<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Jonathan Vila on foojay.io - Friends of OpenJDK</title><link>https://foojayio.github.io/website/today/author/jonathan-vila/</link><description>Articles written by Jonathan Vila on foojay.io - Friends of OpenJDK</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 30 Mar 2026 18:55:59 +0000</lastBuildDate><atom:link href="https://foojayio.github.io/website/today/author/jonathan-vila/index.xml" rel="self" type="application/rss+xml"/><item><title>Best practices for Mastering AI Agents, Subagents, Skills &amp; MCP</title><link>https://foojayio.github.io/website/today/best-practices-for-working-with-ai-agents-subagents-skills-and-mcp/</link><pubDate>Mon, 30 Mar 2026 18:55:59 +0000</pubDate><guid>https://foojayio.github.io/website/today/best-practices-for-working-with-ai-agents-subagents-skills-and-mcp/</guid><description>&lt;p&gt;A practical guide to the five best practices every developer should apply when working with AI agents, subagents, skills and MCP servers &amp;mdash; from choosing the right model and writing precise prompts, to defining agent behaviour with SDD, isolating context with Claude Code subagents, securing MCP calls, and guiding agent response quality with guardrails.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="h2-0-0-where-this-fits-in-the-series"&gt;§0 📖 Where This Fits in the Series&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;This article assumes you already know what MCP is and have used or built at least one Agent.&lt;/p&gt;</description></item><item><title>DevBcn, the developer's conference in Barcelona</title><link>https://foojayio.github.io/website/today/devbcn-2026/</link><pubDate>Tue, 17 Feb 2026 09:56:33 +0000</pubDate><guid>https://foojayio.github.io/website/today/devbcn-2026/</guid><description>&lt;p&gt;Hola developers !!!!!&lt;/p&gt;
&lt;p&gt;The 11th edition of &lt;strong&gt;&lt;a href="http://www.devbcn.com" target="_blank" rel="noopener noreferrer"&gt;DevBcn&lt;/a&gt;
&lt;/strong&gt;, the developer&amp;rsquo;s conference in Barcelona is coming next June. The perfect place to have great technology talks 🤖, perfect weather 🏖️, amazing food 🥘, and an unforgettable experience 💖.&lt;/p&gt;
&lt;figure class="aligncenter size-full is-resized"&gt;
 &lt;a target="_blank" href="http://www.devbcn.com"&gt;&lt;img fetchpriority="high" decoding="async" width="1011" height="851" src="Screenshot-2026-02-17-at-10.35.06.png" alt="" class="wp-image-122749" style="aspect-ratio:1.18804004331396;width:564px;height:auto"&gt;&lt;/a&gt;
&lt;/figure&gt;
&lt;br /&gt;
&lt;p&gt;It will be hosted on the 16th and 17th of June 2026, in the &lt;strong&gt;World Trade Center Conference Center&lt;/strong&gt; , having 4 rooms with talks in parallel during the 2 days of the conference : &lt;strong&gt;Java/JVM, AI, Cloud, Frontend, Managing and Soft skills&lt;/strong&gt;.
&lt;img src="https://foojayio.github.io/website/today/devbcn-2026/unnamed-1-1024x282.png" alt="" loading="lazy"&gt;
&lt;/p&gt;</description></item><item><title>Windsurf AI and SonarQube The Dream Team for AI Code Quality</title><link>https://foojayio.github.io/website/today/windsurf-ai-java-code-quality/</link><pubDate>Mon, 16 Feb 2026 09:34:00 +0000</pubDate><guid>https://foojayio.github.io/website/today/windsurf-ai-java-code-quality/</guid><description>&lt;p&gt;Hola! 👋 As a Java developer, you probably spend a good chunk of your day making sure your code doesn&amp;rsquo;t just &amp;ldquo;work,&amp;rdquo; but is also maintainable, secure, and reliable. I&amp;rsquo;ve been using a tool that is changing how I handle large projects: &lt;strong&gt;Windsurf&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It is an agentic IDE that understands what you are trying to do across your whole project. Let&amp;rsquo;s see why this is a game-changer for our Java workflows. 