
Security News
Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security
Feross Aboukhadijeh joins TBPN to discuss Socket's $60M Series C, 500%+ ARR growth, AI's impact on open source, and the rise in supply chain attacks.
github.com/blakepettersson/gitops-engine
Advanced tools
Various GitOps operators address different use-cases and provide different user experiences but all have similar set of core features. The team behind Argo CD has implemented a reusable library that implements core GitOps features:
Do you want to propose one more feature and want to enhance the existing one?
Proposals and ideas are in markdown docs in the specs/ directory.
To create a new proposal, simply copy the spec template,
name the file corresponding to the title of your proposal, and place it in the
specs/ directory.
A good starting point to understand the structure is the GitOps Engine Design spec.
We tried to answer frequently asked question in a separate FAQ document.
This project is licensed under the Apache 2 license.
The GitOps Engine follows the CNCF Code of Conduct.
If you are as excited about GitOps and one common engine for it as much as we are, please get in touch. If you want to write code that's great, if you want to share feedback, ideas and use-cases, that's great too.
Find us on the #argo-cd-contributors on CNCF Slack (get an invite here).
At this stage we are interested in feedback, use-cases and help on the GitOps Engine.
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Feross Aboukhadijeh joins TBPN to discuss Socket's $60M Series C, 500%+ ARR growth, AI's impact on open source, and the rise in supply chain attacks.

Security News
OSV withdrew 157 OSV malware reports after automated false positives incorrectly flagged trusted npm and PyPI packages, sending bad records into tools that rely on OSV data.

Research
/Security News
TrapDoor crypto stealer hits 36 malicious packages across npm, PyPI, and Crates.io, targeting crypto, DeFi, AI, and security developers.