DevOps Daily with Fexingo · 2026-07-27 · 10 min
Episode 134 of DevOps Daily with Fexingo reveals a hidden risk in containerized CI/CD pipelines: BuildKit cache mounts that silently preserve outdated dependencies. Lucas and Luna unpack a real-world case where a team's npm cache mount kept a vulnerable transitive dependency alive for weeks, bypassing lockfile updates. They explain how cache mount invalidation works, why developers overtrust it, and three practical guardrails to keep builds both fast and fresh. If your pipeline relies on - mount=type=cache, this episode will change how you think about build reproducibility and supply chain security. #DevOps #CI/CD #Kubernetes #BuildKit #Docker #CacheMounts #DependencyRot #SupplyChainSecurity #ContainerSecurity #BuildCaching #CI_Pipeline #InfrastructureAsCode #DevOpsDaily #FexingoBusiness #BusinessPodcast #Technology #SoftwareOperations #Podcast Keep every episode free: buymeacoffee.com/fexingo
Other episodes covering the same guests and topics, from across The B2B Podcast Index.