<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Steve Poole on foojay.io - Friends of OpenJDK</title><link>https://foojayio.github.io/website/today/author/steve-poole/</link><description>Articles written by Steve Poole on foojay.io - Friends of OpenJDK</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 23 Jul 2026 15:26:53 +0000</lastBuildDate><atom:link href="https://foojayio.github.io/website/today/author/steve-poole/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Found the Bugs. Who's Patching Your EOL Java Code?</title><link>https://foojayio.github.io/website/today/ai-found-the-bugs-whos-patching-your-eol-java-code/</link><pubDate>Thu, 23 Jul 2026 15:26:53 +0000</pubDate><guid>https://foojayio.github.io/website/today/ai-found-the-bugs-whos-patching-your-eol-java-code/</guid><description>&lt;p&gt;Earlier this year an AI model found a flaw in OpenBSD&amp;rsquo;s TCP stack that had been sitting there for 27 years. The same scanning run turned up a 16-year-old bug in FFmpeg&amp;rsquo;s H.264 code.&lt;/p&gt;
&lt;h4 id="how-do-you-feel-about-ai-being-used-to-discover-bugs-in-open-source-across-the-board-and-at-scale"&gt;How do you feel about AI being used to discover bugs in open source, across the board and at scale?&lt;/h4&gt;
&lt;p&gt;Because that&amp;rsquo;s what&amp;rsquo;s happening. It&amp;rsquo;s tough enough dealing with machine-speed vulnerability discovery in code that has active maintainers. What about all the code with no friendly pair of safe hands?&lt;/p&gt;</description></item><item><title>Foojay Podcast #100: Java Podcasters on Why They Started, What Broke, and What They Learned</title><link>https://foojayio.github.io/website/today/foojay-podcast-100/</link><pubDate>Mon, 13 Jul 2026 07:05:59 +0000</pubDate><guid>https://foojayio.github.io/website/today/foojay-podcast-100/</guid><description>&lt;p&gt;Foojay Podcast hits episode 100. No plan, no roadmap. It just happened. To mark the occasion, Frank turned the microphone around and invited other podcasters: Adam Bien (airhacks.fm), Jennifer Reif (Breaktime Tech Talks), Kadi McKean and Steve Pool (10xInsights), and Oumaima Zerouali (JCast). Same three questions for each: why did you start, what broke, and what did you learn?&lt;/p&gt;
&lt;h2 id="h2-0-youtube"&gt;YouTube&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
			&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/PID--srP0_U?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
		&lt;/div&gt;

&lt;h2 id="h2-1-podcast-apps"&gt;Podcast Apps&lt;/h2&gt;
&lt;p&gt;You can listen and subscribe to the Foojay Podcast on:&lt;/p&gt;</description></item><item><title>7 Jackson CVEs in One Day: AI-Assisted Security Research</title><link>https://foojayio.github.io/website/today/7-new-vulnerabilities-in-jackson-in-one-day-this-is-what-ai-assisted-security-research-looks-like/</link><pubDate>Mon, 29 Jun 2026 11:47:41 +0000</pubDate><guid>https://foojayio.github.io/website/today/7-new-vulnerabilities-in-jackson-in-one-day-this-is-what-ai-assisted-security-research-looks-like/</guid><description>&lt;p&gt;&lt;strong&gt;Quick version check:&lt;/strong&gt; the affected range for all seven is broadly &lt;code&gt;&amp;gt;=2.10.0 =2.19.0 =3.0.0 &amp;lt;3.1.4&lt;/code&gt; &amp;mdash; with some CVEs affecting narrower ranges. If you&amp;rsquo;re on a supported release, upgrade to 2.18.8, 2.21.4, or 3.1.4. If you&amp;rsquo;re on an EOL line &amp;mdash; 2.13.x, 2.14.x, 2.15.x &amp;mdash; jump to the bottom of the page for more specifics or visit &lt;a href="https://docs.herodevs.com/jackson?utm_source=devrel&amp;amp;amp;utm_medium=referral&amp;amp;amp;utm_campaign=2026q2_spring-boot-3-5-eol_global" target="_blank" rel="noopener noreferrer"&gt;HeroDevs Jackson Support&lt;/a&gt;
&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="h3-0-not-a-sales-pitch"&gt;Not a sales pitch&lt;/h3&gt;
&lt;p&gt;Anyone who knows me knows I dont do that. In this case I&amp;rsquo;m pointing you at &lt;a href="https://docs.herodevs.com/jackson?utm_source=devrel&amp;amp;amp;utm_medium=referral&amp;amp;amp;utm_campaign=2026q2_spring-boot-3-5-eol_global" target="_blank" rel="noopener noreferrer"&gt;HeroDevs&lt;/a&gt;
