<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>HeroDevs on foojay.io - Friends Of OpenJDK</title><link>http://foojayio.github.io/website/sponsor/herodevs/</link><description>Articles from HeroDevs on foojay.io - Friends Of OpenJDK</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 18 Aug 2026 14:01:20 +0000</lastBuildDate><atom:link href="http://foojayio.github.io/website/sponsor/herodevs/index.xml" rel="self" type="application/rss+xml"/><item><title>Your AI Assistant Is Choosing Your Dependencies</title><link>http://foojayio.github.io/website/today/vibe-coding-maven-and-the-dependencies-you-didnt-choose/</link><pubDate>Tue, 18 Aug 2026 14:01:20 +0000</pubDate><category>Java</category><category>Security</category><guid>http://foojayio.github.io/website/today/vibe-coding-maven-and-the-dependencies-you-didnt-choose/</guid><description>AI code generation doesn't just write your Java. It picks your suppliers, edits your build and pulls in ecosystems you don't know. What Maven developers should check.</description></item><item><title>AI Found the Bugs. Who's Patching Your EOL Java Code?</title><link>http://foojayio.github.io/website/today/ai-found-the-bugs-whos-patching-your-eol-java-code/</link><pubDate>Thu, 23 Jul 2026 15:26:53 +0000</pubDate><category>AI</category><category>Java</category><category>Security</category><guid>http://foojayio.github.io/website/today/ai-found-the-bugs-whos-patching-your-eol-java-code/</guid><description>AI finds decades-old flaws at machine speed, but the fixes only reach supported versions. What that means for end-of-life Java, and what to do.</description></item><item><title>Foojay Podcast #100: Java Podcasters on Why They Started, What Broke, and What They Learned</title><link>http://foojayio.github.io/website/today/foojay-podcast-100/</link><pubDate>Mon, 13 Jul 2026 07:05:59 +0000</pubDate><category>Foojay</category><category>Java</category><category>Podcast</category><guid>http://foojayio.github.io/website/today/foojay-podcast-100/</guid><description>Foojay Podcast hits episode 100. No plan, no roadmap. It just happened. To mark the occasion, Frank turned the microphone around and invited other…</description></item><item><title>7 Jackson CVEs in One Day: AI-Assisted Security Research</title><link>http://foojayio.github.io/website/today/7-new-vulnerabilities-in-jackson-in-one-day-this-is-what-ai-assisted-security-research-looks-like/</link><pubDate>Mon, 29 Jun 2026 11:47:41 +0000</pubDate><category>Java</category><category>Security</category><guid>http://foojayio.github.io/website/today/7-new-vulnerabilities-in-jackson-in-one-day-this-is-what-ai-assisted-security-research-looks-like/</guid><description>Seven jackson-databind vulnerabilities, one researcher, one day. Two critical RCEs. This is AI-assisted security research in practice.</description></item><item><title>Did AI Just Break Software Security For Ever?</title><link>http://foojayio.github.io/website/today/did-ai-just-break-software-security-for-ever/</link><pubDate>Tue, 16 Jun 2026 14:51:04 +0000</pubDate><category>Java</category><category>Security</category><guid>http://foojayio.github.io/website/today/did-ai-just-break-software-security-for-ever/</guid><description>AI finds exploits in hours. Patch cycles run 30–60 days. EOL software gets neither. Here's what changed in 2026 and what to do about it.</description></item><item><title>Spring Boot 3.5 Migration and the CRA: When Good Enough Isn't"</title><link>http://foojayio.github.io/website/today/spring-boot-migration-and-the-cra-when-good-enough-isnt/</link><pubDate>Fri, 05 Jun 2026 08:52:01 +0000</pubDate><category>Java</category><category>Security</category><guid>http://foojayio.github.io/website/today/spring-boot-migration-and-the-cra-when-good-enough-isnt/</guid><description>Spring Boot 3.5 reaches EOL on June 30. The legal context is about to change. Here's what 'without undue delay' means when commercial patches exist..</description></item><item><title>Foojay Podcast #95: Is Your Java App Actually Secure, Or Does It Just Look That Way?</title><link>http://foojayio.github.io/website/today/foojay-podcast-95/</link><pubDate>Mon, 11 May 2026 09:57:00 +0000</pubDate><category>Java</category><category>Java Core</category><category>Podcast</category><category>Security</category><guid>http://foojayio.github.io/website/today/foojay-podcast-95/</guid><description>Is your Java application actually secure, or does it just look that way? In this episode of the Foojay Podcast, Frank is joined by Steve Poole and David…</description></item><item><title>Spring Boot 3.5 EOL — The CVE Blind Spot Nobody Talks About</title><link>http://foojayio.github.io/website/today/crossing-the-river-styx-spring-boot-3-5-and-the-zombie-dependency-problem/</link><pubDate>Sun, 19 Apr 2026 13:37:13 +0000</pubDate><category>Java</category><category>Security</category><category>Spring</category><guid>http://foojayio.github.io/website/today/crossing-the-river-styx-spring-boot-3-5-and-the-zombie-dependency-problem/</guid><description>Spring Boot 3.5 goes EOL June 30, 2026. But the real risk isn't the migration. It's what happens to CVE reporting once a project reaches end of life.