PolicyAsCode Blog

Insights and best practices from the policy-as-code community

Latest Post

GitOps Security: Enforcing Policy as Code in Flux and ArgoCD

A comprehensive guide to securing GitOps workflows with policy-as-code. Learn how to integrate OPA, Kyverno, and admission controllers with Flux and ArgoCD to prevent misconfigurations, enforce compliance, and automate security at the Git layer.

PolicyAsCode October 20, 2025 GitOps Security
GitOps Security: Enforcing Policy as Code in Flux and ArgoCD

Recent Articles

21 posts

BREAKING: Massive CI/CD Pipeline Injection Attack Compromises 10,000+ Repositories

A sophisticated supply chain attack targeting CI/CD pipelines has compromised over 10,000 GitHub repositories. The attack, dubbed 'PipelinePhantom,' exploits a previously unknown vulnerability in how GitHub Actions handles workflow file parsing.

AWS IAM AssumeRole Vulnerability Enables Privilege Escalation

A critical vulnerability in AWS Identity and Access Management (IAM) allows attackers to escalate privileges and gain unauthorized access to AWS resources. The vulnerability affects the AssumeRole function and cross-account trust relationships across all AWS regions.

Explore by Category

Browse articles by topic