Follow the latest coverage, related explainers and connected technology stories.
A CNCF article proposes replacing client certificates and long-lived tokens in self-hosted Kubernetes clusters with an OIDC integration based on a public client and PKCE. This approach ties permissions to identity and group membership, simplifies revocation, and improves the accuracy of audit logs without requiring the cluster to be rebuilt.
JetBrains has introduced an OIDC JWT plugin for TeamCity to issue short-lived identity tokens that allow build processes to access AWS, Google Cloud, and other services without storing static credentials. The plugin requires Java 17 and TeamCity 2025.11 or later, with options for managing signing keys and setting token lifetimes.
Microsoft Threat Intelligence analyzed a widespread attack on the npm supply chain in which a credential-stealing worm was hidden inside more than 400 packages published by different entities. The malware collects developer and CI/CD environment secrets, then uses npm and GitHub tokens to republish malicious versions and open additional propagation paths.
Starting August 17, 2026, NuGet.org will limit the duration of new API keys to 30 days, while all keys created before that date will expire on November 1. Microsoft recommends that package publishers move to OIDC-based Trusted Publishing.