🚀&lt;/p&gt;</description></item><item><title>Claude Code SonarQube MCP: A Java Developer’s Workflow</title><link>https://foojayio.github.io/website/today/claude-code-sonarqube-mcp/</link><pubDate>Mon, 02 Feb 2026 15:15:17 +0000</pubDate><guid>https://foojayio.github.io/website/today/claude-code-sonarqube-mcp/</guid><description>&lt;p&gt;Hola Java developers! 👋&lt;/p&gt;
&lt;p&gt;We all know the feeling. You are &amp;ldquo;in the zone,&amp;rdquo; coding away in your terminal, feeling like a hacker from a 90s movie. But then, reality hits. You need to check a rule, review a vulnerability, or verify if your project passes the quality gate.&lt;/p&gt;
&lt;p&gt;What do you do? You Alt+Tab. You open the browser. You log in. You search. And just like that&amp;hellip; the flow is gone. 📉&lt;/p&gt;</description></item><item><title>SonarQube AI Code Assurance &amp; MCP: Auto-Fix Java (Part 4)</title><link>https://foojayio.github.io/website/today/sonarqube-part-4-ai-code-assurance/</link><pubDate>Mon, 19 Jan 2026 15:27:14 +0000</pubDate><guid>https://foojayio.github.io/website/today/sonarqube-part-4-ai-code-assurance/</guid><description>&lt;p&gt;Hola Java developers! 👋&lt;/p&gt;
&lt;p&gt;Welcome to the &lt;strong&gt;Grand Finale&lt;/strong&gt; of our series.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-1/"&gt;Part 1&lt;/a&gt;
&lt;/strong&gt;: We turned your IDE into a fortress.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-2/"&gt;Part 2&lt;/a&gt;
&lt;/strong&gt;: We synced the team with Connected Mode.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://foojayio.github.io/website/today/avoid-the-trojan-horse-in-your-pom-xml-sonarqube-advanced-security-part-3/"&gt;Part 3&lt;/a&gt;
&lt;/strong&gt;: We secured the Supply Chain (dependencies).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We have become excellent at &lt;em&gt;finding&lt;/em&gt; bugs. But let&amp;rsquo;s be honest: Finding them is only half the battle. &lt;strong&gt;Who is going to fix them?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We are drowning in a backlog of &amp;ldquo;Technical Debt,&amp;rdquo; &amp;ldquo;Code Smells,&amp;rdquo; and &amp;ldquo;Security Hotspots.&amp;rdquo; You don&amp;rsquo;t have enough hours in the day to refactor every complex method or research the perfect fix for a regex denial-of-service vulnerability.&lt;/p&gt;</description></item><item><title>How to choose your LLM without ruining your Java code</title><link>https://foojayio.github.io/website/today/dev-guide-how-to-choose-your-llm/</link><pubDate>Fri, 09 Jan 2026 19:49:47 +0000</pubDate><guid>https://foojayio.github.io/website/today/dev-guide-how-to-choose-your-llm/</guid><description>&lt;p&gt;Let&amp;rsquo;s be honest: when we try a new AI model, the first thing we look at is if the code compiles and does what we asked. But if you have been in the Java world for a while, you know that &lt;strong&gt;&amp;ldquo;working&amp;rdquo; is just level 1&lt;/strong&gt;. The real final boss is reliability, maintenance and security. 💀&lt;/p&gt;
&lt;p&gt;I have been analyzing the latest &lt;a href="https://www.sonarsource.com/the-coding-personalities-of-leading-llms/leaderboard/" target="_blank" rel="noopener noreferrer"&gt;&lt;strong&gt;Sonar Leaderboard&lt;/strong&gt;&lt;/a&gt;
 (with fresh data from late 2025/2026 on 4,444 tasks) and there are big surprises.