 because the Jackson issues are serious, &lt;a href="https://docs.herodevs.com/jackson?utm_source=devrel&amp;amp;amp;utm_medium=referral&amp;amp;amp;utm_campaign=2026q2_spring-boot-3-5-eol_global" target="_blank" rel="noopener noreferrer"&gt;HeroDevs&lt;/a&gt;
 have a solution thats stupidly easy to use and I know the folks behind the fixes. It takes a particular type of engineer to create security fixes and I know they have that skillset. Do your own research.&lt;/p&gt;</description></item><item><title>Did AI Just Break Software Security For Ever?</title><link>https://foojayio.github.io/website/today/did-ai-just-break-software-security-for-ever/</link><pubDate>Tue, 16 Jun 2026 14:51:04 +0000</pubDate><guid>https://foojayio.github.io/website/today/did-ai-just-break-software-security-for-ever/</guid><description>&lt;p&gt;Whether the answer is yes or no (read on for my opinion) , something fundamental has changed this year. Not one thing. Four things, converging at once.&lt;/p&gt;
&lt;h3 id="h3-0-first-the-rate-of-cve-arrivals"&gt;First: The rate of CVE arrivals&lt;/h3&gt;
&lt;p&gt;More than 40,000 CVEs were published in 2024, rising to just under 50,000 in 2025. FIRST &amp;mdash; the Forum of Incident Response and Security Teams, &lt;a href="https://www.first.org/blog/20260522-vulnerability-forecast-update" title="projects" target="_blank" rel="noopener noreferrer"&gt;projects&lt;/a&gt;
 a median of 68,000 for 2026, with realistic scenarios reaching 70,000 to 100,000.&lt;/p&gt;</description></item><item><title>Spring Boot 3.5 Migration and the CRA: When Good Enough Isn't"</title><link>https://foojayio.github.io/website/today/spring-boot-migration-and-the-cra-when-good-enough-isnt/</link><pubDate>Fri, 05 Jun 2026 08:52:01 +0000</pubDate><guid>https://foojayio.github.io/website/today/spring-boot-migration-and-the-cra-when-good-enough-isnt/</guid><description>&lt;p&gt;Back in April I &lt;a href="https://foojayio.github.io/website/today/crossing-the-river-styx-spring-boot-3-5-and-the-zombie-dependency-problem/" title="wrote"&gt;wrote&lt;/a&gt;
 about what happens to your security posture when Spring Boot 3.5 crosses the EOL line.&lt;/p&gt;
&lt;p&gt;The short version: the CVE pipeline dries up, your scanner goes quiet, and the bad actors keep watching upstream for anything they can exploit downstream against the dead code nobody&amp;rsquo;s patching.&lt;/p&gt;
&lt;p&gt;I called them zombie dependencies.&lt;/p&gt;
&lt;p&gt;June 30th is coming. In a few weeks, Spring Boot 3.5 reaches end of open-source support. You&amp;rsquo;ve either got a plan or you haven&amp;rsquo;t.&lt;/p&gt;</description></item><item><title>Foojay Podcast #95: Is Your Java App Actually Secure, Or Does It Just Look That Way?</title><link>https://foojayio.github.io/website/today/foojay-podcast-95/</link><pubDate>Mon, 11 May 2026 09:57:00 +0000</pubDate><guid>https://foojayio.github.io/website/today/foojay-podcast-95/</guid><description>&lt;p&gt;Is your Java application actually secure, or does it just look that way? In this episode of the Foojay Podcast, Frank is joined by Steve Poole and David Welch, both from &lt;a href="https://www.herodevs.com/" target="_blank" rel="noopener noreferrer"&gt;HeroDevs&lt;/a&gt;
, to dig deep into the state of Java security in 2025 and beyond.&lt;/p&gt;
&lt;p&gt;Steve introduces the concept of zombie dependencies: end-of-life libraries that appear safely dormant but are quietly accumulating vulnerabilities waiting to bite you. David, a co-chair of the CVE Automation Working Group, explains what a CVE actually is, how the identification and disclosure process works in practice, and why AI tools like Mythos are dramatically accelerating the pace at which new vulnerabilities are found &amp;mdash; on both sides of the wall.&lt;/p&gt;</description></item><item><title>Spring Boot 3.5 EOL — The CVE Blind Spot Nobody Talks About</title><link>https://foojayio.github.io/website/today/crossing-the-river-styx-spring-boot-3-5-and-the-zombie-dependency-problem/</link><pubDate>Sun, 19 Apr 2026 13:37:13 +0000</pubDate><guid>https://foojayio.github.io/website/today/crossing-the-river-styx-spring-boot-3-5-and-the-zombie-dependency-problem/</guid><description>&lt;p&gt;Tomorrow I start (o so early) for &lt;a href="https://2026.europe.jcon.one/" target="_blank" rel="noopener noreferrer"&gt;JCON Europe&lt;/a&gt;
