Security & DevOps Insights
Guides, best practices, and deep dives on private package repositories, CVE management, NIS2 compliance, and Linux supply chain security.
Beyond CVSS: Why EPSS + KEV Change How You Prioritize CVEs
CVSS scores were never designed for prioritization. Learn how combining Grype scanning with EPSS probability scores and the CISA Known Exploited Vulnerabilities catalog gives you a defensible, risk-based remediation workflow.
Setting Up a Private APT Repository with GPG Signing in 15 Minutes
Step-by-step guide to deploying a private Debian/Ubuntu package repository with GPG signing, ClamAV antivirus scanning, and CVE gating — using Docker Compose.
NIS2 Article 21: How a Private Package Repository Helps You Comply
NIS2 mandates supply chain security for essential entities. Learn how a hardened private APT/RPM repository addresses Article 21(2)(d) requirements with GPG signing, CVE gating, and immutable audit trails.