&lt;img src="https://foojayio.github.io/website/today/dev-guide-how-to-choose-your-llm/Screenshot-2026-01-09-at-19.51.02-1024x528.png" alt="" loading="lazy"&gt;
&lt;/p&gt;</description></item><item><title>Stop the trojan horse in your pom : SonarQube Advace Security</title><link>https://foojayio.github.io/website/today/avoid-the-trojan-horse-in-your-pom-xml-sonarqube-advanced-security-part-3/</link><pubDate>Mon, 22 Dec 2025 10:42:41 +0000</pubDate><guid>https://foojayio.github.io/website/today/avoid-the-trojan-horse-in-your-pom-xml-sonarqube-advanced-security-part-3/</guid><description>&lt;p&gt;Hola Java developers! 👋&lt;/p&gt;
&lt;p&gt;Welcome to &lt;strong&gt;Part 3&lt;/strong&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;In &lt;a href="https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-1/"&gt;&lt;strong&gt;Part 1&lt;/strong&gt;&lt;/a&gt;
, we turned your IntelliJ into a security guard.&lt;/li&gt;
&lt;li&gt;In &lt;a href="https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-2/"&gt;&lt;strong&gt;Part 2&lt;/strong&gt;&lt;/a&gt;
, we connected it to the server to enforce the Quality Gate.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We are feeling good. Our code is high quality. Our logic is sound. But here is the scary reality: In a modern Spring Boot application, &lt;strong&gt;you only wrote about 10% of the code.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The other 90%? It comes from Maven Central. It&amp;rsquo;s Hibernate, Jackson, Apache Commons, Spring Security&amp;hellip; You are building a house, and you made sure &lt;em&gt;your&lt;/em&gt; bricks are solid. But did you check if the foundation you bought from a stranger is made of explosive material? 🧨&lt;/p&gt;</description></item><item><title>Java developer's guide : Sync Rules &amp; Stop CI Failures</title><link>https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-2/</link><pubDate>Tue, 16 Dec 2025 15:53:28 +0000</pubDate><guid>https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-2/</guid><description>&lt;p&gt;Hola Java developers! 👋&lt;/p&gt;
&lt;p&gt;Welcome back. In &lt;a href="https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-1/"&gt;&lt;strong&gt;Part 1&lt;/strong&gt;&lt;/a&gt;
, we installed &lt;strong&gt;SonarQube for IDE&lt;/strong&gt; in IntelliJ. You are now catching those nasty NullPointerExceptions and Optional.get() risks &lt;em&gt;before&lt;/em&gt; they leave your keyboard.&lt;/p&gt;
&lt;p&gt;But&amp;hellip; you are not working alone. You are part of a team pushing code to a repo full of XML configs, DTOs, and Services.&lt;/p&gt;
&lt;p&gt;Here is the nightmare scenario: You spend all day refactoring your &lt;strong&gt;Spring Boot&lt;/strong&gt; service. It looks perfect. You run your tests. They pass. You push it to Git. You grab a coffee. ☕ And then&amp;hellip; &lt;strong&gt;FAIL.&lt;/strong&gt; 🔴&lt;/p&gt;</description></item><item><title>SonarQube for IDE in IntelliJ: The Ultimate Java Developer’s Guide</title><link>https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-1/</link><pubDate>Fri, 12 Dec 2025 15:43:00 +0000</pubDate><guid>https://foojayio.github.io/website/today/developers-guide-to-sonarqube-part-1/</guid><description>&lt;p&gt;Hola Java developers! 👋&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s be honest. We have all been there. You write a piece of code, it compiles perfectly, the unit tests pass, and you think: &lt;em&gt;&amp;ldquo;This is solid.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Then&amp;hellip; boom. The CI/CD pipeline fails 20 minutes later because of a security vulnerability. Or worse, a NullPointerException wakes you up on the weekend because you forgot to check if that Optional was actually present.&lt;/p&gt;
&lt;p&gt;We want to deliver &lt;strong&gt;High&lt;/strong&gt; &lt;strong&gt;Code Quality and Security&lt;/strong&gt;, but we are humans. We get tired, we lose focus.&lt;/p&gt;</description></item><item><title>The 5 Knights of the MCP Apocalypse 😱</title><link>https://foojayio.github.io/website/today/the-5-knights-of-the-mcp-apocalypse/</link><pubDate>Tue, 09 Dec 2025 15:55:41 +0000</pubDate><guid>https://foojayio.github.io/website/today/the-5-knights-of-the-mcp-apocalypse/</guid><description>&lt;p&gt;Let&amp;rsquo;s talk about that new &lt;strong&gt;MCP (Model Context Protocol) Server&lt;/strong&gt; your team is using to connect to your real data services. It&amp;rsquo;s awesome, right? It&amp;rsquo;s the &amp;ldquo;magic box&amp;rdquo; that gives your AI Agent access to the &lt;strong&gt;real world&lt;/strong&gt;&amp;mdash;live databases, internal APIs, and all your tools.&lt;/p&gt;