</description></item><item><title>Spring I/O 2026: Field Notes from Barcelona</title><link>http://foojayio.github.io/website/today/spring-i-o-2026-field-notes-from-barcelona/</link><pubDate>Fri, 17 Apr 2026 13:09:24 +0000</pubDate><category>Java</category><category>Spring</category><guid>http://foojayio.github.io/website/today/spring-i-o-2026-field-notes-from-barcelona/</guid><description>Three days at Spring I/O 2026 in Barcelona. Agents, Embabel, the sessions that didn't get the main stage, and a booth full of dragons</description></item><item><title>Why Java Developers Over-Trust AI-Generated Code</title><link>http://foojayio.github.io/website/today/why-java-developers-over-trust-ai-dependency-suggestions/</link><pubDate>Thu, 09 Apr 2026 10:45:36 +0000</pubDate><category>Java</category><category>Security</category><guid>http://foojayio.github.io/website/today/why-java-developers-over-trust-ai-dependency-suggestions/</guid><description>AI coding tools sound confident even when they're wrong. Here's the psychology behind why Java developers accept bad suggestions — and habits that help.</description></item><item><title>Grails Is Back: Inside the Apache Software Foundation Migration</title><link>http://foojayio.github.io/website/today/grails-isnt-done-yet-part-2-eol-spring-boot-and-what-comes-next/</link><pubDate>Wed, 01 Apr 2026 08:48:56 +0000</pubDate><category>Spring</category><guid>http://foojayio.github.io/website/today/grails-isnt-done-yet-part-2-eol-spring-boot-and-what-comes-next/</guid><description>Grails graduated to a Top-Level Apache project in 2025. Here's what the 18-month migration, Grails 7 release, and Spring Boot alignment mean for teams still running it.</description></item><item><title>Grails Is Back: Inside the Apache Software Foundation Migration</title><link>http://foojayio.github.io/website/today/grails-isnt-done-yet-part-1-inside-the-asf-reboot/</link><pubDate>Wed, 25 Mar 2026 08:30:21 +0000</pubDate><category>Developer Tools</category><category>Interviews</category><category>Java</category><category>Spring</category><category>Tools</category><guid>http://foojayio.github.io/website/today/grails-isnt-done-yet-part-1-inside-the-asf-reboot/</guid><description>Grails graduated to a Top-Level Apache project in 2025. Here's what the 18-month migration, Grails 7 release, and Spring Boot alignment mean for teams still running it.</description></item><item><title>Tomcat TLSv1.3 cipher configuration</title><link>http://foojayio.github.io/website/today/tomcat-tlsv13-cipher-configuration-spring-boot/</link><pubDate>Thu, 26 Feb 2026 18:02:34 +0000</pubDate><category>Apache Tomcat</category><category>Java</category><category>Security</category><category>Spring</category><guid>http://foojayio.github.io/website/today/tomcat-tlsv13-cipher-configuration-spring-boot/</guid><description>A Tomcat update splits TLSv1.3 cipher configuration into a new attribute, silently dropping your Spring Boot cipher restrictions. Here's how to fix it.</description></item><item><title>Shai-Hulud and the npm Worm: How Speed-Optimised Dev Ecosystems Made a Self-Propagating Supply Chain Attack Inevitable</title><link>http://foojayio.github.io/website/today/the-shai-hulud-cyber-worm-and-more-thoughts-on-supply-chain-attacks/</link><pubDate>Thu, 12 Feb 2026 11:47:48 +0000</pubDate><category>DevOps</category><category>Security</category><guid>http://foojayio.github.io/website/today/the-shai-hulud-cyber-worm-and-more-thoughts-on-supply-chain-attacks/</guid><description>first, a word about ecosystems Before we dive into Shai-Hulud, before we label it “sophisticated” or “advanced” or “next generation,” we need to be honest…</description></item><item><title>FOSDEM 2026: Open Source Supply Chains, CRA Compliance, and the Future of Software</title><link>http://foojayio.github.io/website/today/fosdem-2026-and-the-open-source-firehose/</link><pubDate>Mon, 02 Feb 2026 22:52:20 +0000</pubDate><category>AI</category><category>Conference</category><category>Events</category><category>Trip Reports</category><guid>http://foojayio.github.io/website/today/fosdem-2026-and-the-open-source-firehose/</guid><description>Is open source hitting a watershed moment? After 8,000 developers converged for FOSDEM 2026, it’s clear that legal obligations and supply chain security are rewriting the rules. Discover why the…</description></item><item><title>Security Doesn’t Start at Liftoff</title><link>http://foojayio.github.io/website/today/security-doesnt-start-at-liftoff/</link><pubDate>Fri, 23 Jan 2026 10:22:31 +0000</pubDate><category>Security</category><guid>http://foojayio.github.io/website/today/security-doesnt-start-at-liftoff/</guid><description>This is a follow-on to the article The Real Mechanics of Vulnerabilities in an Upstream/Downstream, Topsy-Turvy EOL World. What you'll learn in this…</description></item></channel></rss>