Shift left security — Good intentions, poor execution, and ways to fix it

The concept of “shift left” is fundamentally sound. Integrating security earlier into the software development life cycle (SDLC) seems like the obvious move. Instead of leaving security as an afterthought, why not address it before it becomes a problem? It sounds ideal: Faster remediation, fewer vulnerabilities slipping through the cracks, and developers becoming security heroes. …

Top misconceptions about platform engineering (and what to do about them)

While it’s often said that “time is money” when it comes to business, that phrase is now applicable to software development. Staying competitive in today’s world means staying current. Whether large or small, organizations need the ability to respond quickly to changing marketing conditions, business needs, security requirements, and more. And they can’t do that …

Techniques to secure open source software

Attackers are increasingly targeting open source projects, seeking to exploit holes in software that millions of organizations rely on as the foundation of their technology stacks. The staggering 280% year-over-year increase in software supply chain attacks in 2023 serves as a stark warning: open source projects and their leadership must elevate security to their highest …

The rise of “soft” skills: How GenAI is reshaping developer roles

The software development landscape is undergoing a profound transformation as generative AI (GenAI) reshapes traditional coding practices. This technological revolution isn’t just changing how code is written—it’s fundamentally altering the skill set developers need to succeed in their careers. As development teams across the industry integrate GenAI into their workflows, a new paradigm is emerging …

Latest News

Predictions for software development in 2025

As we do every year, we’ve heard from folks around the software development industry who share their thoughts on which areas will thrive and which might not survive in 2025 and beyond. Here are some of their predictions for next year. Derek Holt, CEO of Digital.ai While Value Stream Management continued to lose steam in …

The top software development news of 2024

As 2024 comes to a close, SD Times is looking back at the top software development news stories of the year across the industry. Here are 10 of what we believe to be the biggest stories we covered throughout the year: Microsoft releases .NET 9 .NET 9 was released in November, adding a number of …

GitHub Copilot Free launches to expand reach of platform to all developers

GitHub has announced a free tier of GitHub Copilot to expand the platform’s reach to more developers. “We couldn’t be more excited to make Copilot available to the 150M developers on GitHub,” Thomas Dohmke, CEO of GitHub, wrote in a post.  The free tier provides access to 2,000 code completions and 50 chat messages per …

OpenAI announces latest capabilities for developers

OpenAI announced several new capabilities for developers, including the availability of OpenAI o1 in the API and updates to the Realtime API. OpenAI o1 is the company’s reasoning model for complex multi-step tasks, and it has begun rolling out to developers on the API’s usage tier 5.  Some key capabilities enabled by o1 include function …

Tabnine introduces Code Provenance and Attribution feature that flags restrictively licensed code generated by AI assistants

The AI coding assistant provider Tabnine today announced a new feature, Code Provenance and Attribution, to protect companies from unintentionally adding restrictively licensed code into their codebase when using generative AI to write code.  The new feature checks AI-generated code against public GitHub repositories to find matches, and flags the license type of the original …

Emotional intelligence in IT management: Impact, challenges, and cultural differences

Emotional intelligence (EI) has become one of the most sought-after soft skills in the IT industry, especially at the management level. The ability to understand and manage emotions — both one’s own and those of others — is critical in many areas of IT, from support services and user experience (UX) to cross-functional leadership and …

Redefining software excellence: Quality, testing, and observability in the age of GenAI

As software development undergoes a seismic shift with GenAI at the forefront, testing, quality assurance, and observability are being transformed in unprecedented ways. These advancements are driving new levels of automation and efficiencies, while challenging traditional methodologies and long-held assumptions about speed, adaptability, and innovation. As GenAI automates routine tasks and enables smarter decision-making, it …

Report: TypeScript, Rust, and Python among the languages showing the most promise in 2024

JetBrains has released its annual State of Developer Ecosystem report, highlighting the trends across software development. This year the report includes a new section called the Language Promise Index, which ranks languages by growth, stability, and adoption willingness. Across the board since 2017, JavaScript has topped the list, with 61% of users programming in that …

Google announces Gemini 2.0 Flash and new coding agent

Google has announced the launch of the latest model in the Gemini family, as well as a new coding agent for developers called Jules.  Gemini comes in two different model variants, with Flash balancing performance with speed and Pro optimizing for performance. The newest model, Gemini 2.0 Flash, is twice as fast as Gemini 1.5 …

OpenSilver 3.1 adds new drag-and-drop XAML designer for VS Code

OpenSilver 3.1 has been released, bringing new features to the open source framework for building web apps using .NET. These include a drag-and-drop XAML designer for VS code, a more modern UI theme, expanded support for Windows Presentation Foundation (WPF) features, and full compatibility with .NET 9. The new drag-and-drop XAML designer in VS Code …

Latest Webinars

SD Times Live! Microwebinar Series — with ActiveState

ActiveState is revolutionizing open source management with a streamlined, secure, and scalable approach. In this microwebinar series, learn how ActiveState helps DevSecOps teams eliminate the complexities of managing open source, securing the software supply chain, and integrating with your CI/CD workflows. With experts like CTO Scott Robertson and Product Director Pete Garcin, discover how ActiveState …

Using AI to code: What could possibly go wrong?

