Episode

Amazon S3 Files, Malicious npm Plugins, Trivy Fallout, and Kubernetes’ Gateway Shift

Podcast
Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News
Published
Apr 10, 2026
Duration seconds
904
Processing state
not_requested
Canonical source
https://rss.com/podcasts/ship-it-weekly/2710524
Audio
https://content.rss.com/episodes/356364/2710524/ship-it-weekly/2026_04_08_19_26_01_5b77e7ff-1445-45e0-bd83-7d45363c9449.mp3
JSON
/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift
Markdown
/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

This episode of Ship It Weekly is about the interface layer becoming the story. Brian covers Amazon S3 Files and why it feels more like a managed filesystem layer in front of S3 than “S3 is EFS now,” including how it relates to the old s3fs and FUSE-style approach. He also digs into 36 malicious npm packages posing as Strapi plugins, the uglier follow-on to the Trivy incident he discussed previously, Kubernetes Ingress2Gateway 1.0 and the push toward Gateway API, and Kubernetes Agent Sandbox as a sign that newer AI-style workloads are starting to reshape the platform itself. Links Amazon S3 Files https://aws.amazon.com/blogs/aws/launching-s3-files-making-s3-buckets-accessible-as-file-systems/ Malicious npm packages posing as Strapi plugins https://thehackernews.com/2026/04/36-malicious-npm-packages-exploited.html Trivy follow-on incident discussion https://github.com/aquasecurity/trivy/discussions/10425 RoseSecurity on Trivy / typosquatting angle https://rosesecurity.dev/2026/03/20/typosquatting-trivy.html Earlier episode covering the first Trivy incident https://www.tellerstech.com/ship-it-weekly/aws-bahrain-uae-data-center-issues-amid-iran-strikes-argocd-vs-flux-gitops-failures-github-actions-hackerbot-claw-attacks-trivy-roguepilot-codespaces-prompt-injection-block-ai-remake/ Kubernetes Ingress2Gateway 1.0 https://kubernetes.io/blog/2026/03/20/ingress2gateway-1-0-release/ Kubernetes Agent Sandbox https://kubernetes.io/blog/2026/03/20/running-agents-on-kubernetes-with-agent-sandbox/ Fortinet FortiClient EMS emergency patch https://www.fortiguard.com/psirt/FG-IR-26-099 Karpathy post https://x.com/karpathy/status/2036487306585268612 ProofShot https://github.com/AmElmo/proofshot More episodes and show notes https://shipitweekly.fm On Call Briefs https://oncallbrief.com