイン単位の並行リリース リリース手法が分散する ブランチ間の同期が必要 パイプラインの増加 CI/CD実行時間の長期化 リリーサーを制限できない CI/CDの刷新 高速かつシンプルなCIパイプライン 変更差分を利用したCIパイプラインの実行 承認機能付きのCDパイプライン GitHub Environmentsによるリリー

          ついに最強のCI/CDが完成した 〜巨大リポジトリで各チームが独立して・安全に・高速にリリースする〜 - ZOZO TECH BLOG
        • Claude Code Best Practices

          Published Apr 18, 2025 Claude Code is a command line tool for agentic coding. This post covers tips and tricks that have proven effective for using Claude Code across various codebases, languages, and environments. We recently released Claude Code, a command line tool for agentic coding. Developed as a research project, Claude Code gives Anthropic engineers and researchers a more native way to int

            Claude Code Best Practices
          • Lambda の運用面でのベストプラクティスを学べる「AWS Lambda Operator Guide」を読んだ - kakakakakku blog

            AWS の公式ドキュメント「AWS Lambda Operator Guide」を読んだ❗️AWS Lambda を軸にサーバーレスアプリケーションを構築するときに意識しておくべき "運用面のポイント・ベストプラクティス" がまとまっていて,とても良いドキュメントだった👏 内容的には AWS Well-Architected Framework: Serverless Applications Lens と重複するところもあるけど,サーバーレスアプリケーションを開発・運用しているなら1度は読んでおくと良いのではないでしょうか❗️ \( 'ω')/ 多くの人に読みやすくなるように日本語翻訳もあるとイイなぁ〜 docs.aws.amazon.com 構成 ドキュメントとしては全6章で構成されている.どれも重要で,理解を深めるために読むのはもちろん,開発中もしくは運用中のアプリケーションに対し

              Lambda の運用面でのベストプラクティスを学べる「AWS Lambda Operator Guide」を読んだ - kakakakakku blog
            • Claude Code: Best Practices and Pro Tips

              This guide provides tips and tricks for effectively using Claude Code, a command-line tool for agentic coding. Using Claude Code as a Bash CLI Claude Code (often invoked as claude or cc) can be used similarly to other bash-based command-line interfaces. Use CC as a bash CLI You can perform many standard command-line operations. For example, to checkout a new branch and lint the project: claude "ch

                Claude Code: Best Practices and Pro Tips
              • ChatGPT Pro は高いので Codex + GitHub Copilot でお小遣いを守りたい - Qiita

                Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? AI 関連サービスの使いすぎでお小遣いがピンチです。贅沢に ChatGPT Pro を契約して遠慮なく使いたい所ですが、ちょっとでも節約した使い方が出来ないか思考を巡らせてみました。 最近は Coding Agent の選択肢も豊富です。そもそも Codex にこだわらなければ他にもより安価なサブスクリプションはありますが、ここではそれは触れません。私よりもお小遣いが厳しい方は私の記事を読むよりは以下のような Coding Agent を検索しても良いでしょう。 色々な Coding Agent Claude Code (高ぇ) Ope

                  ChatGPT Pro は高いので Codex + GitHub Copilot でお小遣いを守りたい - Qiita
                • Next.jsをVercelからCloudflareへ移行し、90%のコスト削減を実現した話 - Hello Tech

                  酒井です。ハローでは、プロダクトのローンチ前からAutoReserveの開発に関わっています。 この記事では、Next.jsアプリケーションであるautoreserve.comをVercelからCloudflareに移行し、月額コストを約90%削減した背景と実装の詳細を共有します。 Next.jsは比較的セルフホスティングが難しいフレームワークとして知られており、Vercelへのベンダーロックインが懸念されることがあります。Next.js 16でBuild Adapters APIが導入されるなど、セルフホスティングのハードルは徐々に下がっていますが、実運用では課題が多いのが現状です。 VercelからOpenNext + Cloudflare Workersの構成に本番環境を移行したため、現場でのNext.jsのセルフホスティングの実際について紹介できればと思います。 背景 AutoRe

                    Next.jsをVercelからCloudflareへ移行し、90%のコスト削減を実現した話 - Hello Tech
                  • 『GitHub CI/CD実践ガイド』でGitHub ActionsとCI/CDを体系的に学ぼう - 憂鬱な世界にネコパンチ!