 in Cologne and then, at the tail end of the week, go to Devoxx France to give more talks. If you&amp;rsquo;re at either, come say hi. Herodevs has a booth at both.&lt;/p&gt;
&lt;p&gt;After digging into the CVE stories behind &lt;a href="https://foojayio.github.io/website/today/the-real-mechanics-of-vulnerabilities-in-an-upstream-downstream-topsy-turvy-eol-world/"&gt;Tomcat 8.5&amp;rsquo;s end of life&lt;/a&gt;
, I turned my attention to Spring Boot 3.5. Same question, different framework: what &lt;em&gt;actually&lt;/em&gt; happens to your security posture when a project crosses the EOL line?&lt;/p&gt;</description></item><item><title>Spring I/O 2026: Field Notes from Barcelona</title><link>https://foojayio.github.io/website/today/spring-i-o-2026-field-notes-from-barcelona/</link><pubDate>Fri, 17 Apr 2026 13:09:24 +0000</pubDate><guid>https://foojayio.github.io/website/today/spring-i-o-2026-field-notes-from-barcelona/</guid><description>&lt;p&gt;Spring I/O 2026 wrapped in Barcelona on Wednesday. Three days at the Palau de Congressos. A thousand-plus developers, five tracks, sixty sessions (or there abouts) Here are the things I&amp;rsquo;m still thinking about..&lt;/p&gt;
&lt;h2 id="h2-0-agents-everywhere"&gt;Agents everywhere&lt;/h2&gt;
&lt;p&gt;It was a Spring AI conference with a Spring Boot conference attached.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s not a complaint. Count the programme yourself. Across the two main days, roughly a third of the main-track sessions were about Spring AI, MCP, agents, or building on LLMs. Josh Long opened Day 2 at eleven with &lt;em&gt;Bootiful Spring Boot 4&lt;/em&gt; . By twelve, the Auditorium had moved on to &lt;em&gt;The Spring AI Ecosystem in 2026: From Foundations to Agents&lt;/em&gt;.&lt;/p&gt;</description></item><item><title>Why Java Developers Over-Trust AI-Generated Code</title><link>https://foojayio.github.io/website/today/why-java-developers-over-trust-ai-dependency-suggestions/</link><pubDate>Thu, 09 Apr 2026 10:45:36 +0000</pubDate><guid>https://foojayio.github.io/website/today/why-java-developers-over-trust-ai-dependency-suggestions/</guid><description>&lt;p&gt;&lt;em&gt;This article is adapted from &lt;a href="https://noregressions.substack.com/p/the-confidence-trap-why-developers" target="_blank" rel="noopener noreferrer"&gt;The Confidence Trap&lt;/a&gt;
, part of the &amp;ldquo;2026 Supply Chain Reckoning&amp;rdquo; series on my No Regressions newsletter.&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Your boss calls you on a Friday afternoon. He&amp;rsquo;s read all the available data, he tells you with absolute confidence, and he&amp;rsquo;s decided that migrating from Spring Boot 3.5 to 4.0 will be straightforward. Wants it done over the weekend.&lt;/p&gt;
&lt;p&gt;You&amp;rsquo;d push back. You&amp;rsquo;d ask which data. You&amp;rsquo;d point out the breaking changes.&lt;/p&gt;</description></item><item><title>Grails Is Back: Inside the Apache Software Foundation Migration</title><link>https://foojayio.github.io/website/today/grails-isnt-done-yet-part-2-eol-spring-boot-and-what-comes-next/</link><pubDate>Wed, 01 Apr 2026 08:48:56 +0000</pubDate><guid>https://foojayio.github.io/website/today/grails-isnt-done-yet-part-2-eol-spring-boot-and-what-comes-next/</guid><description>&lt;p&gt;In the &lt;a href="https://foojayio.github.io/website/today/grails-isnt-done-yet-part-1-inside-the-asf-reboot/"&gt;companion article&lt;/a&gt;
 to this one, I looked at the revitalisation of Grails under the Apache Software Foundation: the 18-month migration, the technical modernisation, and the release of Grails 7 as a Top-Level ASF Project. That is the good-news story, and it is a genuinely impressive piece of community engineering.&lt;/p&gt;
