{"podcast":{"title":"Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News","slug":"ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275","podcast_index_feed_id":7591275,"rss_url":"https://media.rss.com/ship-it-weekly/feed.xml","website_url":"https://www.shipitweekly.fm/","image_url":"https://media.rss.com/ship-it-weekly/20260103_010109_fc16278a46c7b2c61123ed668a34f79d.jpg","author":"Teller's Tech - DevOps, SRE and Cloud Podcast","episode_count":55,"summary":"Ship It Weekly is a short, practical recap of what actually matters in DevOps, SRE, cloud infrastructure, and platform engineering. Each episode, your host Brian Teller walks through the latest outages, releases, tools, and incident writeups, then translates them into “here’s what this means for your systems” instead of just reading headlines. Expect a couple of main stories with context, a quick hit of tools or releases worth bookmarking, and the occasional segment on on-call, burnout, or team culture. This isn’t a certification prep show or a lab walkthrough. It’s aimed at people who are already working in the space and want to stay sharp without scrolling status pages, cloud updates, and blogs all week. You’ll hear about things like cloud provider incidents, Kubernetes and platform trends, Terraform and infrastructure changes, and real postmortems that are actually worth your time. Most episodes are 15–30 minutes, so you can catch up on the way to work or between meetings. Every now and then there will be a “special” focused on a big outage or a specific theme, but the default format is simple: what happened, why it matters, and what you might want to do about it in your own en…","last_synced_at":"2026-07-19T00:20:39.423055+00:00","page_url":"https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275"},"episode":{"title":"Amazon Q CVEs, Hijacked npm and Go Packages, AWS WAF HTTP/2 Issues, Lambda MicroVMs, and Why Execution Is the Boundary Now","slug":"amazon-q-cves-hijacked-npm-and-go-packages-aws-waf-http-2-issues-lambda-microvms-and-why-execution-is-the-boundary-now","published_at":"2026-07-03T01:00:02+00:00","page_url":"https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/amazon-q-cves-hijacked-npm-and-go-packages-aws-waf-http-2-issues-lambda-microvms-and-why-execution-is-the-boundary-now","show_page_url":"https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275","url":"https://rss.com/podcasts/ship-it-weekly/2960832","audio_url":"https://content.rss.com/episodes/356364/2960832/ship-it-weekly/2026_07_02_23_29_05_26976129-6540-4d57-b3c9-f4cebc9be169.mp3","summary":"This week on Ship It Weekly : Amazon Q Developer and the AWS language servers had a pair of trust-boundary CVEs, JFrog found hijacked npm and Go packages using hidden VS Code tasks to run malware when a workspace opens, AWS WAF had HTTP/2 request-body inspection issues, and AWS introduced Lambda MicroVMs for running user-generated and AI-generated code in isolated sandboxes. The bigger theme: execution is the boundary now. The repo, the IDE, the AI assistant, the WAF, and the sandbox all sit at the point where something gets to run, inspect, block, or decide. Before execution, trust is a policy. After execution, trust is a blast radius. In the lightning round, Brian covers GitHub’s record advisory volume, Git 2.55, Valkey 9.1 on Amazon ElastiCache, and a quick Fable 5 callback now that Anthropic’s Fable 5 is back online. Links AWS security bulletin: Amazon Q / AWS language server CVEs https://aws.amazon.com/security/security-bulletins/2026-047-aws/ JFrog: Hijacked npm packages using VS Code tasks https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/ AWS security bulletin: AWS WAF HTTP/2 inspection issues https://aws.amazon.com/security/security-bulletins/2026-048-aws/ AWS Lambda MicroVMs https://aws.amazon.com/blogs/aws/run-isolated-sandboxes-with-full-lifecycle-control-aws-lambda-introduces-microvms/ GitHub Advisory Database record volume https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/ Git 2.55 highlights https://github.blog/open-source/git/highlights-from-git-2-55/ Amazon ElastiCache Valkey 9.1 https://aws.amazon.com/blogs/database/announcing-valkey-9-1-for-amazon-elasticache/ Claude Fable 5 and Mythos 5 model docs https://platform.claude.com/docs/en/about-claud…","meta_description":"This week on Ship It Weekly : Amazon Q Developer and the AWS language servers had a pair of trust-boundary CVEs, JFrog found hijacked npm and Go packages…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1086,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/amazon-q-cves-hijacked-npm-and-go-packages-aws-waf-http-2-issues-lambda-microvms-and-why-execution-is-the-boundary-now/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/amazon-q-cves-hijacked-npm-and-go-packages-aws-waf-http-2-issues-lambda-microvms-and-why-execution-is-the-boundary-now.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}