                    『GitHub CI/CD実践ガイド――持続可能なソフトウェア開発を支えるGitHub Actionsの設計と運用』という書籍を最近出版したので紹介します。本書ではGitHub Actionsの実装と、CI/CDの設計・運用を体系的に学べます。一粒で二度美味しい書籍です。筆者個人としては「実践Terraform」以来、4年半ぶりの商業出版になります。 gihyo.jp どんな本? GitHub利用者にとって、もっとも導入が容易なCI/CD向けのソリューションはGitHub Actionsです。GitHub Actionsの活用事例は多く、検索すればたくさん情報が出てきます。ただ断片的な情報には事欠かない反面、体系的に学習する方法は意外とありません。CI/CD自体がソフトウェア開発の主役になることもまずないため、なんとなく運用している人が大半でしょう。そこで執筆したのが『GitHub CI/

                      『GitHub CI/CD実践ガイド』でGitHub ActionsとCI/CDを体系的に学ぼう - 憂鬱な世界にネコパンチ!
                    • Terraform職人のためのOpenTofu入門 - Qiita

                      Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? この記事は クラウドワークス Advent Calendar 2023 シリーズ1 の 4日目の記事です。 はじめに 「父さんな、Terraform職人やめてお豆腐職人で食っていこうと思うんだ」と言いたいだけの @minamijoyo です。 2023年8月HashiCorpはこれまでMPL2のOSSライセンスで公開していた主要製品をBSL(Business Source License)に変更することを発表し、Terraformはv1.6.0からOSSではなくなりました。 このライセンス変更を受けて、OSS版のTerraformを求め

                        Terraform職人のためのOpenTofu入門 - Qiita
                      • Go Scheduler

                        Go Scheduler Contents Introduction Compilation and Go Runtime Primitive Scheduler Scheduler Enhancement GMP Model Program Bootstrap Creating a Goroutine Schedule Loop Finding a Runnable Goroutine Goroutine Preemption Handling System Calls Network I/O and File I/O How netpoll Works Garbage Collector Common Functions Go Runtime APIs Disclaimer This blog post primarily focuses on Go 1.24 programming

                          Go Scheduler
                        • CircleCI incident report for January 4, 2023 security incident - CircleCI

                          CircleCI incident report for January 4, 2023 security incident On January 4, 2023, we alerted customers to a security incident. Today, we want to share with you what happened, what we’ve learned, and what our plans are to continuously improve our security posture for the future. We would like to thank our customers for your attention to rotating and revoking secrets, and apologize for any disrupti

                            CircleCI incident report for January 4, 2023 security incident - CircleCI
                          • CircleCI security alert: Rotate any secrets stored in CircleCI (Updated Jan 13) - CircleCI

                            CircleCI security alert: Rotate any secrets stored in CircleCI (Updated Jan 13) Security update 01/13/2023 - 21:25 UTC Our full incident report is now available. Read the Report Security update 01/12/2023 - 00:30 UTC We have partnered with AWS to help notify all CircleCI customers whose AWS tokens may have been impacted as part of this security incident. Today, AWS began alerting customers via ema

                              CircleCI security alert: Rotate any secrets stored in CircleCI (Updated Jan 13) - CircleCI
                            • OpenAIのBatch APIを使ってお得にプロンプトを一括処理してみる - Taste of Tech Topics

                              はじめに こんにちは。データサイエンスチームYAMALEXのSsk1029Takashiです。 最近はOpenAIに日本支社が出来て、日本語対応が加速するというニュースにわくわくしています。 今回はそんなOpenAIから発表されたBatch APIという機能が便利、かつお得な機能だったのでどのように使えるのか試してみます。 Introducing the Batch API: save costs and get higher rate limits on async tasks (such as summarization, translation, and image classification). Just upload a file of bulk requests, receive results within 24 hours, and get 50% off API pri

                                OpenAIのBatch APIを使ってお得にプロンプトを一括処理してみる - Taste of Tech Topics
                              • act: GitHub Actions のワークフローをローカル環境で実行する - kakakakakku blog

                                GitHub Actions でワークフローを実行するときに git commit と git push を実行して GitHub Actions の実行を待つことがよくある.より迅速に実行して,結果を受け取るために「act」を使って GitHub Actions をローカル環境(コンテナ)で実行する仕組みを試してみた.便利だったので紹介しようと思う❗️ 当然ながら GitHub Actions を完全再現できてるわけではなく,最終的には GitHub Actions を使うことにはなるけど,特に開発中に頻繁にテストを実行できるのはメリットだと思う.うまく併用しながら開発体験を高めよう👌 github.com セットアップ macOS の場合は Homebrew を使って簡単にセットアップできる.他には Chocolatey (Windows) や Bash script も選べる.今回

