AI Found the Bugs. Who's Patching Your EOL Java Code?
AI finds decades-old flaws at machine speed, but the fixes only reach supported versions. What that means for end-of-life Java, and what to …

Java Champion | Oracle ACE | AI and Software Supply Chain Security Consultant | Developer Advocate | DevOps Geek | HeroDevs

AI finds decades-old flaws at machine speed, but the fixes only reach supported versions. What that means for end-of-life Java, and what to …

Foojay Podcast hits episode 100. No plan, no roadmap. It just happened. To mark the occasion, Frank turned the microphone around and invited …

Seven jackson-databind vulnerabilities, one researcher, one day. Two critical RCEs. This is AI-assisted security research in practice.

AI finds exploits in hours. Patch cycles run 30–60 days. EOL software gets neither. Here's what changed in 2026 and what to do about it.

Spring Boot 3.5 reaches EOL on June 30. The legal context is about to change. Here's what 'without undue delay' means when commercial …

Is your Java application actually secure, or does it just look that way? In this episode of the Foojay Podcast, Frank is joined by Steve …

Spring Boot 3.5 goes EOL June 30, 2026. But the real risk isn't the migration. It's what happens to CVE reporting once a project reaches end …

Three days at Spring I/O 2026 in Barcelona. Agents, Embabel, the sessions that didn't get the main stage, and a booth full of dragons

AI coding tools sound confident even when they're wrong. Here's the psychology behind why Java developers accept bad suggestions — and …
Grails graduated to a Top-Level Apache project in 2025. Here's what the 18-month migration, Grails 7 release, and Spring Boot alignment mean …
Grails graduated to a Top-Level Apache project in 2025. Here's what the 18-month migration, Grails 7 release, and Spring Boot alignment mean …

first, a word about ecosystems Before we dive into Shai-Hulud, before we label it “sophisticated” or “advanced” or “next generation,” we …

Is open source hitting a watershed moment? After 8,000 developers converged for FOSDEM 2026, it’s clear that legal obligations and supply …

This is a follow-on to the article The Real Mechanics of Vulnerabilities in an Upstream/Downstream, Topsy-Turvy EOL World. What you'll learn …

In this article you’ll learn Why CVEs record that a vulnerability exists, not that a usable fix exists How vulnerabilities are often …

As we settle into 2025, legislation around AI and cybercrime is no longer a distant threat or vague aspiration.

The takeaways of moving to a data-driven and test portability approach are more than a quality improvement.

This is part 2 of the interviews we recorded at the JCON conference earlier this month in Germany. In this episode, you get two main topics: …

The “enlightenment roadmap” of a Java developer can be scary. How do you become the 10x Java Developer you always dreamed of becoming?

AI and Java what is there?, what can it do?, what do we want it to do?, Asking for your input readers. Share your thoughts at Foojay.io

Dive into the highlights from Sonatype's 9th edition of the 'State of the Software Supply Chain Report.' Discover insights on open source …

Friends of OpenJDK Community Survey. Kickoff and instructions for a community driven data gathering exercise.

Software bill of materials, anyone? A year ago, developers had not heard of the 'SBOM' acronym... and now SBOM visualiser called BOM Doctor.