
55K
Downloads
111
Episodes
This is the show by and for DevSecOps practitioners who are trying to survive information overload, get through marketing nonsense, do the right technology bets, help their organizations to deliver value, and last but not the least to have some fun. Tune in for talks about technology, ways of working, and news from DevSecOps. This show is not sponsored by any technology vendor and trying to be as unbiased as possible. We talk like no one is listening! For good or bad :) For more info, show notes, and discussion of past and upcoming episodes visit devsecops.fm
Episodes

4 days ago
4 days ago
29 min
An agent asked to build a service found an Argo CD repository and deployed it to a cluster. Helpful automation gets harder to trust when a request leaves room for actions nobody intended.
Mattias Hemmingsson and Paulina Dubas discuss AI-assisted compliance checks, unexpected deployments, evolving guardrails, company AI bans and whether regulation improves transparency or prices smaller competitors out.
What you will learn
- How Claude turned AWS database checks into reusable audit evidence
- How an agent found a deployment path through Argo CD
- Why vague instructions and guardrail edge cases cause unwanted actions
- Why approving a hosted assistant does not make it local
- Where the hosts see benefits and competitive risks in regulation
Full article and show notes: https://devsecops.fm/episodes/111/

Sep 14, 2026
Sep 14, 2026
20 min
Why would a security improvement break a working deployment? Andrey questions the operational cost of GitHub’s OIDC change, while Mattias explains how repository renames can break AWS access. The hosts share a real incident involving a blocked account and discuss how to prepare for the change.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page

Sep 11, 2026
Sep 11, 2026
33 min
What changed in Docker while everyone was watching AI? The hosts review BuildKit, Buildx, security features, provenance, and the updates practitioners should know.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page

Sep 11, 2026
Sep 11, 2026
30 min
Are AI tools making software safer, or creating an endless patching treadmill? Mattias, Andrey, and Paulina discuss Dependabot, human review, and why teams should assume their software is already vulnerable.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page

Sep 11, 2026
Sep 11, 2026
30 min
CI changed how teams integrate code, but its core promise remains the same: integrate often and keep the mainline green. Andrey and Paulina trace its history and examine how Git, merge queues, and modern pipelines changed the mechanics.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page

Sep 11, 2026
Sep 11, 2026
40 min
This is a lighter summer episode about building things for yourself. The hosts talk personal projects, fitness data, AI agents, and the honest gap between having a smart plan and doing the work.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page

Sep 11, 2026
Sep 11, 2026
46 min
Are European LLMs good enough to protect company data without sacrificing capability? Pawel Piwosz, Filipe Berti, and Mark Shine discuss sovereignty, self-hosting costs, compliance, and the tooling Europe still needs.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page

Sep 11, 2026
Sep 11, 2026
33 min
Is flat-rate AI coding coming to an end? Mattias, Paulina, and Andrey discuss Copilot’s token billing, runaway API costs, and why an expensive model can sometimes be the cheaper choice.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page

Jun 14, 2026
Jun 14, 2026
56 min
Mark Shine, Pawel Piwosz, and Filipe Berti discuss why the default choice of AWS, Azure, or GCP is no longer automatic for every team. The conversation covers cost, managed services, open source, AI workloads, and what European cloud providers can offer instead.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page

Jun 4, 2026
Jun 4, 2026
51 min
What happens when AI can turn patches into exploits in hours? The hosts discuss why the 90-day disclosure window is breaking, what Mythos Preview changes, and why shipping vulnerable code is becoming more expensive.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page
