Continuous Testing
How’s Facebook Work? They Don’t Know! | Cali. Pay Law | NASA RISC-V Launch
In this week’s The Long View: Facebook engineers admit they’ve no idea what Meta stores (or where), California requires job ads quote salaries, and RISC-V will power future NASA spacecraft ...
Playwright: A Modern, Open Source Approach to End-To-End Testing
I was excited when I started writing my first end-to-end tests years ago. The idea was promising; create an automated test suite that spins up a browser and mimics your user's behavior ...
Supply Chain Security: Has the Next SolarWinds Already Happened?
More than two years after the now-infamous hack of the firm SolarWinds, the incident is very much in the foreground of conversations about cybersecurity defense, threat detection and incident response. As evidence ...
Agile Sucks (Redux) | Plus: DevOps on Mars
In this week’s The Long View: Agile is bad, but “Wagile” is worse. Plus: This prod is even worse than yours ...
Avoiding Security Review Delays
In the summer of 2021, I had lunch with a senior security developer at one of Seattle's leading tech firms. Even though we were relaxed in the sunny and cool afternoon of ...
Cycode Expands Scope of AppDev Security Platform
At the Black Hat USA 2022 conference, Cycode this week announced it has added static application security testing (SAST) and container scanning capabilities to its software composition analysis (SCA) platform that is based ...
Why You Should Rip Up Your Org Chart and Reorganize Around Value Streams
To compete in the digital economy, teams must optimize both efficiency and effectiveness–it's a tough ask. The traditional dominator hierarchy is a problem because organizations that use command and control create silos ...
What GitHub’s 2FA Mandate Means for Devs Everywhere
Multifactor authentication (MFA) is becoming increasingly standard within software development organizations, with GitHub recently announcing that two-factor authentication (2FA) will be mandatory for all code contributors by the end of 2023. This ...
GitHub Brings 2FA to JavaScript Package Manager
GitHub has made generally available a two-factor authentication tool for the package manager for JavaScript applications maintained by its NPM, Inc. arm. In addition, all npm packages have been re-signed and there ...
CREST Defines Quality Verification Standard for AppSec Testing
At the Black Hat USA 2022 conference, CREST today shared a quality assurance verification standard to improve application security testing. The standard is based on the open source framework defined by the ...
IBM Unveils Simulation Tool for Attacking SCM Platforms
At the Black Hat USA 2022 conference, IBM today revealed it is making available a toolkit for launching simulated attacks against source code management (SCM) platforms. The toolkit was launched as a ...
Don’t Let Developer Toil Affect the Business Value of Your Apps
It is no surprise that the world today is driven by apps. Organizations all over the world are basing their business goals on their capacity to integrate new apps quickly, and they ...