&lt;p&gt;This article is about the other side of the same coin.&lt;/p&gt;
&lt;p&gt;While Grails moves forward, many of the applications built on it cannot move at the same pace. The result is a growing gap between where the framework is heading and where a significant number of production systems actually sit. Understanding that gap, and what options exist for managing it, is what this piece is about.&lt;/p&gt;</description></item><item><title>Grails Is Back: Inside the Apache Software Foundation Migration</title><link>https://foojayio.github.io/website/today/grails-isnt-done-yet-part-1-inside-the-asf-reboot/</link><pubDate>Wed, 25 Mar 2026 08:30:21 +0000</pubDate><guid>https://foojayio.github.io/website/today/grails-isnt-done-yet-part-1-inside-the-asf-reboot/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Steve Poole | With contributions from James Fredley, Apache Grails PMC Chair&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;For a technology that many people filed under &amp;ldquo;legacy,&amp;rdquo; Grails has been unusually active. While much of the industry&amp;rsquo;s attention has drifted toward newer frameworks and shinier stacks, something more deliberate has been happening in the background.&lt;/p&gt;
&lt;p&gt;Grails has been moving into the Apache Software Foundation (ASF), modernising and positioning itself for the next chapter.&lt;/p&gt;
&lt;p&gt;If you have not looked at Grails recently, your mental model is likely several years out of date. And that, in many ways, is exactly the problem.&lt;/p&gt;</description></item><item><title>Shai-Hulud and the npm Worm: How Speed-Optimised Dev Ecosystems Made a Self-Propagating Supply Chain Attack Inevitable</title><link>https://foojayio.github.io/website/today/the-shai-hulud-cyber-worm-and-more-thoughts-on-supply-chain-attacks/</link><pubDate>Thu, 12 Feb 2026 11:47:48 +0000</pubDate><guid>https://foojayio.github.io/website/today/the-shai-hulud-cyber-worm-and-more-thoughts-on-supply-chain-attacks/</guid><description>&lt;h2 id="h2-0-first-a-word-about-ecosystems"&gt;first, a word about ecosystems&lt;/h2&gt;
&lt;p&gt;Before we dive into Shai-Hulud, before we label it &amp;ldquo;sophisticated&amp;rdquo; or &amp;ldquo;advanced&amp;rdquo; or &amp;ldquo;next generation,&amp;rdquo; we need to be honest about something.&lt;/p&gt;
&lt;p&gt;The worm didn&amp;rsquo;t appear in a broken system. It appeared in the one we deliberately optimised.&lt;/p&gt;
&lt;p&gt;In the book Dune, the worm is integral to the ecosystem. The planet, its environment, and the worms are deeply interconnected.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s true for the cyber-worm equivalent. The worm is an entirely predictable outcome of the ecosystem in which we, as developers, are part&lt;/p&gt;</description></item><item><title>FOSDEM 2026: Open Source Supply Chains, CRA Compliance, and the Future of Software</title><link>https://foojayio.github.io/website/today/fosdem-2026-and-the-open-source-firehose/</link><pubDate>Mon, 02 Feb 2026 22:52:20 +0000</pubDate><guid>https://foojayio.github.io/website/today/fosdem-2026-and-the-open-source-firehose/</guid><description>&lt;p&gt;&lt;em&gt;(a.k.a. &amp;ldquo;So&amp;hellip; what did you do this weekend?&amp;rdquo;)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m back from four days in Brussels and the uniquely exhausting experience that is FOSDEM. Mentally fried. Physically wrecked. Entirely glad I went.&lt;/p&gt;
&lt;h2 id="h2-0-the-chaos-and-the-crowd"&gt;The Chaos and the Crowd&lt;/h2&gt;
&lt;p&gt;Around 8,000 people made the trip this year. Some arrived for the first time; many returned as annual pilgrims.&lt;/p&gt;
&lt;p&gt;FOSDEM remains a strange outlier in the modern conference world: free to attend, no registration gatekeeping, and no sponsors dictating the tone. You just turn up.&lt;/p&gt;</description></item><item><title>Security Doesn’t Start at Liftoff</title><link>https://foojayio.github.io/website/today/security-doesnt-start-at-liftoff/</link><pubDate>Fri, 23 Jan 2026 10:22:31 +0000</pubDate><guid>https://foojayio.github.io/website/today/security-doesnt-start-at-liftoff/</guid><description>&lt;p&gt;This is a follow-on to the article &lt;a href="https://foojayio.github.io/website/today/the-real-mechanics-of-vulnerabilities-in-an-upstream-downstream-topsy-turvy-eol-world/"&gt;The Real Mechanics of Vulnerabilities in an Upstream/Downstream, Topsy-Turvy EOL World&lt;/a&gt;