&lt;p&gt;But here&amp;rsquo;s the catch: &lt;strong&gt;you don&amp;rsquo;t own the code.&lt;/strong&gt; 🚫&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s a vendor product, an open-source project, or another team&amp;rsquo;s platform. You can&amp;rsquo;t just change its code when you find a security hole, unless you have the code and recompile it and deploy it.&lt;/p&gt;</description></item><item><title>A Guide to SonarQube MCP Server on IntelliJ</title><link>https://foojayio.github.io/website/today/your-new-ai-powered-coding-buddy-a-guide-to-sonarqube-mcp-server-on-intellij/</link><pubDate>Fri, 07 Nov 2025 17:00:24 +0000</pubDate><guid>https://foojayio.github.io/website/today/your-new-ai-powered-coding-buddy-a-guide-to-sonarqube-mcp-server-on-intellij/</guid><description>&lt;p&gt;Hey Java devs! 👋 Ever feel like you&amp;rsquo;re drowning in a sea of code, trying to keep it reliable,, efficient, and secure? We&amp;rsquo;ve all been there. Juggling new features, bug fixes, and pull requests is a daily grind. But what if you had an AI-powered assistant to help you out? That&amp;rsquo;s where the &lt;a href="https://github.com/SonarSource/sonarqube-mcp-server" target="_blank" rel="noopener noreferrer"&gt;&lt;strong&gt;SonarQube MCP Server&lt;/strong&gt;&lt;/a&gt;
 comes in. Let&amp;rsquo;s dive into how this cool new MCP can supercharge your daily coding routine. 🚀&lt;/p&gt;</description></item><item><title>Sonar Connect Zurich</title><link>https://foojayio.github.io/website/today/sonar-connect-zurich/</link><pubDate>Mon, 03 Nov 2025 17:19:16 +0000</pubDate><guid>https://foojayio.github.io/website/today/sonar-connect-zurich/</guid><description>&lt;p&gt;&lt;strong&gt;Sonar Connect Zurich: Maximize the ROI of your generative AI projects&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Where?&lt;/strong&gt; AWS Offices Event Space - Marsstrasse 2, 8002 Zurich, Switzerland&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;When?&lt;/strong&gt; November 18, 13:00 - 17:00&lt;/p&gt;
&lt;p&gt;Generative AI projects&amp;mdash;especially code assistants&amp;mdash;introduce new complexities. Maintaining code quality and security is paramount to control the exponential growth of technical debt and ensure you achieve the desired return on investment (ROI). Join us at the AWS offices to:&lt;/p&gt;
&lt;p&gt;Gain insights on the key success factors for Gen AI coding projects, based on data from thousands of customers.&lt;/p&gt;</description></item><item><title>Let's create an AI MCP server with Quarkus</title><link>https://foojayio.github.io/website/today/lets-talk-about-mcp/</link><pubDate>Mon, 03 Nov 2025 10:15:45 +0000</pubDate><guid>https://foojayio.github.io/website/today/lets-talk-about-mcp/</guid><description>&lt;h2 id="h2-0-hey-java-devs-let-s-talk-about-ai-mcp"&gt;&lt;strong&gt;Hey Java Devs, Let&amp;rsquo;s Talk About AI MCP! 🤖&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Ever feel like your AI models are stuck in a bubble, cut off from the real-time data and tools they need to be truly useful? Well, you&amp;rsquo;re not alone! This has been a major headache for developers. But what if I told you there&amp;rsquo;s a new sheriff in town that&amp;rsquo;s changing the game? Enter the &lt;strong&gt;Model Context Protocol (MCP)&lt;/strong&gt;.&lt;/p&gt;
&lt;h3 id="h3-1-so-what-s-the-big-deal-with-mcp"&gt;&lt;strong&gt;So, What&amp;rsquo;s the Big Deal with MCP?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Think of MCP as a universal translator for your AI. It&amp;rsquo;s an open standard that lets AI assistants, like large language models (LLMs), seamlessly connect with external data sources, tools, and just about any environment you can think of. No more building custom, one-off integrations for every single tool and data source. With MCP, you create a standardized way for your AI to talk to the outside world. Pretty neat, huh? 😉&lt;/p&gt;</description></item><item><title>7 habits of Highly Effective Java Coding</title><link>https://foojayio.github.io/website/today/7-habits-of-highly-effective-java-coding/</link><pubDate>Wed, 15 Oct 2025 11:25:03 +0000</pubDate><guid>https://foojayio.github.io/website/today/7-habits-of-highly-effective-java-coding/</guid><description>&lt;h3 id="h3-0-from-ai-user-to-ai-pro"&gt;&lt;strong&gt;From AI User to AI Pro&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Let&amp;rsquo;s be real, AI coding tools are everywhere now. 🤖 They&amp;rsquo;re no longer some shiny new toy&amp;mdash;they&amp;rsquo;re a part of our daily grind as developers, just like our morning coffee. ☕&lt;/p&gt;