                                  act: GitHub Actions のワークフローをローカル環境で実行する - kakakakakku blog
                                • neue cc - ゼロアロケーションLINQライブラリ「ZLinq」のリリースとアーキテクチャ解説

                                  ゼロアロケーションLINQライブラリ「ZLinq」のリリースとアーキテクチャ解説 2025-05-05 ZLinq v1を先月リリースしました!structとgenericsベースで構築することによりゼロアロケーションを達成しています。またLINQ to Span, LINQ to SIMD, LINQ to Tree(FileSystem, JSON, GameObject, etc.)といった拡張要素と、任意の型のDrop-in replacement Source Generator。そして.NET Standard 2.0, Unity, Godotなどの多くのプラットフォームサポートまで含めた大型のライブラリとなっています!現在GitHub Starsも2000を超えました。 https://github.com/Cysharp/ZLinq structベースのLINQそのものは

                                  • GitHub CI/CD実践ガイド | 技術評論社

                                    概要 本書はCI/CDの設計や運用について、GitHubを使ってハンズオン形式で学ぶ書籍です。GitHub Actionsの基本構文からスタートし、テスト・静的解析・リリース・コンテナデプロイなどを実際に自動化していきます。あわせてDependabot・OpenID Connect・継続的なセキュリティ改善・GitHub Appsのような、実運用に欠かせないプラクティスも多数習得します。 実装しながら設計や運用の考え方を学ぶことで、品質の高いソフトウェアをすばやく届けるスキルが身につきます。GitHubを利用しているなら、ぜひ手元に置いておきたい一冊です。 こんな方にオススメ GitHubは使っているけれど、プルリクエストぐらいしか利用していない CI/CDというキーワードは知っているけれど、自分で設計したことはない GitHub Actionsには触れているけれど、正直雰囲気で運用してい

                                      GitHub CI/CD実践ガイド | 技術評論社
                                    • RemixでAWSサーバレス構成を手軽に作成できるGrunge Stackを試してみた | DevelopersIO

                                      はじめに こんにちは、CX事業本部MAD事業部の森茂です。 先日リリースされたRemix Stacks、Remixチームが公開しているAWSを利用したサーバレス構成のGrunge Stackテンプレートがどのような構成になっているのかを調べるために早速デプロイまでの流れを試してみました。 Grunge Stack Grunge StackはAWSを利用したサーバレス構成のアプリケーションテンプレートです。サーバレスフレームワークとしてはArchitectを利用しています。データベースにはDynamoDBを利用し、アプリケーションはCloudFormationを利用してLambdaへデプロイされAPI Gatewayを介して公開されます。また開発用にローカル環境のサンドボックス環境も用意されているのでAWS環境へデプロイせずに動作を確認することが可能です。(サンドボックス環境のDynamoD

                                        RemixでAWSサーバレス構成を手軽に作成できるGrunge Stackを試してみた | DevelopersIO
                                      • 実録!GitHub Enterprise Cloud 導入 〜コスト増を乗り越えたわけ〜 - Leverages Tech Blog

                                        はじめに こんにちは!レバレジーズ株式会社テクノロジー戦略室SREチームの竹村です。 テクノロジー戦略室のSREチームでは、全社のエンジニアの開発生産性の向上やシステムの信頼性向上に取り組んでいます。 エンジニアの生産性向上や工数削減を叶えるため、2024年にレバレジーズの開発組織全体で、GitHub Enterprise Cloud(GHEC) への移行を行いました。 今回は、複数の施策を積み上げることで、コスト増を上回るメリットを示し、導入に至った経緯を赤裸々に皆さんにお届けできればと思います!GHEC以外のサービス導入検討の参考にもなると思うので、何か新しいサービスやプランアップを検討されているかたもご一読いただけると幸いです。 苦労したポイント! GHEC への移行・導入にあたっての一番苦労したポイントはやはり、大幅なコスト増をまわりに理解してもらうことでした。多くの高度な機能が利

                                          実録!GitHub Enterprise Cloud 導入 〜コスト増を乗り越えたわけ〜 - Leverages Tech Blog
                                        • Announcing TypeScript 7.0 - TypeScript

