Q&A: The growing divide between developers and FinOps

Development teams and FinOps aren’t always on the same page, and lately developers have been feeling the effects of not having proper visibility into their cloud spend. In a recent episode of our podcast, we interviewed Martin Reynolds, field CTO at Harness, about the company’s recent FinOps in Focus 2025 report, which explored the ways … continue reading

The 2025 State of Vulnerability Management and Remediation Report

Open source fuels innovation, but hidden vulnerabilities can put your entire organization at risk.         The 2025 State of Vulnerability Management and Remediation Report explores the growing risks organizations face due to vulnerable open source components. While open source powers modern innovation, outdated and unpatched libraries can compromise entire applications, leading to financial … continue reading

Microsoft has been working on a native implementation of TypeScript

Microsoft has announced it has been working on creating a native implementation of the TypeScript compiler and tools, significantly improving editor startup time, reducing build time, and drastically cutting down on memory usage. TypeScript is a language that builds on JavaScript, but according to Anders Hejlsberg, lead architect of TypeScript, JavaScript does have its limitations.  … continue reading

OpenSSF creates Project Security Baseline

UPDATED MARCH 28 The Open Source Security Foundation (OpenSSF) has created a Project Security Baseline that helps open source projects of all sizes ensure that their efforts are secure. The baseline defines a minimum set of requirements for application security that developers can do to enforce secure development practices, such as how they need to … continue reading

Lessons and surprises from a Kubernetes migration

Large migrations are always fraught with potential dangers. The team has built trust with customers over years and years on a platform that the organization chose many years ago. The team knows the platform inside and out, including all of its quirks and odd little behaviors. It feels a bit like a team member itself. … continue reading

Mar 7, 2025: 10 AI updates from the past week

Software companies are constantly trying to add more and more AI features to their platforms, and it can be hard to keep up with it all. We’ve written this roundup to share updates from 10 notable companies that have recently enhanced their products with AI.  JFrog launches end-to-end DevSecOps platform for deploying AI applications JFrog … continue reading

Taking think-time about the future of AI for development

I’m always looking for more time and space to get things done. For every useful unit of actual hands-on-keys work time I spend writing thought leadership pieces, or time on briefing and advisory calls with innovative vendors, there must be a corresponding amount of time away from the computer to realign my thinking and grasp … continue reading

Two reinforcement learning researchers receive 2024 ACM A.M. Turing Award

Andrew G. Barto and Richard S. Sutton have been named as the recipients of the 2024 ACM A.M. Turing Award for their contributions to the field of reinforcement learning beginning in the 1980s. Reinforcement learning is a training method for AI systems that teaches them how to make the most optimal decisions through a series … continue reading

GitHub unbundling its GitHub Advanced Security offering starting in April

GitHub announced it is making some changes to GitHub Advanced Security (GHAS), its AI-powered solution for application security that offers remediation, static analysis, secret scanning, and software composition analysis. Beginning April 1, GHAS will be split into two products that will be available as standalone options. GitHub Secret Protection prevents secret leaks by scanning secrets … continue reading

Sonatype Unveils Industry-First AI Software Composition Analysis (SCA) to Power AI-Driven Innovation

Sonatype®, the leader in software supply chain security, today announced end-to-end AI Software Composition Analysis (AI SCA) capabilities that enable enterprises to harness the full potential of AI. With its unparalleled expertise in open source governance, Sonatype now extends its trusted platform to protect, manage, and optimize AI/ML models across development and deployment. Sonatype is the first … continue reading

JFrog launches end-to-end DevSecOps platform for deploying AI applications

JFrog is releasing a new end-to-end solution for developing and deploying enterprise AI applications that brings together development teams, data scientists, and machine learning engineers into a single platform.  JFrog ML provides a holistic view of the entire AI software supply chain, from software packages to LLMs, so that companies can ensure their AI applications … continue reading

Keeping your decentralized workforce better protected from security risks

Hybrid work structures have become a popular choice for many modern companies. Not only do they add more flexibility when scaling a business, but they also help to create a better work-life balance for all employees. However, while maintaining a decentralized workforce does come with a number of advantages, there are also certain risks associated … continue reading

« Previous PageNext Page »
DMCA.com Protection Status