Skip to main content

Posts

Introducing Futurum Media: Why Futurum, Why Now?

I am a builder. My career has spanned the rise of the commercial internet, web hosting, application service providers, managed infrastructure, security, DevOps, cloud native computing, platform engineering and now AI. Through all of it, I have been a builder and a leader. I didn’t think, after all these years, I would be building again quite like this. But in the age of AI, we can all be builders. I am happy to be doing this. Today, The Futurum Group is launching Futurum Media , bringing Techstrong, Tech Field Day and Visible Impact together into a go-to-market execution business. It becomes the umbrella for Futurum’s editorial properties and media services, backed by the broader organization’s research, intelligence and expertise. For those of you who read DevOps.com and our other publications, participate in our programs or work with us, here is why I believe this is a significant next step. A Community Worth Building On DevOps.com grew alongside a community changing how softw...
Recent posts

Survey Surfaces Sharp Increase in Amount of Code Written by AI

A global survey of 705 developers and IT leaders finds 42% of respondents reporting that artificial intelligence (AI) now writes at least half their code, with only 21% of developers now spending more than half their week writing new code from scratch. Conducted by BairesDev, a provider of software development services, the survey also finds nearly 80% of developers now spend less than half their week coding. As a result, developers on average are saving 13 hours a week on coding, allowing them to devote more time to reviewing AI output (67%) and debugging it (52%). Developers are also now spending, on average, nine hours a week learning AI tools and new technologies. That investment appears to also be paying off, with AI tool fluency (29%), system architecture (20%), and human skills (15%) expertise driving pay increases for developers, the survey finds. A full 86% of respondents also report they now find their role in their organization more fulfilling, according to the survey. I...

A Semicolon in a Branch Name Was All It Took to Steal an AI Agent’s GitHub Token

AI coding agents don’t just suggest code anymore. Tools like OpenAI’s Codex spin up a real container, clone a real repository, and authenticate with a real GitHub credential to get the job done — which means every agent your team wires up is also a new privileged identity, holding real access, running with comparatively little of the scrutiny a human with that same access would get. A Branch Name Was the Whole Attack In March, BeyondTrust’s Phantom Labs disclosed a critical command injection vulnerability in Codex. The flaw was almost absurdly simple: when Codex creates a task container, it passes the target branch name into a shell command without sanitizing it first. Characters like ; && | $() and backticks get interpreted literally by Bash. The proof-of-concept needed nothing more exotic than that. Set the branch to main , append a semicolon to terminate the intended git command, then inject a second command that writes the output of git remote get-url o...

Perforce Applies Machine Learning to Generate Synthetic Data for App Testing

Perforce Software has added a tool that leverages artificial intelligence (AI) to make it simpler for application development teams to generate synthetic data for application testing purposes. Mayank Ahluwalia, a senior product manager for Perforce Delphix, said Delphix Synthetic Data makes use of machine learning algorithms to generate synthetic data for specific use cases. It automatically identifies data structures, relationships, and business context across multiple sources. Historically, DevOps teams would have had to manually provide access to those data sources using some type of legacy tool, he added. The overall goal is to limit or eliminate the need to give application development teams access to production data in order to test an application, noted Ahluwalia. At the moment, providing those teams with access to data needed to run tests has become a bottleneck that can be eliminated by using a self-service platform for generating synthetic data, he added. That capability...

AWS Benchmark Aims to Reduce Number of False Positives Found by AI Vulnerability Scanners

Amazon Web Services (AWS) has developed a benchmark that can be used to test whether a model can distinguish real vulnerabilities from code that looks risky but is actually safe. The Deception Benchmark was created following an evaluation of the capabilities of 12 models from five different providers. In all, the benchmark includes 14,822 samples of code built using 16 different languages spanning more than 70 Common Weakness Enumeration (CWE) categories. Each sample is run through an adversarial loop to generate code, test it against frontier models, harden, repeat. If a model gets it right easily, the sample is removed. According to the benchmark, every AI model has the same fundamental issue. While they identify up to 95% of real vulnerabilities, they also flag 41 to 99% of safe code. Proof-of-exploit prompting can cut false positives by 17 to 74 percentage points but misses 7% to 44% of real vulnerabilities. The environment-gated challenges are worse: models flag the code and ig...

Git 2.56 Takes Aim at Messy Merges, Slow Diffs and Branch Sprawl

Most developers don’t think about Git until it gets in the way. A resolved merge conflict gets staged with a stray marker still in the file. A diff on a massive repository hangs long enough to grab coffee. A branch list grows so long nobody wants to clean it up. Git 2.56, released this week, goes after many of those small but persistent problems. The release drew contributions from 104 developers, 39 of them first-time contributors, according to a GitHub blog post by Elijah Newren. Much of the work focuses on safety during merges, raw performance at scale, and cleanup chores that teams tend to put off. Start with merge conflicts. Resolving one usually ends with running git add on the files you fixed. But it’s easy to stage the wrong thing, whether that’s an unrelated change or a file that still contains conflict markers. The new git add --resolved option narrows that step. It considers only paths that are currently unmerged in the index, and it scans those files fo...

Docker Introduces Open Sandbox Kit Spec for AI Agent Permissions

AI agents are getting good at probing the boundaries developers put around them. Their ability to improvise makes them hard to contain. “You ask for something in a very high-level, vague-at-best way. You walk away, and you come back to a remarkable pile of mostly working software. But you then realize that you gave a probabilistic machine access to your life and your systems,” said Docker President and COO Mark Cavage, speaking to the crowd at the opening session of the WeAreDevelopers North America conference in San Jose Thursday. During his keynote, Cavage unveiled a new specification for packaging an AI agent and its tools together with a declaration of the access it requests from a sandbox. He also announced that Docker plans to contribute the new specification to the Cloud Native Computing Foundation. A Common Format for Agent Sandboxes Published under the Apache 2.0 license, the specification is meant to give developers and sandbox providers a common format they can use acr...