&lt;p&gt;For us Java devs, whether we&amp;rsquo;re wrestling with a giant legacy app or juggling a bunch of microservices, these tools look like a huge win for getting stuff done faster. 🚀&lt;/p&gt;
&lt;p&gt;But here&amp;rsquo;s the catch: just coding faster isn&amp;rsquo;t the whole story. If you&amp;rsquo;re not careful, it can actually lead to bigger problems down the road. 🤔&lt;/p&gt;</description></item><item><title>AI4Devs - Schedule published</title><link>https://foojayio.github.io/website/today/ai4devs-schedule-published/</link><pubDate>Mon, 01 Sep 2025 20:05:04 +0000</pubDate><guid>https://foojayio.github.io/website/today/ai4devs-schedule-published/</guid><description>&lt;p&gt;The wait is over&amp;mdash;&lt;strong&gt;AI4Devs Amsterdam has just published its official schedule&lt;/strong&gt;, and it&amp;rsquo;s packed with talks that every developer working with (or curious about) AI will want to catch.&lt;/p&gt;
&lt;p&gt;From live coding sessions to hands-on workshops, from security insights to multi-agent architectures&amp;mdash;the program is designed to keep things practical, technical, and deeply relevant.&lt;/p&gt;
&lt;p&gt;Whether you&amp;rsquo;re already building AI-powered systems or just starting to explore what&amp;rsquo;s possible, this year&amp;rsquo;s edition has something for you. Let&amp;rsquo;s take a look at the highlights.&lt;/p&gt;</description></item><item><title>AI Gives Time, Not Confidence: Developer Productivity Toolkit</title><link>https://foojayio.github.io/website/today/ai-gives-time-not-confidence-developer-productivity-toolkit/</link><pubDate>Mon, 25 Aug 2025 07:07:56 +0000</pubDate><guid>https://foojayio.github.io/website/today/ai-gives-time-not-confidence-developer-productivity-toolkit/</guid><description>&lt;p&gt;Let&amp;rsquo;s be real &amp;ndash; keeping up with the pace of software development today is intense. New frameworks pop up and the push for faster, better, &lt;em&gt;and&lt;/em&gt; more secure code never stops.&lt;/p&gt;
&lt;p&gt;This article is all about cutting through the buzz and looking at how AI-powered tools can actually help you, the Java developer, day-to-day. We&amp;rsquo;ll dive into specific ways AI can help you through the whole SDLC:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Understanding Complex Tasks&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Accelerating Code Creation&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Streamlining Cloud Deployment&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Creating Effective Tests&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Increasing Code Quality and Security&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Improving Code Review&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Okay, first up: wrapping your head around the job at hand. You know those moments where you need to implement a feature based on requirements that feel a bit&amp;hellip; fuzzy. Traditionally, this means lots of reading, maybe drawing diagrams, and asking clarifying questions.&lt;/p&gt;</description></item><item><title>Foojay Podcast #77: DevBcn Report, Part 2 – Spanish Knowledge Sharing</title><link>https://foojayio.github.io/website/today/foojay-podcast-77/</link><pubDate>Mon, 28 Jul 2025 06:49:00 +0000</pubDate><guid>https://foojayio.github.io/website/today/foojay-podcast-77/</guid><description>&lt;p&gt;This is the first Foojay podcast in Spanish. It&amp;rsquo;s also the shortest one and the final of season 4 😉 Jonathan Vila &amp;ldquo;highjacked&amp;rdquo; the microphone from Geertjan Wielenga (See &lt;a href="https://foojayio.github.io/website/today/foojay-podcast-76-devbcn-report-part-1-learn-from-the-community/"&gt;episode 76&lt;/a&gt;
) during the DevBcn conference in Barcelona and interviewed a few of the participants for this first Spanish-only edition of the podcast.&lt;/p&gt;
&lt;p&gt;Stay tuned and subscribe to the podcast in your favorite app or on YouTube. We&amp;rsquo;re taking a short break and will be back in September with the launch of Java 25!&lt;/p&gt;</description></item><item><title>Java 22 to 24: Level up your Java Code by embracing new features in a safe way</title><link>https://foojayio.github.io/website/today/java-22-to-24-level-up-your-java-code-by-embracing-new-features-in-a-safe-way/</link><pubDate>Wed, 23 Jul 2025 15:29:09 +0000</pubDate><guid>https://foojayio.github.io/website/today/java-22-to-24-level-up-your-java-code-by-embracing-new-features-in-a-safe-way/</guid><description>&lt;h3 id="h3-0-java-introduces-several-new-language-features-in-the-22-to-24-versions-which-collectively-simplify-code-enhance-documentation-and-provide-powerful-tools-for-bytecode-manipulation-and-advanced-stream-processing-this-article-shows-you-how-to-leverage-these-new-features-with-simple-examples"&gt;Java introduces several new language features in the 22 to 24 versions which collectively simplify code, enhance documentation, and provide powerful tools for bytecode manipulation and advanced stream processing. This article shows you how to leverage these new features with simple examples.&lt;/h3&gt;
