Blog
XZ Utils, the xz Backdoor & What We Can Learn from Open Source CVEs
The xz backdoor was a vulnerability in XZ Utils, a popular data compression library. The xz backdoor could let unauthorized users gain admin-level access to systems, endangering data security and much more.
Read on to learn more about the xz backdoor, where it came from, and how to minimize the impact of software vulnerabilities in your systems.
Security & Compliance, How to & Use Cases
Blog
Enhancing Security Best Practices: Lessons from Puppet's Proactive Approach to GitHub Repository Management
We are committed to maintaining the highest standards of security — here's how we further strengthened our security practices thanks to valuable input from an independent security researcher.
Security & Compliance
Blog
Stay Ahead of Known Vulnerabilities with Automated Patch Management
The consequences of not patching are everywhere: remember the Log4j vulnerability that grants hackers complete access to your devices? The best way to prevent this from happening is to use a patched version of Log4j — so why did this become a catastrophic and prolific security vulnerability event?
Security & Compliance
Blog
The Secret to Enterprise Observability: Agent-Based Automation & Configuration Management
Observability provides crucial insights to an IT system & its components. Agent-based automation makes sure observability tools don't run into scaling problems.
Configuration Management, Infrastructure Automation
Blog
Software Change Impact Analysis: 3 Benefits of Knowing What Your Code Will Do Before You Merge
Conducting impact analysis for your infrastructure code can help you make better decisions, avoid unexpected effects, and take on the right level of risk with each code deployment.
Infrastructure Automation, How to & Use Cases
Blog
AWS OpsWorks Deprecation: How to Keep Managing Servers After AWS OpsWorks EOL
The AWS OpsWorks Puppet Enterprise integration was a fully managed service to help you accelerate your migration to the cloud. AWS OpsWorks for Puppet Enterprise end-of-life (EOL) was March 31, 2024. Find out what to do next and discover options for your Puppet-managed infrastructure.
Products & Services, Ecosystems & Integrations
Blog
DISA STIGs: Who Needs Them & How to Enforce DISA STIG Compliance
DISA STIGs outline system security recommendations for DoD contractors, and they're a heavy lift for any DevSecOps team. In this blog, learn how Puppet Enterprise and Security Compliance Enforcement premium features can help you cut down on the time it takes to configure and maintain DISA STIG compliance.
Security & Compliance, Government