• Datadog's Real User Monitoring (RUM) package has an API that can lead to sensitive user data being accidentally sent to unintended domains. The "site" parameter can be confusing - developers can easily mistake it for their website domain. Instead of defaulting to Datadog's data intake domains, the RUM package constructs a new domain based on the provided "site" value, which could potentially send data to a domain the developer doesn't control. This happened to a company called Corporate Clash, where a misconfiguration led to user data being sent to an unauthorized third-party domain.

    Wednesday, April 10, 2024
  • GitLab currently has a market value of about $8 billion, more than the $7.5 billion Microsoft paid for GitHub in 2018.

  • It's not unusual to find a ratio of 25:1 between developers and ops people in modern software development environments. Giving developers the tools to succeed is more challenging than ever. This ebook, authored by Director of Software Architecture and Distinguished Engineer Christian Oestreich, covers 9 critical practices that enable developers to focus on writing high quality code. These include: Baking ops tasks into project bootstrapping, Building libraries to accelerate code instrumentation, Integrating reporting agents into hosts and containers, Automating platform compliance checks. To see the full list and a detailed explanation of each principle, download the full ebook from Datadog (free).