&lt;p&gt;Understanding these new features in Java is crucial for writing updated, efficient, and high quality code. To assist developers in adopting these changes correctly, SonarQube has introduced &lt;a href="https://rules.sonarsource.com/java/tag/java22" target="_blank" rel="noopener noreferrer"&gt;several new rules&lt;/a&gt;
 designed to check for the proper usage of unnamed variables and patterns, javadoc and markdown, Class-file new API and Stream gatherers, ensuring your code adheres to best practices and avoids common pitfalls.&lt;/p&gt;</description></item><item><title>Foojay Podcast #76: DevBcn Report, Part 1 – Learn from the Community</title><link>https://foojayio.github.io/website/today/foojay-podcast-76/</link><pubDate>Mon, 21 Jul 2025 06:41:00 +0000</pubDate><guid>https://foojayio.github.io/website/today/foojay-podcast-76/</guid><description>&lt;p&gt;In early July, the DevBcn conference in Barcelona featured a diverse lineup of speakers, covering topics across multiple technology domains. Geertjan Wielenga took the camera and microphone with him to Spain. Together with Nacho Cougil and Jonathan Vila, two of the organizers, he spoke with many visitors about what they like most in Java, how AI influences their work, and what is important to them in the work they do.&lt;/p&gt;</description></item><item><title>New AI Conference For And By Developers</title><link>https://foojayio.github.io/website/today/new-ai-conference-for-and-by-developers/</link><pubDate>Mon, 07 Jul 2025 11:50:54 +0000</pubDate><guid>https://foojayio.github.io/website/today/new-ai-conference-for-and-by-developers/</guid><description>&lt;p&gt;AI4DEVS, &lt;strong&gt;September 19, 2025&lt;/strong&gt; in Amsterdam, is created &lt;strong&gt;for and by developers working with AI technologies&lt;/strong&gt; . Our mission is simple: share practical, usable knowledge with real use cases and code. Whether you&amp;rsquo;re an experienced AI engineer or just starting to explore machine learning in your applications, AI4DEVS offers &lt;strong&gt;valuable knowledge for every level&lt;/strong&gt; . All the details are here: &lt;a href="https://amsterdam.ai4devs.io/" target="_blank" rel="noopener noreferrer"&gt;https://amsterdam.ai4devs.io/&lt;/a&gt;

&lt;a href="https://amsterdam.ai4devs.io/" target="_blank" rel="noopener noreferrer"&gt;&lt;img src="https://foojayio.github.io/website/today/new-ai-conference-for-and-by-developers/ai4devs0-1024x616.png" alt="" loading="lazy"&gt;
&lt;/a&gt;
 &lt;a href="https://amsterdam.ai4devs.io/" target="_blank" rel="noopener noreferrer"&gt;&lt;img src="https://foojayio.github.io/website/today/new-ai-conference-for-and-by-developers/ai4devs-730x1024.png" alt="" loading="lazy"&gt;
&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;All the details are here: &lt;a href="https://amsterdam.ai4devs.io/" target="_blank" rel="noopener noreferrer"&gt;https://amsterdam.ai4devs.io/&lt;/a&gt;
&lt;/p&gt;</description></item><item><title>Sonar Connect Amsterdam 2025</title><link>https://foojayio.github.io/website/today/sonar-connect-amsterdam-2025/</link><pubDate>Mon, 16 Jun 2025 15:51:13 +0000</pubDate><guid>https://foojayio.github.io/website/today/sonar-connect-amsterdam-2025/</guid><description>&lt;h3 id="h3-0-code-quality-code-security-for-open-source-ai-code"&gt;Code quality + Code security for Open Source &amp;amp; AI code&lt;/h3&gt;
&lt;p&gt;In the age of AI, ensuring code quality and code security is more critical than ever. Are you using the best methodologies to introduce GenAI in your company? do you know the risks? have you heard about AI MCP and the benefits ? what about using AI in the full SDLC? do you know the latest features of SonarQube regarding AI and SCA(dependencies vulnerabilities)?&lt;/p&gt;</description></item><item><title>AI-Driven Testing Best Practices</title><link>https://foojayio.github.io/website/today/ai-driven-testing-best-practices/</link><pubDate>Mon, 26 May 2025 08:06:15 +0000</pubDate><guid>https://foojayio.github.io/website/today/ai-driven-testing-best-practices/</guid><description>&lt;h2 id="h2-0-so-ai-can-write-tests-now-cool-but"&gt;&lt;strong&gt;So, AI Can Write Tests Now? Cool, But&amp;hellip;&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;AI assisted coding tools are everywhere now, helping with autocomplete, suggesting fixes, and sometimes writing surprisingly large blocks of code. A hot topic is using generative AI to generate tests automatically &amp;ndash; unit, integration, e2e, etc.&lt;/p&gt;