                                          As you can see, these codebases get a better speedup from dedicating more cores, but results will differ across projects and underlying machines. On the other hand, on machines with fewer CPU cores and less memory (e.g. CI runners) you may want to decrease this number to avoid unnecessary or incidental overhead. You can specify a value as low as --checkers 1, effectively making type-checking singl

                                            Announcing TypeScript 7.0 - TypeScript
                                          • MCPアーキテクチャパターン - Carpe Diem

                                            背景 MCP(Model Context Protocol)を使う上で、ローカルMCPサーバやリモートMCPサーバ、更にはそれらを集中管理するゲートウェイ的なサービスもあったりと複雑だと感じたので、それぞれのパターンを一度洗い出してみました。 事前知識 MCP(Model Context Protocol)とは MCPとは AI <-> 外部データソース連携 の為の標準規格で、Claude Codeを出しているAnthropicが標準化しました。 MCP Clientの例 よくある例は次のようなAIエディターです。 Cline(VS Code) Cursor Claude Code Windsurf もちろん自前でMCP Clientを作ることも可能です。 生成AIを組み込んだチャットボットなどが外部リソースにアクセスしたいときなどですね。 MCP Serverの例 開発でよく使われる例と

                                              MCPアーキテクチャパターン - Carpe Diem
                                            • Countering misuse of AI: September 2026 / Anthropic

                                              Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. In each case, we disrupted the activity, used what we le

                                                Countering misuse of AI: September 2026 / Anthropic
                                              • WSL containers is now generally available

                                                WSL is central to our commitment to making Windows the best place to build, run and manage Linux workloads. As AI, cloud-native development, containers, and open-source ecosystems continue to converge on Linux, more developers are choosing to perform these workloads directly on Windows devices. We’re continuing our journey towards this goal with a new feature in WSL: WSL containers, which is gener

                                                  WSL containers is now generally available
                                                • Platform Engineering on Kubernetes を読んでCloud Native の現在地を理解する - じゃあ、おうちで学べる

                                                  はじめに 近年、Kubernetesの採用が進む中、複数のチームが関わり、複数のクラウドプロバイダーへのデプロイを行い、異なるスタックを扱う組織では、その導入の複雑さが新たな問題となっています。本書 『Platform Engineering on Kubernetes』は、Kubernetes に登場しつつあるベストプラクティスとオープンソースツールを活用し、これらのクラウドネイティブの問題を技術的に組織的にどのように解決するかを示してくれます。 learning.oreilly.com 本書では、Kubernetes上に優れたプラットフォームを構築するための要素を明確に定義し、組織の要件に合わせて必要なツールを体系的に紹介しており、実際の例とコードを交えながら各ステップをわかりやすく説明することで、最終的にはクラウドネイティブなソフトウェアを効率的に提供するための完全なプラットフォーム

                                                    Platform Engineering on Kubernetes を読んでCloud Native の現在地を理解する - じゃあ、おうちで学べる
                                                  • 【2024年】AWS全サービスまとめ | DevelopersIO

                                                    こんにちは。サービス開発室の武田です。このエントリは、2018年から毎年公開しているAWS全サービスまとめの2024年版です。 こんにちは。サービス開発室の武田です。 このエントリは、2018年から毎年公開している AWS全サービスまとめの2024年版 です。昨年までのものは次のリンクからたどってください。 AWSにはたくさんのサービスがありますが、「結局このサービスってなんなの?」という疑問を自分なりに理解するためにまとめました。 今回もマネジメントコンソールを開き、「サービス」の一覧をもとに一覧化しました。そのため、プレビュー版など一覧に載っていないサービスは含まれていません。また2023年にまとめたもののアップデート版ということで、新しくカテゴリに追加されたサービスには[New]、文章を更新したものには[Update]を付けました。ちなみにサービス数は 247個 です。 まとめるにあ

                                                      【2024年】AWS全サービスまとめ | DevelopersIO
                                                    • コーディングエージェント向けのリモートサンドボックス

                                                      コーディングエージェントの普及にともない、エージェントをリモートで動作させるための専用開発環境——リモートサンドボックスが注目されています。ここでいうサンドボックスとは、プロジェクトやエージェントごとに気軽に生成・破棄できるリモートVMのことで、exe.dev、Sprites、Docker Sandbox などのサービス・ツールが登場しています。 本記事ではこれらのリモートサンドボックスの用途を整理し、exe.dev・Sprites・Docker Sandboxの3つを比較します。 なぜ専用の開発環境が必要なのかコーディングエージェントをリモートで走らせる環境として、これまで一般的だった選択肢を列挙すると以下のようになります。 Mac miniやRaspberry Piを買って自宅サーバーを立てるVPS(Hetzner、さくらVPSなど)を契約するDevin、Claude Code on

                                                        コーディングエージェント向けのリモートサンドボックス
                                                      • Vite 8.0 is out!