The hype around using AI in software development is at a high not seen since the cloud. Companies are rushing to get on the train, with spending plans for 2025 almost all targeting AI-based tools. And with all we understand – and don’t understand – about using AI in software development, and all the hurdles …

From Source to Container – Gaining Productivity with Open Source Paketo Buildpacks

Bloomberg, Capital One, and tens of thousands of developers are using open source Cloud Native Buildpacks to transition application source code to container images that can be easily maintained and updated. Paketo Buildpacks, an implementation of the cloud Native Buildpacks, run on any container runtime that supports container images, which makes them suitable for  Docker and Kubernetes based environments. …

ValueOps ConnectALL: Pattern Thinking & Automation

Join us for an insightful webinar on “ValueOps ConnectALL: Pattern Thinking & Automation,” where Lance Knight, ValueOps by Broadcom’s Chief Value Stream Architect, delves into the transformative power of optimizing flow in software delivery value streams. This session will explore how identifying and leveraging patterns in your processes can significantly enhance efficiency and drive automation …

Continuous Testing Microwebinar Series

SD Times Live! Microwebinar Series — Continuous Testing  Achieving continuous testing means shifting your testing left. That is a goal shared by every testing team in the industry, and this series will give you valuable insight and impactful tips for implementing a continuous testing approach into your testing strategy. Led by Perforce Vice President of …

Secrets Management Microwebinar Series

The Best Way to Manage Development Secrets Protecting sensitive data like API keys, passwords, and encryption keys is crucial. With applications sprawling across various environments, managing these secrets securely can become a complex challenge. Brian Vallelunga, CEO of Doppler, dives deep into the concept of secrets management, explaining: What are secrets and why are they …

Learning Center

  • White Papers

    How AI is Transforming Enterprise Content Management

    As organizations face increasing volumes of data, traditional Enterprise Content Management (ECM) systems often struggle with manual content management and document processing, leading to inefficiencies. The ECM market is evolving with advanced AI technologies like Natural Language Processing (NLP) and machine learning (ML), which are transforming how businesses manage, process, and secure their content. ​ …

  • Webinars

    SD Times Live! Microwebinar Series — with ActiveState

    ActiveState is revolutionizing open source management with a streamlined, secure, and scalable approach. In this microwebinar series, learn how ActiveState helps DevSecOps teams eliminate the complexities of managing open source, securing the software supply chain, and integrating with your CI/CD workflows. With experts like CTO Scott Robertson and Product Director Pete Garcin, discover how ActiveState …

  • Webinars

    Using AI to code: What could possibly go wrong?

    The hype around using AI in software development is at a high not seen since the cloud. Companies are rushing to get on the train, with spending plans for 2025 almost all targeting AI-based tools. And with all we understand – and don’t understand – about using AI in software development, and all the hurdles …

  • Webinars

    From Source to Container – Gaining Productivity with Open Source Paketo Buildpacks

    Bloomberg, Capital One, and tens of thousands of developers are using open source Cloud Native Buildpacks to transition application source code to container images that can be easily maintained and updated. Paketo Buildpacks, an implementation of the cloud Native Buildpacks, run on any container runtime that supports container images, which makes them suitable for  Docker and Kubernetes based environments. …

  • Webinars

    ValueOps ConnectALL: Pattern Thinking & Automation

    Join us for an insightful webinar on “ValueOps ConnectALL: Pattern Thinking & Automation,” where Lance Knight, ValueOps by Broadcom’s Chief Value Stream Architect, delves into the transformative power of optimizing flow in software delivery value streams. This session will explore how identifying and leveraging patterns in your processes can significantly enhance efficiency and drive automation …

  • Webinars

    Continuous Testing Microwebinar Series

    SD Times Live! Microwebinar Series — Continuous Testing  Achieving continuous testing means shifting your testing left. That is a goal shared by every testing team in the industry, and this series will give you valuable insight and impactful tips for implementing a continuous testing approach into your testing strategy. Led by Perforce Vice President of …

SD Times Newswire

DMCA.com Protection Status