.&lt;/p&gt;
&lt;h4 id="what-youll-learn-in-this-article"&gt;What you&amp;rsquo;ll learn in this article:&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The Security Timeline Inversion&lt;/strong&gt;: CVE disclosure is no longer the true start of the security timeline.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security Outcomes&lt;/strong&gt;: Routine maintenance decisions, not reaction speed or tooling, determine security outcomes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Flawed Indicators&lt;/strong&gt;: CVE scores, scanners, and compliance deadlines are not effective early-warning systems.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability Distortion&lt;/strong&gt;: Embedded, forked, and end-of-life components obscure vulnerability visibility and responsibility.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Your Mission&lt;/strong&gt;: Governance and lifecycle changes are necessary to avoid being structurally late to &amp;ldquo;silent&amp;rdquo; vulnerabilities.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="h2-0-are-you-sitting-comfortably"&gt;Are you sitting comfortably?&lt;/h2&gt;
&lt;p&gt;In February 2025, Apache Tomcat shipped a set of routine point releases. They arrived without urgency, without commentary, and without the kind of noise that can accompany significant security incidents.&lt;/p&gt;</description></item><item><title>The Real Mechanics of Vulnerabilities in an Upstream/Downstream, Topsy-Turvy EOL World</title><link>https://foojayio.github.io/website/today/the-real-mechanics-of-vulnerabilities-in-an-upstream-downstream-topsy-turvy-eol-world/</link><pubDate>Fri, 19 Dec 2025 13:36:28 +0000</pubDate><guid>https://foojayio.github.io/website/today/the-real-mechanics-of-vulnerabilities-in-an-upstream-downstream-topsy-turvy-eol-world/</guid><description>&lt;h3 id="h3-0-in-this-article-you-ll-learn"&gt;In this article you&amp;rsquo;ll learn&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Why CVEs record that a vulnerability exists, not that a usable fix exists&lt;/li&gt;
&lt;li&gt;How vulnerabilities are often discovered and fixed downstream before upstream ever acknowledges them&lt;/li&gt;
&lt;li&gt;Why EOL branches continue to accumulate exploitable behaviour even when no CVEs appear&lt;/li&gt;
&lt;li&gt;How downstream-only patches break the assumptions scanners and SBOMs rely on&lt;/li&gt;
&lt;li&gt;What disclosure actually enables when &amp;ldquo;just upgrade&amp;rdquo; is not a viable option&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="h3-1-introduction"&gt;Introduction&lt;/h3&gt;
&lt;p&gt;There is a tidy, almost academic version of how software security is supposed to work. It appears in conference talks, compliance documents and in the cheerful diagrams seen on marketing slides. It usually looks something like this:&lt;/p&gt;</description></item><item><title>Time to panic? AI and Cybercrime legislation is on your doorstep now</title><link>https://foojayio.github.io/website/today/time-to-panic-ai-and-cybercrime-legislation-is-on-your-doorstep-now/</link><pubDate>Thu, 10 Apr 2025 07:25:52 +0000</pubDate><guid>https://foojayio.github.io/website/today/time-to-panic-ai-and-cybercrime-legislation-is-on-your-doorstep-now/</guid><description>&lt;p&gt;&lt;strong&gt;As we settle into 2025, legislation around AI and cybercrime is no longer a distant threat or vague aspiration. It&amp;rsquo;s here, real, and it&amp;rsquo;s already changing how companies must build, deploy, and secure intelligent systems.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re a developer, security engineer, or anyone responsible for the software supply chain, it&amp;rsquo;s time to recalibrate. Here&amp;rsquo;s what&amp;rsquo;s coming, who&amp;rsquo;s shaping it, and what tools are emerging to help navigate the new landscape.&lt;/p&gt;</description></item><item><title>Thinking differently about testing</title><link>https://foojayio.github.io/website/today/thinking-differently-about-testing/</link><pubDate>Mon, 27 Jan 2025 07:26:34 +0000</pubDate><guid>https://foojayio.github.io/website/today/thinking-differently-about-testing/</guid><description>&lt;h3 id="h3-0-10x-insights-on-a-different-view-of-quality-assurance"&gt;10x Insights on a different view of quality assurance&lt;/h3&gt;