                                                        Vite 8.0 is out! ​ March 12, 2026 We're thrilled to announce the stable release of Vite 8! When Vite first launched, we made a pragmatic bet on two bundlers: esbuild for speed during development, and Rollup for optimized production builds. That bet served us well for years. We're very grateful to the Rollup and esbuild maintainers. Vite wouldn't have succeeded without them. Today, it resolves into

                                                          Vite 8.0 is out!
                                                        • Amazon ECS と AWS Lambda で汎用 self-hosted runner を提供する基盤 - クックパッド開発者ブログ

                                                          技術部 SRE グループの @s4ichi です。ここ最近は本業に加えて Overwatch2 のヒーローとして戦いに明け暮れています。救わなければならないレートがある。 GitHub flow に従った開発では GitHub Actions が非常に便利です。特に最近では CI 用途だけでなく、ソフトウェアのデリバリーなども Actions で完結させる事例も見かけます。しかしながら、クックパッド社内では GitHub Enterprise Server を使っているため、GtiHub Actions の利用には self-hosted runnner の利用が不可欠になっています。 そこで、社内では Amazon ECS 上に ephemeral で汎用的な self-hosted runner を提供しています。実行する job の数に応じた autoscaling を備え、runn

                                                            Amazon ECS と AWS Lambda で汎用 self-hosted runner を提供する基盤 - クックパッド開発者ブログ
                                                          • Announcing TypeScript 6.0 - TypeScript

                                                            Today we are excited to announce the availability of TypeScript 6.0! If you are not familiar with TypeScript, it’s a language that builds on JavaScript by adding syntax for types, which enables type-checking to catch errors, and provide rich editor tooling. You can learn more about TypeScript and how to get started on the TypeScript website. But if you’re already familiar with the language, you ca

                                                              Announcing TypeScript 6.0 - TypeScript
                                                            • GitHub - modelcontextprotocol/servers: Model Context Protocol Servers

                                                              Official integrations are maintained by companies building production ready MCP servers for their platforms. 21st.dev Magic - Create crafted UI components inspired by the best 21st.dev design engineers. 2slides - An MCP server that provides tools to convert content into slides/PPT/presentation or generate slides/PPT/presentation with user intention. ActionKit by Paragon - Connect to 130+ SaaS inte

                                                                GitHub - modelcontextprotocol/servers: Model Context Protocol Servers
                                                              • Ultimate Guide to Visual Testing with Playwright

                                                                Ultimate Guide to Visual Testing with Playwright February 28, 2024 As your web app matures, it becomes challenging to ensure your GUI doesn’t break with any given update. There are a lot of browsers and devices, and countless states for every one of your components. Unit tests ensure your code remains consistent, and E2E tests will ensure your system remains consistent, but neither will catch visu

                                                                • Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages - StepSecurity

                                                                  Executive SummaryThe NPM ecosystem is facing another critical supply chain attack. The popular @ctrl/tinycolor package, which receives over 2 million weekly downloads, has been compromised along with more than 40 other packages across multiple maintainers. This attack demonstrates a concerning evolution in supply chain threats - the malware includes a self-propagating mechanism that automatically

                                                                    Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages - StepSecurity
                                                                  • Migrating to OpenTelemetry | Airplane

                                                                    At Airplane, we collect observability data from our own systems as well as remote “agents” that are running in our customers’ infrastructure. The associated outputs, which include the standard “three pillars of observability” (logs, metrics, and traces) are essential for us to monitor our infrastructure and also help customers debug problems in theirs. Over the last year, we’ve made a concerted ef

                                                                      Migrating to OpenTelemetry | Airplane
                                                                    • 保存版: Railsアプリケーションのセキュリティベストプラクティス(翻訳)|TechRacho by BPS株式会社