&lt;p&gt;The idea&amp;rsquo;s definitely appealing. Who wouldn&amp;rsquo;t want an AI to help crank out tests, bump up those coverage numbers, and maybe save us from some of the testing grind? It sounds like a fast track to better feedback and tackling that mountain of untested code.&lt;/p&gt;</description></item><item><title>Code Reviews with AI a developer guide</title><link>https://foojayio.github.io/website/today/code-reviews-with-ai-a-developer-guide/</link><pubDate>Fri, 07 Mar 2025 12:10:37 +0000</pubDate><guid>https://foojayio.github.io/website/today/code-reviews-with-ai-a-developer-guide/</guid><description>&lt;p&gt;Code reviews are a cornerstone of software development. They&amp;rsquo;re where we share knowledge, catch bugs early, and ensure our code meets the highest standards.&lt;/p&gt;
&lt;p&gt;But let&amp;rsquo;s be honest&amp;hellip;&lt;/p&gt;
&lt;p&gt;Traditional code reviews can be time-consuming and tedious and sometimes even miss subtle yet critical issues. Enter the age of AI-powered code review, a game-changer that addresses these challenges and elevates code quality to new heights.&lt;/p&gt;
&lt;p&gt;This article dives into the common pitfalls of code reviews and explores how AI tools can revolutionize each phase of the development lifecycle.&lt;/p&gt;</description></item><item><title>Build local LLM applications with Quarkus, Ollama, Testcontainers</title><link>https://foojayio.github.io/website/today/building-local-llm-ai-powered-applications-with-quarkus-ollama-and-testcontainers/</link><pubDate>Thu, 27 Feb 2025 10:13:19 +0000</pubDate><guid>https://foojayio.github.io/website/today/building-local-llm-ai-powered-applications-with-quarkus-ollama-and-testcontainers/</guid><description>&lt;p&gt;Traditionally, many AI-powered applications rely on cloud-based APIs or centralized services for model hosting and execution. While this approach has its advantages, such as scalability and ease of use, it also introduces challenges around latency, data privacy, and dependency on third-party providers.&lt;/p&gt;
&lt;p&gt;This is where local AI models shine. By running models directly within your application&amp;rsquo;s infrastructure, you gain greater control over performance, data security, and deployment flexibility. However, building such systems requires the right tools and frameworks to bridge the gap between traditional software development and AI model integration.&lt;/p&gt;</description></item><item><title>Foojay Podcast #58: How Java Developers Can Secure Their Code</title><link>https://foojayio.github.io/website/today/foojay-podcast-58/</link><pubDate>Mon, 30 Sep 2024 07:43:46 +0000</pubDate><guid>https://foojayio.github.io/website/today/foojay-podcast-58/</guid><description>&lt;p&gt;Three years after Log4Shell caused a significant security issue, we still struggle with insecure dependencies and injection problems.&lt;/p&gt;
&lt;p&gt;In this podcast, we&amp;rsquo;ll discuss how developers can secure their code.&lt;/p&gt;
&lt;p&gt;I talked with three authors who posted a security and code quality post on Foojay.io.&lt;/p&gt;
&lt;h2 id="h2-0-video"&gt;Video&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
			&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/sRVcqILDuSo?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
		&lt;/div&gt;

&lt;h2 id="h2-1-podcast-apps"&gt;Podcast Apps&lt;/h2&gt;
&lt;p&gt;You can listen and subscribe to the Foojay Podcast on:&lt;/p&gt;</description></item><item><title>Top Security Flaws hiding in your code right now</title><link>https://foojayio.github.io/website/today/top-security-flaws-hiding-in-your-code-right-now-and-how-to-fix-them/</link><pubDate>Thu, 05 Sep 2024 16:41:02 +0000</pubDate><guid>https://foojayio.github.io/website/today/top-security-flaws-hiding-in-your-code-right-now-and-how-to-fix-them/</guid><description>&lt;h3 id="h3-0-recent-years-have-seen-numerous-injection-attacks-causing-significant-damage-including-a-2019-sql-injection-breach-in-the-fortnite-video-game-and-a-2018-attack-on-tesla-s-systems"&gt;Recent years have seen numerous injection attacks causing significant damage, including a 2019 SQL injection breach in the Fortnite video game and a 2018 attack on Tesla&amp;rsquo;s systems.&lt;/h3&gt;