&lt;p&gt;I&amp;rsquo;ve given a few talks about 10x developers, or rather 10x professionals and been involved in process (re)engineering for many teams and projects.&lt;/p&gt;
&lt;p&gt;However much you learn about people and their roles - there&amp;rsquo;s always something new to discover.&lt;/p&gt;
&lt;p&gt;In fact, it is amazing how often your worldview is blinkered, how often there&amp;rsquo;s a different way to do or think about some aspect of your life or your career.&lt;/p&gt;</description></item><item><title>Foojay Podcast #50: JCON Report, Part 2 - Maven, Software Security, Code Quality</title><link>https://foojayio.github.io/website/today/foojay-podcast-50/</link><pubDate>Mon, 27 May 2024 08:07:54 +0000</pubDate><guid>https://foojayio.github.io/website/today/foojay-podcast-50/</guid><description>&lt;p&gt;This is part 2 of the interviews we recorded at the JCON conference earlier this month in Germany. In this episode, you get two main topics: &lt;strong&gt;Maven and Code Quality&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;In the first part, you&amp;rsquo;ll hear Karl Heinz Marbaise and Steve Poole discuss the Maven project, the repository, Sonaytype, and the security impact of dependencies.&lt;/p&gt;
&lt;p&gt;But next to security, we developers are also responsible for creating readable and maintainable code. Miro Wengner, Marit van Dijk, and Hinse ter Schuur dive into this topic, in the second part!&lt;/p&gt;</description></item><item><title>Crowd-Publishing the 10x Java Dev Book</title><link>https://foojayio.github.io/website/today/crowd-publishing-the-10x-java-dev-book/</link><pubDate>Thu, 02 May 2024 07:17:58 +0000</pubDate><guid>https://foojayio.github.io/website/today/crowd-publishing-the-10x-java-dev-book/</guid><description>&lt;p&gt;&lt;strong&gt;Java transformed the world of software development as we know it and continues to evolve as a platform and language. Nevertheless, the &amp;ldquo;&lt;a href="https://github.com/devoxx/JavaRoadmap" target="_blank" rel="noopener noreferrer"&gt;enlightenment roadmap&lt;/a&gt;
&amp;rdquo; of a Java developer can be scary. How do you become the 10x Java Developer you always dreamed of becoming?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s the question Steve Poole and Olimpiu Pop embarked on to respond. And, what better way to achieve it than to tap into the best resource Java has: its community!&lt;/p&gt;</description></item><item><title>Generative AI and Java - hype or urgent reality?</title><link>https://foojayio.github.io/website/today/generative-ai-and-java-hype-or-urgent-reality/</link><pubDate>Mon, 06 Nov 2023 07:59:04 +0000</pubDate><guid>https://foojayio.github.io/website/today/generative-ai-and-java-hype-or-urgent-reality/</guid><description>&lt;p&gt;&lt;img src="https://foojayio.github.io/website/today/generative-ai-and-java-hype-or-urgent-reality/image1-700x272.png" alt="" loading="lazy"&gt;
&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s hard to grasp that it&amp;rsquo;s been about a year since Chat GPT and other generative AI tools burst onto the scene. We&amp;rsquo;re all still grappling with, well, everything about them. Whatever equilibrium we eventually find, it&amp;rsquo;s clear that the world is changing. The whole world mind, not just the IT industry.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://twitter.com/olimpiupop" title="Olimpiu Pop" target="_blank" rel="noopener noreferrer"&gt;Olimpiu Pop&lt;/a&gt;
