Skip to main content

Posts

Docker Introduces Open Sandbox Kit Spec for AI Agent Permissions

AI agents are getting good at probing the boundaries developers put around them. Their ability to improvise makes them hard to contain. “You ask for something in a very high-level, vague-at-best way. You walk away, and you come back to a remarkable pile of mostly working software. But you then realize that you gave a probabilistic machine access to your life and your systems,” said Docker President and COO Mark Cavage, speaking to the crowd at the opening session of the WeAreDevelopers North America conference in San Jose Thursday. During his keynote, Cavage unveiled a new specification for packaging an AI agent and its tools together with a declaration of the access it requests from a sandbox. He also announced that Docker plans to contribute the new specification to the Cloud Native Computing Foundation. A Common Format for Agent Sandboxes Published under the Apache 2.0 license, the specification is meant to give developers and sandbox providers a common format they can use acr...
Recent posts

Survey: Lack of Confidence in Software Supply Chain Security Runs High

A survey of 400 platform and security engineers in the U.S and United Kingdom (UK), finds nearly three quarters (73%) are either only moderately confident (58%) or not confident (15%) in the ability of their existing tools for managing software artifacts to prevent attacks against their organization’s software supply chain. Conducted by Cloudsmith, a provider of a platform for managing software artifacts, the survey also finds nearly half of respondents (48%) can identify an intrusion in their software supply chain but need to rely on manual efforts to enforce some type of quarantine or resolve the issue. Only 37% said they can automatically identify, block, and trace an intrusion within minutes. As a result, nearly two thirds (65%) are either investigating a different approach to compliance (45%) or are evaluating some type of security framework (25%), the survey finds. Cloudsmith CEO Glenn Weinstein said that as it becomes more apparent in the AI era that changes will be made to h...

DHH Declares End of Hand-Writing Code at Rails World 2026

Controversial developer David Heinemeier Hansson (aka DHH) announced last week at Rails World 2026 that the end of handwritten code is upon us, calling it the modern era’s “Brownie” moment. The moment to which he referred was when Kodak released its Brownie camera that forever changed the trajectory of photography. In this case, the Brownie of our era is AI. During the event, DHH announced that his company, 37signals, decided it would no longer write code by hand and, instead, would use AI agents as its default code generation tool; humans were to only intervene when the auto-generated code needed to be fixed. To back up that migration, DHH proclaimed that he’d written half as much code over the past twenty months as he had in the previous twenty-one months. One justification for this change, DHH addressed in a REWORK Podcast episode , when he spoke about how AI doesn’t suffer the same “attachment” to code as humans. To that, DHH said, ...

Ten Great DevOps Job Opportunities

DevOps.com is now providing a weekly DevOps jobs report through which opportunities for DevOps professionals will be highlighted as part of an effort to better serve our audience. Our goal in these challenging economic times is to make it just that much easier for DevOps professionals to advance their careers. Of course, the pool of available DevOps talent is still relatively constrained, so when one DevOps professional takes on a new role, it tends to create opportunities for others. The ten job postings shared this week are selected based on the company looking to hire, the vertical industry segment and naturally, the pay scale being offered. We’re also committed to providing additional insights into the state of the DevOps job market. In the meantime, for your consideration. Dice Booz Allen Hamilton McLean, VA DevOps Engineer $77,600 to $176,000 Alarm.com Centennial, CO DevOps Engineer $120,000 to $130,000 HarbourVest Partners Boston, MA DevOps Engineer $135,00...

GitHub’s Security Autofix Agent Now Remembers What It Fixed

Most codebases have a favorite mistake. It might be a query built from string concatenation, or a missing check on user input. A developer fixes it in one file. A few weeks later, the scanner finds the same flaw in another file, and the fix starts from scratch. GitHub wants to stop paying for that lesson twice. On September 25, the company said agentic autofix now uses Copilot Memory for customers who have turned Memory on. Before the agent works on a security alert, it checks stored memories for context that might help. After it creates a fix, it saves the fix pattern as a memory for later use. Those patterns don’t stay inside autofix. According to GitHub’s changelog, they help the agent resolve other security alerts, and they inform other Copilot features, including code review and the Copilot cloud agent, about secure development practices specific to the repository. Both agentic autofix and Copilot Memory are still in public preview. How the Pieces Fit Agentic autof...

Leaked GitLab Email Tokens Can Reach Code, Secrets and CI/CD Pipelines

Security researchers have uncovered a GitLab behavior that could let attackers use a leaked project email address to push code, trigger CI/CD jobs and reach other repositories accessible to the address owner. Aikido Security researcher Joe Leon detailed the attack path this week in a blog post after reporting it to GitLab earlier this year. The issue involves GitLab’s incoming email token, a credential embedded in private email addresses that GitLab provides for creating issues and merge requests by email. “The token inside this email address is essentially a fine-grained personal access token with significant access to your GitLab projects,” the report said. GitLab’s documentation says the token never expires and warns that anyone who obtains it can create issues and merge requests as the user. GitLab also allows users to attach .patch files when creating merge requests by email. GitLab applies the patches to the named source branch or creates the branch if it does not already exi...

DevSecOps Teams as Partners in Secure Software Delivery

A dependency scan warns of a vulnerable library several hours before the release. The developer finds a solution, but it might affect some working features, and security and operations teams wait for approval to take any action. The end-of-line race against the clock to finalize releases is well known to teams that postpone security decisions to the final hours of a release. DevSecOps teams can streamline such processes by establishing protocols and providing feedback as the work progresses. This article discusses the location and responsibilities involved in making such determinations and decisions and examines approaches to negotiating releases in the presence of an unresolved security problem. Why the Final Security Gate Slows Everyone Down It is a difficult situation, however, to discover that a design choice needs to be changed. Late findings also raise new questions that should have been asked earlier. Should the developer be expected to investigate every scanner finding? Can t...