Security team keeps breaking our CI/CD
Posted by One_Animator5355@reddit | sysadmin | View on Reddit | 171 comments
Every time we try to deploy, security team has added 47 new scanning tools that take forever and fail on random shit.
Latest: they want us to scan every container image for vulnerabilities. Cool, except it takes 20 minutes per scan and fails if there's a 3-year-old openssl version that's not even exposed.
Meanwhile devs are pushing to prod directly because "the pipeline is broken again."
How do you balance security requirements with actually shipping code? Feel like we're optimizing for compliance BS instead of real security.
171 Comments
Budget-Consequence17@reddit
Luke_corner94@reddit
danokazooi@reddit
Far-Smile-2800@reddit
Far-Smile-2800@reddit
CanYouShowMeTheError@reddit
Separate_Forever_123@reddit
Unlucky-Work3678@reddit
Chvxt3r@reddit
badaz06@reddit
TheRealLambardi@reddit
Yupsec@reddit
TheRealLambardi@reddit
TheRealLambardi@reddit
yankdevil@reddit
Ssakaa@reddit
yankdevil@reddit
txstubby@reddit
ansibleloop@reddit
Ssakaa@reddit
ansibleloop@reddit
R_X_R@reddit
Ssakaa@reddit
pizzacake15@reddit
Lethalspartan76@reddit
Fun_Olive_6968@reddit
Hunter_Holding@reddit
Lethalspartan76@reddit
k_marts@reddit
R_X_R@reddit
BeanBagKing@reddit
ozzie286@reddit
NeverDocument@reddit
svv1tch@reddit
NetInfused@reddit
DoctorHathaway@reddit
NetInfused@reddit
Sieran@reddit
Ssakaa@reddit
tekno45@reddit
Ssakaa@reddit
TerrorsOfTheDark@reddit
Ssakaa@reddit
AcidRefleks@reddit
Ssakaa@reddit
Sad_Recommendation92@reddit
Silent_Title5109@reddit
Odd-Sun7447@reddit
kezow@reddit
dark_frog@reddit
niomosy@reddit
UninterestingSputnik@reddit
petrichorax@reddit
fresh-dork@reddit
AcidRefleks@reddit
MrSanford@reddit
niomosy@reddit
agent-squirrel@reddit
MrSanford@reddit
agent-squirrel@reddit
kuroimakina@reddit
MrSanford@reddit
agent-squirrel@reddit
kuroimakina@reddit
agent-squirrel@reddit
fuckedfinance@reddit
mkosmo@reddit
AliveInTheFuture@reddit
MendaciousFerret@reddit
petrichorax@reddit
mkosmo@reddit
Parking_Media@reddit
MrSanford@reddit
Internet-of-cruft@reddit
Odd-Sun7447@reddit
fuckedfinance@reddit
imnotonreddit2025@reddit
fuckedfinance@reddit
Hotshot55@reddit
rdesktop7@reddit
Odd-Sun7447@reddit
rdesktop7@reddit
Odd-Sun7447@reddit
pfak@reddit
fresh-dork@reddit
rdesktop7@reddit
fresh-dork@reddit
petrichorax@reddit
RFC_1925@reddit
disclosure5@reddit
ZealousidealTurn2211@reddit
petrichorax@reddit
ZealousidealTurn2211@reddit
petrichorax@reddit
ZealousidealTurn2211@reddit
petrichorax@reddit
UninterestingSputnik@reddit
goatsinhats@reddit
ConfusionFront8006@reddit
StefanAdams@reddit
altodor@reddit
BedSome8710@reddit
mirrax@reddit
NeppyMan@reddit
fedroxx@reddit
BeatMastaD@reddit
Ssakaa@reddit
Marathon2021@reddit
gosuexac@reddit
flummox1234@reddit
bageloid@reddit
flummox1234@reddit
OldSprinkles3733@reddit
AuroraFireflash@reddit
peakdecline@reddit
old_skul@reddit
mkosmo@reddit
matt0_0@reddit
mkosmo@reddit
Ssakaa@reddit
DevinSysAdmin@reddit
Nonaveragemonkey@reddit
Leif_Henderson@reddit
Zortrax_br@reddit
agent-squirrel@reddit
DellR610@reddit
BarracudaDefiant4702@reddit
petrichorax@reddit
SikhGamer@reddit
Awkward-Candle-4977@reddit
dedjedi@reddit
cozyHousecatWasTaken@reddit
heapsp@reddit
ChataEye@reddit
JWK3@reddit
Lofoten_@reddit
povlhp@reddit
arkatron5000@reddit
LordValgor@reddit
knightress_oxhide@reddit
New_Enthusiasm9053@reddit
I_ride_ostriches@reddit
AcidRefleks@reddit
Jmc_da_boss@reddit
Cold-Pineapple-8884@reddit
endfm@reddit
bulldg4life@reddit
trullaDE@reddit
fresh-dork@reddit
knightress_oxhide@reddit
BigBobFro@reddit
nefarious_bumpps@reddit
eagle6705@reddit
dean771@reddit
Intelligent_Ad4448@reddit
UninterestingSputnik@reddit
bbell6238@reddit
trisanachandler@reddit
cakefaice1@reddit
imnotonreddit2025@reddit
Helpjuice@reddit
patmorgan235@reddit
lightmatter501@reddit
Thorlas6@reddit
maziarczykk@reddit
dev_all_the_ops@reddit
Resident-Artichoke85@reddit
ThomasTrain87@reddit
brunozp@reddit
chesser45@reddit
Leucippus1@reddit