
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Fri, 12 Jun 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/ci/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-npm-supply-chain-attack-defense.en</guid>
    <title>Anatomy of npm Supply Chain Attacks — Defense Strategies for the Era When Even Red Hat Got Hit</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-npm-supply-chain-attack-defense.en</link>
    <description>Triggered by the June 2026 incident in which even official Red Hat Cloud Services npm packages were exposed to malicious code, this post dissects the types of npm supply chain attacks and lays out the defense stack organizations need, from lockfile integrity and provenance signing to internal registries and CI network isolation. Ready-to-apply .npmrc and GitHub Actions examples are included.</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>npm</category><category>supply-chain</category><category>security</category><category>devops</category><category>sigstore</category><category>ci</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-npm-supply-chain-attack-defense.ja</guid>
    <title>npmサプライチェーン攻撃の解剖 — Red Hatすら突破された時代の防御戦略</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-npm-supply-chain-attack-defense.ja</link>
    <description>2026年6月、Red Hat Cloud Servicesの公式npmパッケージまでもが悪意あるコードに晒された事件を契機に、npmサプライチェーン攻撃の類型を解剖し、lockfileの完全性、provenance署名、社内レジストリ、CIネットワーク隔離まで、組織が備えるべき防御スタックを整理します。すぐに適用できる.npmrcとGitHub Actionsの設定例も提供します。</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>npm</category><category>supply-chain</category><category>security</category><category>devops</category><category>sigstore</category><category>ci</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-npm-supply-chain-attack-defense</guid>
    <title>npm 공급망 공격 해부 — Red Hat까지 뚫린 시대의 방어 전략</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-npm-supply-chain-attack-defense</link>
    <description>2026년 6월 Red Hat Cloud Services 공식 npm 패키지까지 악성 코드에 노출된 사건을 계기로, npm 공급망 공격의 유형을 해부하고 lockfile 무결성, provenance 서명, 사내 레지스트리, CI 네트워크 격리까지 조직이 갖춰야 할 방어 스택을 정리합니다. 바로 적용할 수 있는 .npmrc와 GitHub Actions 설정 예제를 함께 제공합니다.</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>npm</category><category>supply-chain</category><category>security</category><category>devops</category><category>sigstore</category><category>ci</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-property-based-testing-practical.en</guid>
    <title>Property-Based Testing in Practice — Catching the Bugs Examples Cannot</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-property-based-testing-practical.en</link>
    <description>A practice-first guide to property-based testing (PBT), which catches the bugs that example-based tests miss. Covers the core concepts of properties, generators, and shrinking, a pattern catalog for discovering properties, working examples in Python Hypothesis, Java jqwik, and JS fast-check, state machine testing, CI integration, and the synergy with verifying AI-written code.</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>testing</category><category>property-based-testing</category><category>hypothesis</category><category>jqwik</category><category>fast-check</category><category>ci</category><category>quality</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-property-based-testing-practical.ja</guid>
    <title>プロパティベーステスト実践 — 例示テストが捕まえられないバグを捕まえる方法</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-property-based-testing-practical.ja</link>
    <description>例示ベースのテストが見逃すバグを捕まえるプロパティベーステスト(PBT)を実践中心に整理します。プロパティ/ジェネレーター/シュリンキングの核心概念、プロパティ発見のパターンカタログ、Python HypothesisとJava jqwikとJS fast-checkの動作例、ステートマシンテスト、CI統合、AIが書いたコードの検証とのシナジーまで扱います。</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>testing</category><category>property-based-testing</category><category>hypothesis</category><category>jqwik</category><category>fast-check</category><category>ci</category><category>quality</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-property-based-testing-practical</guid>
    <title>속성 기반 테스트 실전 — 예제가 못 잡는 버그를 잡는 법</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-property-based-testing-practical</link>
    <description>예제 기반 테스트가 놓치는 버그를 잡는 속성 기반 테스트(PBT)를 실전 중심으로 정리합니다. 속성/제너레이터/슈링킹 핵심 개념, 속성 발견 패턴 카탈로그, Python Hypothesis와 Java jqwik과 JS fast-check 동작 예제, 상태 머신 테스트, CI 통합, AI가 작성한 코드 검증과의 시너지까지 다룹니다.</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>testing</category><category>property-based-testing</category><category>hypothesis</category><category>jqwik</category><category>fast-check</category><category>ci</category><category>quality</category>
  </item>

    </channel>
  </rss>