                                                                      概要 元サイトの許諾を得て翻訳・公開いたします。 英語記事: Security Best Practices for Your Rails Application | AppSignal Blog 原文公開日: 2022/10/05 原著者: Paweł Dąbrowski サイト: AppSignal Blog 参考: 週刊Railsウォッチ20221011 Railsのセキュリティベストプラクティス 日本語タイトルは内容に即したものにしました。原文の章インデントは訳文で一部を変更しています。 以下のRailsセキュリティガイドも合わせてお読みください。 参考: Rails セキュリティガイド - Railsガイド Webアプリケーションを構築するときは、パフォーマンスや使い勝手を重視するのはもちろんですが、セキュリティにも注目する必要があります。ハッキング手法は、技術の進化と変わらない

                                                                        保存版: Railsアプリケーションのセキュリティベストプラクティス(翻訳)|TechRacho by BPS株式会社
                                                                      • TerraformでGitHubを管理する - 10X Product Blog

                                                                        こんにちは、SREの@babarotです。 10Xでは GitHub Organization のリソースを Terraform で管理しています。メンバーの追加・削除、チーム構成、78リポジトリの設定(Repository Ruleset、アクセス権、GitHub Environments)など、可能な限りすべてコードで定義してPull Requestベースで変更・運用しています。 この仕組みで目指しているのは「SREだけが管理する」のではなく「誰でも安全に変更できるセルフサービス」です。メンバーの追加はtfvarsに1行足してPRを出すだけ、リポジトリの設定変更は各チームが自分でPRを出せる、新規リポジトリの作成はGitHub Actionsでリポジトリ名を入力するだけ、といったようなイメージです。ガバナンスとセルフサービスを両立する仕組みを、約2年かけて段階的に構築してきました。 こ

                                                                          TerraformでGitHubを管理する - 10X Product Blog
                                                                        • GitHub Actionsの脆弱な構成の検知ツール、任せられる範囲と人が見極めるべきリスク - GMO Flatt Security Blog

                                                                          はじめに こんにちは、GMO Flatt Security株式会社 セキュリティエンジニアの佐藤(@Nick_nick310)です。 これまで公開した記事にて、GitHub Actionsにおける攻撃手法や防御策、緩和策を解説してきました。 Vol.1: 相次ぐGitHub Actions 侵害から学ぶ、初期アクセス手法と開発者が知っておきたい対策 - GMO Flatt Security Blog Vol.2: GitHub Actions 認証情報ごとのリスクから読み解く、権限昇格パターンとその対策 - GMO Flatt Security Blog Vol.3: OIDC・Trusted Publishing でも残る、GitHub Actionsの認証情報の漏洩リスクと軽減策 - GMO Flatt Security Blog 一方で、個々の脆弱性パターンと対策を把握できたとしても

                                                                            GitHub Actionsの脆弱な構成の検知ツール、任せられる範囲と人が見極めるべきリスク - GMO Flatt Security Blog
                                                                          • GitHub - kysely-org/kysely: A type-safe TypeScript SQL query builder

                                                                            Kysely (pronounce “Key-Seh-Lee”) is a type-safe and autocompletion-friendly TypeScript SQL query builder. Inspired by Knex.js. Mainly developed for Node.js but also runs on all other JavaScript environments like Deno, Bun, Cloudflare Workers and web browsers. Kysely makes sure you only refer to tables and columns that are visible to the part of the query you're writing. The result type only has th

                                                                              GitHub - kysely-org/kysely: A type-safe TypeScript SQL query builder
                                                                            • Introducing workerd: the Open Source Workers runtime

                                                                              September 27, 2022Introducing workerd: the Open Source Workers runtime Today I'm proud to introduce the first beta release of workerd, the JavaScript/Wasm runtime based on the same code that powers Cloudflare Workers. workerd is Open Source under the Apache License version 2.0. workerd shares most of its code with the runtime that powers Cloudflare Workers, but with some changes designed to make i

                                                                                Introducing workerd: the Open Source Workers runtime
                                                                              • Fintech Engineering Handbook

                                                                                Fintech Engineering Handbook Patterns for building software that handles money Welcome to the Fintech Engineering Handbook. This resource aims to describe the most important patterns used in software engineering, where money is the primary focus of the system. It can be read in full to get a comprehensive understanding or in parts when dealing with a particular problem. For whom? People joining fi

                                                                                • Artifacts: versioned storage that speaks Git

                                                                                  Agents have changed how we think about source control, file systems, and persisting state. Developers and agents are generating more code than ever — more code will be written over the next 5 years than in all of programming history — and it’s driven an order-of-magnitude change in the scale of the systems needed to meet this demand. Source control platforms are especially struggling here: they we

                                                                                    Artifacts: versioned storage that speaks Git