&lt;p&gt;Other serious incidents involve the Log4Shell logging injection and a deserialization attack on Atlassian Jira. These examples show that various code vulnerabilities can affect any organization. This article will examine the three most common attack types&amp;mdash;SQL injection, Deserialization Injection, and Logging Injection&amp;mdash;and discuss ways to prevent them.&lt;/p&gt;</description></item><item><title>Ensuring the right usage of the Java 21 new features</title><link>https://foojayio.github.io/website/today/ensuring-the-right-usage-of-java-21-new-features/</link><pubDate>Sun, 14 Apr 2024 16:16:13 +0000</pubDate><guid>https://foojayio.github.io/website/today/ensuring-the-right-usage-of-java-21-new-features/</guid><description>&lt;p&gt;&lt;strong&gt;Last September 2023 a new version of Java was released as the latest LTS (Long Time Support). This 21st version &lt;a href="https://www.sonarsource.com/blog/the-new-jdk-lts-is-out-long-live-jdk-21/" title="brought lots of new features" target="_blank" rel="noopener noreferrer"&gt;brought lots of new features&lt;/a&gt;
 that will improve performance and clarity in our code base.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;But taking advantage of these changes and new features, which we are not used to including in our code, can be a tough task. Also, it can lead to improper use or poor uptake, bugs, or basically not taking full advantage of new improvements.&lt;/p&gt;</description></item><item><title>More readability &amp; less complexity with Java's Pattern Matching.</title><link>https://foojayio.github.io/website/today/increase-readability-and-reduce-complexity-with-javas-pattern-matching/</link><pubDate>Thu, 14 Mar 2024 13:29:36 +0000</pubDate><guid>https://foojayio.github.io/website/today/increase-readability-and-reduce-complexity-with-javas-pattern-matching/</guid><description>&lt;p&gt;&lt;strong&gt;Increase readability, reduce cognitive complexity, and avoid bugs that are hard to spot with Java&amp;rsquo;s Pattern Matching.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I bet you don&amp;rsquo;t like writing ugly but necessary boilerplate code or reading it. But, sometimes we need to create logic that has to deal with an object of unknown type and follow different paths depending on the type. This code is prone to be too verbose, is complex to understand, and may involve some hidden errors hard to spot due to intermediate assignments.&lt;/p&gt;</description></item><item><title>Builders, Withers, and Records - Java’s path to immutability</title><link>https://foojayio.github.io/website/today/builders-withers-and-records-javas-path-to-immutability/</link><pubDate>Wed, 28 Feb 2024 12:19:11 +0000</pubDate><guid>https://foojayio.github.io/website/today/builders-withers-and-records-javas-path-to-immutability/</guid><description>&lt;p&gt;&lt;strong&gt;We know that immutable objects are easier to maintain, lead to fewer errors, and are multi-thread friendly. In this article, I will talk about two different approaches in Java to creating objects: Builders and Withers, typically used in the context of immutable objects, along with a new type of immutable object in Java: Records.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;When it comes to creating objects in Java, we can use fluent approaches, especially for complex objects containing lots of fields, that will increase readability and also adaptability allowing us to evolve the code with lower impact on the existing code. And we want to because fluent code is both easier to read and easier to write.&lt;/p&gt;</description></item><item><title>Java top most detected issues</title><link>https://foojayio.github.io/website/today/top-most-detected-issues-in-java-projects/</link><pubDate>Wed, 14 Feb 2024 09:49:16 +0000</pubDate><guid>https://foojayio.github.io/website/today/top-most-detected-issues-in-java-projects/</guid><description>&lt;p&gt;&lt;strong&gt;Using the telemetry from SonarLint after analyzing thousands of projects, these are the top most raised issues in Java projects.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We know that having clean code in our projects is important, and every developer would agree on that. But, according to what SonarLint telemetry shows, there are still lots of issues that appear in the huge list of analyzed projects.&lt;/p&gt;
&lt;p&gt;From the SonarLint telemetry for the last 2 years, with more than 2.5 million issues, I have taken the top most common issues happening in Java projects, from the +600 rules covering the language, considering quality and security to see how we can avoid them and align our code a bit more towards having a consistent, intentional, adaptable, and responsible code.&lt;/p&gt;</description></item></channel></rss>