Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News

Amazon Linux 2027, GitHub Actions Cache Security, Secret-Scanning Merge Blocks, N-central CVSS 10 RCE, Karmada Graduation, ShieldCrash, CodeQL ARM64 & When Observability Fails Too

September 12, 2026·14 min
Episode Description from the Publisher

This week on Ship It Weekly: Amazon Linux 2027 enters public preview with kernel 7.1+, SELinux enforcing by default, DNF5, newer language runtimes, AWS-LC, and an x86-64-v3 baseline. GitHub Actions adds explicit cache permissions to reduce cache-poisoning risk. GitHub can now block pull requests from merging when they introduce exposed secrets. And N-able N-central has a critical pre-auth RCE that Huntress says is being actively exploited in the wild. The bigger theme this week is catching problems before they turn into incidents. Amazon Linux 2027 gives teams time to test AMIs, bootstrap scripts, agents, Terraform, CloudFormation, and CI/CD before the next platform generation becomes production reality. GitHub’s new cache controls make workflow trust boundaries explicit instead of leaving them implied. And secret-scanning rulesets move credential detection directly into the merge path, where developers can actually act on it. In the lightning round: Karmada graduates from the CNCF as multi-cluster and distributed AI scheduling grow, ShieldCrash research claims another Microsoft Defender patch bypass with SYSTEM-level access, CodeQL 2.27 adds native Linux ARM64 support, and Dependabot can now read private GitHub Packages without another personal access token.And the human closer is about what happens when observability shares the same failure domain as the thing it is watching. A full disk is bad enough. It gets worse when logs stop writing, monitoring data disappears, and the tools used to diagnose the outage start failing too. The takeaway is not that every monitoring component needs total isolation. It is that you should know what can blind you, and make sure at least one useful signal survives the failures you care about most.LinksAmazon Linux 2027 Public Previewhttps://tsn.io/NHlEaAmazon Linux 2027 Overview and Preview Detailshttps://tsn.io/izDYxAmazon Linux 2027 Known Issues and Preview Limitationshttps://tsn.io/tdugdGitHub Actions Cache Permissions with cache-modehttps://tsn.io/8p94nBlock Pull Requests with Exposed Secrets from Merginghttps://tsn.io/BspA2N-able N-central 2026.3 Hotfix 4https://tsn.io/xredGHuntress: N-able N-central Vulnerability and Active Exploitationhttps://tsn.io/QjNd5Karmada Graduates from the CNCFhttps://tsn.io/lcJGhMicrosoft Defender ShieldCrash Zero-Day Researchhttps://tsn.io/YfsJ6CodeQL 2.27 Adds Linux ARM64 Supporthttps://tsn.io/lxfnFAutomatic Dependabot Access to GitHub-Hosted Registrieshttps://tsn.io/pSilAShip It Weeklyhttps://www.tellerstech.com/go/siw/On Call Briefhttps://www.tellerstech.com/go/ocb/

Podzilla Summary coming soon

Sign up to get notified when the full AI-powered summary is ready.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.

Listen to This Episode

Get summaries like this every morning.

Free AI-powered recaps of Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News and your other favorite podcasts, delivered to your inbox.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.