360SOFTY

Insights

Engineering Insights

Practical writing on software architecture, SaaS products, AI automation, legacy modernisation, and the business of building reliable systems.

RSS

Curated links from external sources — not 360Softy original articles.

ExternalCybersecurity
OWASP Blog

ASVS 5.0 RC1 is ready for your review!

Introduction We are on the final countdown to the release of the OWASP Application Security Verification Standard (ASVS) version 5.0! This will be a major release with a lot of changes to bring the ASVS up to date and make it more usable. See here for more information on the guiding principles of the new release. We have now released a release candidate version of 5.0 and we are waiting for your feedback! How can I help? Reading through the release candidate version of ASVS is a great place to s

OWASP BlogRead original
ExternalCloud
Cloudflare Changelog

Access - Cloudflare Zero Trust SCIM User and Group Provisioning Logs

Cloudflare Zero Trust SCIM provisioning now has a full audit log of all create, update and delete event from any SCIM Enabled IdP. The SCIM logs support filtering by IdP, Event type, Result and many more fields. This will help with debugging user and group update issues and questions. SCIM logs can be found on the Zero Trust Dashboard under Logs -> SCIM provisioning.

Access
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

Access - Cloudflare Zero Trust SCIM User and Group Provisioning Logs

Cloudflare Zero Trust SCIM provisioning now has a full audit log of all create, update and delete event from any SCIM Enabled IdP. The SCIM logs support filtering by IdP, Event type, Result and many more fields. This will help with debugging user and group update issues and questions. SCIM logs can be found on the Zero Trust Dashboard under Logs -> SCIM provisioning.

Access
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

Hyperdrive - Hyperdrive now supports custom TLS/SSL certificates

Hyperdrive now supports more SSL/TLS security options for your database connections: Configure Hyperdrive to verify server certificates with verify-ca or verify-full SSL modes and protect against man-in-the-middle attacks Configure Hyperdrive to provide client certificates to the database server to authenticate itself (mTLS) for stronger security beyond username and password Use the new wrangler cert commands to create certificate authority (CA) certificate bundles or client certificate pairs:

Hyperdrive
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

Rules - Cloudflare Snippets are now Generally Available

Cloudflare Snippets are now generally available at no extra cost across all paid plans — giving you a fast, flexible way to programmatically control HTTP traffic using lightweight JavaScript. You can now use Snippets to modify HTTP requests and responses with confidence, reliability, and scale. Snippets are production-ready and deeply integrated with Cloudflare Rules, making them ideal for everything from quick dynamic header rewrites to advanced routing logic. What's new: Snippets are now GA –

Rules
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

Secrets Store, SSL/TLS - Cloudflare Secrets Store now available in Beta

Cloudflare Secrets Store is available today in Beta. You can now store, manage, and deploy account level secrets from a secure, centralized platform to your Workers. To spin up your Cloudflare Secrets Store, simply click the new Secrets Store tab in the dashboard or use this Wrangler command: wrangler secrets-store store create <name> --remote The following are supported in the Secrets Store beta: Secrets Store UI & API: create your store & create, duplicate, update, scope, and delete a s

Secrets StoreSSL/TLS
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

Workers - Investigate your Workers with the Query Builder in the new Observability dashboard

The Workers Observability dashboard offers a single place to investigate and explore your Workers Logs. The Overview tab shows logs from all your Workers in one place. The Invocations view groups logs together by invocation, which refers to the specific trigger that started the execution of the Worker (i.e. fetch). The Events view shows logs in the order they were produced, based on timestamp. Previously, you could only view logs for a single Worker. The Investigate tab presents a Query Builder

Workers
Cloudflare ChangelogRead original

Work with 360Softy

Building a SaaS product, AI system, or business platform?

Book a free consultation and we will tell you honestly whether we can help.