 and I have debated the situation multiple times, and we realised that there&amp;rsquo;s lots of rumour around AI and Java but not much in the way of fact.&lt;/p&gt;</description></item><item><title>State of the Software Supply Chain Report: Key Takeaways for Java Developers</title><link>https://foojayio.github.io/website/today/evolving-landscape-software-supply-chains-java-developers/</link><pubDate>Thu, 12 Oct 2023 08:19:25 +0000</pubDate><guid>https://foojayio.github.io/website/today/evolving-landscape-software-supply-chains-java-developers/</guid><description>&lt;p&gt;&lt;strong&gt;Sonatype have just released the 9th edition of their &lt;a href="https://www.sonatype.com/state-of-the-software-supply-chain/introduction" target="_blank" rel="noopener noreferrer"&gt;State of the Software Supply Chain Report&lt;/a&gt;
. It delves into the landscape of open source, software development, and software supply chain security. I thought I&amp;rsquo;d pull out some highlights for Java Developers!&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="h2-0-software-supply-chains-and-open-source"&gt;Software Supply Chains and Open Source&lt;/h2&gt;
&lt;h4 id="maven-central-hits-1-trillion-downloads"&gt;Maven Central hits 1 Trillion downloads&lt;/h4&gt;
&lt;p&gt;Open source adoption continues to grow, with Java (Maven) being a significant ecosystem.&lt;/p&gt;
&lt;p&gt;The report indicates that Java projects and their versions have seen substantial growth. a 28% year-over-year increase in total projects available on Maven Central - hitting the amazing 1 Trillion download number.&lt;/p&gt;</description></item><item><title>Friends of OpenJDK Community Survey</title><link>https://foojayio.github.io/website/today/2023-community-survey/</link><pubDate>Tue, 06 Jun 2023 08:33:06 +0000</pubDate><guid>https://foojayio.github.io/website/today/2023-community-survey/</guid><description>&lt;h3 id="h3-0-here-s-the-idea"&gt;Here&amp;rsquo;s the idea.&lt;/h3&gt;
&lt;p&gt;A survey that allows the community to ask the questions they want, including (shock horror) occasional commercial ones.&lt;/p&gt;
&lt;p&gt;Often, when a survey&amp;rsquo;s results are released, the reader is left wanting more, experiencing that perennial &amp;ldquo;yes but&amp;rdquo; moment. Typically, the survey data is hidden and unavailable for analysis, and the desired follow-up questions or clarifications are not addressed.&lt;/p&gt;
&lt;p&gt;The Foojay survey breaks this pattern. We will make all the data available, within the bounds of GDPR, and you will have the opportunity to propose the questions that should be included. The &lt;a href="https://foojayio.github.io/website/board/"&gt;Foojay Board&lt;/a&gt;
 also has the chance to propose their own questions.&lt;/p&gt;</description></item><item><title>SBOMs: First Steps in a New Journey for Developers</title><link>https://foojayio.github.io/website/today/sboms-first-steps-in-a-new-journey-for-developers/</link><pubDate>Tue, 14 Feb 2023 10:01:28 +0000</pubDate><guid>https://foojayio.github.io/website/today/sboms-first-steps-in-a-new-journey-for-developers/</guid><description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;This article is the first in a series about SBOMs, software supply chains, the government and you. Buckle up - it&amp;rsquo;s going to be a wild ride. Luckily there is cake to see you through.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Software bill of materials, anyone? A year ago, most developers had not heard of the &amp;lsquo;SBOM&amp;rsquo; acronym.&lt;/p&gt;
&lt;p&gt;Indeed, related terms like &amp;ldquo;software supply chain&amp;rdquo; or &amp;ldquo;security hygiene&amp;rdquo; were absent from most developers&amp;rsquo; vocabularies.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Things are about to change! This year is already shaping up to be the year of SBOMs, of securing the software supply chain, and of the appearance of legislation that enforces better security practices among those involved in software. Whether in creation, testing, deploying, securing or operating, we all have specific security responsibilities in protecting our part of the software supply chain.&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>