Social – Facebook
A Semicolon in a Branch Name Was All It Took to Steal an AI Agent’s GitHub Token
AI coding agents don't just suggest code anymore. Tools like OpenAI's Codex spin up a real container, clone a real repository, and authenticate with a real GitHub credential to get the job ...
Perforce Applies Machine Learning to Generate Synthetic Data for App Testing
Perforce Software has added a tool that leverages artificial intelligence (AI) to make it simpler for application development teams to generate synthetic data for application testing purposes. Mayank Ahluwalia, a senior product ...
AWS Benchmark Aims to Reduce Number of False Positives Found by AI Vulnerability Scanners
Amazon Web Services (AWS) has developed a benchmark that can be used to test whether a model can distinguish real vulnerabilities from code that looks risky but is actually safe. The Deception ...
Git 2.56 Takes Aim at Messy Merges, Slow Diffs and Branch Sprawl
Git 2.56 improves merge safety, speeds up large-repository operations and adds cleanup tools that could prove especially useful for AI coding agents and busy DevOps teams ...
env zero Previews Control Plane for Agentic DevOps Workflows
env zero’s EZ Control introduces an agentic DevOps control plane that detects infrastructure drift, applies policy-driven remediation and keeps automated changes attributable, reversible and auditable ...
Docker Introduces Open Sandbox Kit Spec for AI Agent Permissions
AI agents are getting good at probing the boundaries developers put around them. Their ability to improvise makes them hard to contain. “You ask for something in a very high-level, vague-at-best way ...
Survey: Lack of Confidence in Software Supply Chain Security Runs High
A survey of 400 platform and security engineers in the U.S and United Kingdom (UK), finds nearly three quarters (73%) are either only moderately confident (58%) or not confident (15%) in the ...
DHH Declares End of Hand-Writing Code at Rails World 2026
Controversial developer David Heinemeier Hansson (aka DHH) announced last week at Rails World 2026 that the end of handwritten code is upon us, calling it the modern era's "Brownie" moment. The moment ...
Ten Great DevOps Job Opportunities
DevOps.com is now providing a weekly DevOps jobs report through which opportunities for DevOps professionals will be highlighted as part of an effort to better serve our audience. Our goal in these ...
GitHub’s Security Autofix Agent Now Remembers What It Fixed
GitHub’s agentic autofix now uses Copilot Memory to reuse repository-specific security fix patterns, helping Copilot apply lessons from past vulnerabilities across future alerts, reviews and coding workflows ...
Leaked GitLab Email Tokens Can Reach Code, Secrets and CI/CD Pipelines
Security researchers have uncovered a GitLab behavior that could let attackers use a leaked project email address to push code, trigger CI/CD jobs and reach other repositories accessible to the address owner ...
Blitzy Makes Sandbox for Reverse Engineering Code Available at No Cost
Blitzy has made available a sandbox where DevOps teams can reverse-engineer up to one million lines of code, generate up to 25,000 lines of tested end-to-end code, and identify security vulnerabilities across ...

