
How I Consolidated Duplicate Delivery Pipelines With Parameters and Build Tags
Two modules in a repository had near-identical Azure DevOps build and release definitions. A third would have required another pair. The delivery chain used five definitions: one change decider, two builds, and two releases. I consolidated it into one decider, one generic build, and one release with a deployment stage for each onboarded module. The […]

Critical Flaw in isolated-vm Can Lead to Sandbox Escape, RCE Threat
Developers for years have been using vm2, an open-source Node.js library, to run untrusted JavaScript inside a secure and isolated sandbox environment. It uses Node.js’s built-in modules and JavaScript Proxies and lets developers whitelist particular built-in Node modules or limit what the script can access. During that time, vm2 has been the default for safely […]

LangChain’s dcode Isn’t New. Its Governance Play for Sensitive Code Is
Enterprises are running into the same wall with AI coding agents: the tools that write code fastest are usually the ones IT trusts least with sensitive codebases. Legacy modernization projects — COBOL migrations, .NET upgrades, decade-old frameworks nobody wants to touch by hand — are exactly where agentic coding tools could help most, and exactly […]

Enterprise Smart Contracts Have a Cryptography Problem. EY Just Built a Way Around It
The business case for smart contracts is building fast. Major financial institutions are using programmable, code-based agreements to underpin financial workflows, supply chain operations, and tokenization initiatives. Developers are being asked to prove the value. But there’s a problem most organizations don’t fully see until they’re already stuck: Privacy. Public blockchains are transparent by design. […]

Survey Surfaces Rise in IT Incidents Attributable to AI Coding Tools
A survey of 406 IT decision makers at organizations with more than 250 employees in North America finds 93% have experienced at least one infrastructure incident caused by reliance on artificial intelligence (AI) tooling. Conducted by Panterra Group on behalf of Spacelift, a provider of a platform for automating the management of infrastructure-as-code (IaC), the […]

AWS Previews Release Management Capabilities Added to DevOps Agent
Amazon Web Services (AWS) today previewed a release management capability for the artificial intelligence (AI) agent it developed to automate DevOps workflows. Announced at the AWS New York Summit, the latest release of the AWS DevOps Agent makes available in preview an updated version of the AWS DevOps Agent that can now review and test […]

GitHub Enterprise Server 3.21 Is Now Generally Available
GitHub has released GitHub Enterprise Server (GHES) 3.21, the latest version of its self-hosted platform for enterprise development teams. The release focuses on improving deployment efficiency, monitoring, code security, and policy management — areas that matter most to enterprise DevOps teams managing complex environments at scale. Here’s a look at what’s new and why it […]

Copado Brings AI Agents to DevOps Platform for Building Custom Salesforce Apps
Copado has added artificial intelligence (AI) agents to its DevOps platform for building and deploying custom applications for the software-as-a-service (SaaS) application platform from Salesforce. At launch, Copado is making available Agentia AI agents specifically that can be assigned plan, build and testing tasks via an orchestration agent that manages the overall workflow. Each Agentia […]

Low-Code’s New Frontier: Tailored Solutions for Each Industry
For years, most low-code platforms have focused on one primary challenge: efficiency. The goal was to help teams build applications faster and with less effort, reducing manual coding, speeding up iterations, empowering non-developers, and enabling apps to be created in just a few clicks. That focus delivered real value, but it’s no longer enough. Today, […]

Crates.io Removes Malicious Rust Package Targeting Web3 Developers
A malicious Rust package that was found to be downloading payloads aimed at stealing cryptocurrency was removed from the crates.io Rust package registry, along with another package by the same author that appeared benign but was dependent on the first. The crates.io team removed both packages this week after security researchers with Socket alerted it […]

JFrog and Dynatrace Extend DevOps Reach to NVIDIA Enterprise AI Factory
NVIDIA in partnership with JFrog and Dynatrace are working toward integrating DevOps tools with a platform for building artificial intelligence (AI) agents. At the COMPUTEX conference in Taiwan this week, NVIDIA added a validated design for building AI agents to the NVIDIA Enterprise AI Factory, an application development platform based on the NVIDIA Inference Microservices […]

Intelligent Continuous Security From the Platform Outward
In the end, ICS is not a tool — it’s a philosophy of secure software delivery. When it begins with the platform, everything else aligns: Speed, safety and scale.

From Testing Hell to Quality Heaven With Intelligent Continuous Testing
Intelligent Continuous Testing is not just the next step in automation — it’s the missing link between speed and quality in modern software delivery. If your team is stuck in manual testing purgatory, it’s time to reimagine testing as a smart, adaptive, and always-on partner in your journey to excellence.

Typosquat Supply Chain Attack Targets Go Developers
A backdoor that impersonates a widely used database module in the popular Go programming language can give hackers control of infected systems, according to a senior threat intelligence analyst with developer-focused platform provider Socket. The malicious package, which the threat actor first published in November 2021 and remains in the Go Module Proxy, typosquats the […]

Crossing the DevOps Performance Chasm With Continuous Feedback
Continuous Testing, Quality, Security, and Feedback — is essential for organizations aiming to become DevOps high-performers.

CloudBees Acquires Launchable to Advance Testing Using AI
CloudBees today revealed it has acquired Launchable, a provider of a test automation platform, to enable DevOps teams to improve both application security and software quality. Financial terms of the acquisition are not being disclosed.

DARPA Turns to AI to Help Turn C and C++ Code Into Rust
DARPA will lean on emerging AI capabilities to deal with the costly and time-consuming challenge of rewriting C and C++ code to Rust in a move designed to meet the push for federal agencies and private organizations to adopt memory-safe programming languages.

Polyfill Becomes a Supply-Chain Risk to 100,000 Websites
A Chinese company in February bought the domain and GitHub account for Polyfill, a popular open-source library used by more than 100,000 websites to deliver JavaScript code.

Most Critical Open Source Projects Lack Memory-Safe Code, CISA Says
The country’s top cybersecurity agency is continuing to urge software developers to adopt memory-safe programming languages to help reduce the number of vulnerabilities in their products.

Platform Engineering: The Evolution to DevOps-as-a-Service
Platform engineering represents the evolution of DevOps into a more structured and service-oriented model, effectively embodying the principles of DevOps-as-a-service.

Cisco Adds Generative AI and Deeper Splunk Integrations to AppDynamics
Several Cisco platforms will gradually be integrated into a single data platform, including Cisco AppDynamics, the Cisco ThousandEyes networking monitor service and the Splunk platform.

AlmaLinux Introduces Engineering Steering Committee to Enhance Community Collaboration
AlmaLinux is keeping its Linux community in the technology loop.

Atlassian Taps AI to Automate Software Engineering Workflows
Atlassian acquired Optic, which uses OpenAPI to track API changes across a continuous integration pipeline. It also announced a new AI tool.
