#code-provenance

[ follow ]
Software development
fromDevOps.com
2 days ago

Why Code Validation is the Next Frontier - DevOps.com

Shared staging environments are inadequate for modern development; isolated, on-demand setups are needed for effective validation.
#open-source
Software development
fromZDNET
4 days ago

How AI has suddenly become much more useful to open-source developers

AI tools are becoming increasingly useful for open-source maintainers, but legal and quality issues remain.
DevOps
fromZDNET
2 months ago

7 open-source apps I'd happily pay for - because they're that good

Many high-quality open-source applications exist across Linux, MacOS, and Windows; some are indispensable enough that users would willingly pay for them.
Software development
fromTheregister
1 month ago

Open source registries underfunded as security costs rise

Open source registries lack sustainable funding, leaving them unable to implement critical security features despite exponential growth and increasing infrastructure costs.
Python
fromThe Hacker News
2 days ago

The State of Trusted Open Source Report

AI is reshaping software development and security, influencing container image usage and vulnerability management.
Software development
fromZDNET
4 days ago

How AI has suddenly become much more useful to open-source developers

AI tools are becoming increasingly useful for open-source maintainers, but legal and quality issues remain.
Cryptocurrency
fromnews.bitcoin.com
1 day ago

Linux Foundation and Coinbase Launch x402 Foundation for AI Agents

The Linux Foundation launched the x402 Foundation to establish an open protocol for seamless internet-native payments.
fromRubyflow
2 days ago
Ruby on Rails

Internator now runs on OpenCode (bye Codex)

Internator is a Ruby CLI that automates code changes and now operates on OpenCode for enhanced flexibility and efficiency.
#ai
fromFuturism
1 day ago
Intellectual property law

Anthropic Suddenly Cares Intensely About Intellectual Property After Realizing With Horror That It Accidentally Leaked Claude's Source Code

fromThe Verge
4 days ago
Artificial intelligence

Claude Code leak exposes a Tamagotchi-style 'pet' and an always-on agent

Intellectual property law
fromFuturism
1 day ago

Anthropic Suddenly Cares Intensely About Intellectual Property After Realizing With Horror That It Accidentally Leaked Claude's Source Code

Anthropic's copyright takedown request for its AI model's source code highlights hypocrisy in its stance on copyright laws.
Artificial intelligence
fromThe Verge
4 days ago

Claude Code leak exposes a Tamagotchi-style 'pet' and an always-on agent

Leaked code reveals unreleased features and internal instructions for Anthropic's AI tool, Claude, including a Tamagotchi-like pet and a KAIROS feature.
Information security
fromThe Hacker News
4 days ago

Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

Anthropic confirmed a human error led to the accidental release of Claude Code's internal source code, but no sensitive data was exposed.
Information security
fromInfoQ
2 days ago

Open Source Security Tool Trivy Hit by Supply Chain Attack, Prompting Urgent Industry Response

A malicious release of the Trivy vulnerability scanner exposed critical weaknesses in software supply chain security, allowing for potential credential theft.
#github
fromMedium
5 days ago

The Best Way To Work With Claude Code

Voice interaction with Claude Code significantly enhances the user experience by allowing for faster input. Speaking is often 2-3 times quicker than typing, which can streamline the process of giving commands.
Typography
DevOps
fromApp Developer Magazine
1 week ago

Private Repository Secures the AI-driven Development Boom

ActiveState Curated Catalog provides a secure repository of vetted open source components for organizations, reducing risks associated with public registries.
Cryptocurrency
fromnews.bitcoin.com
2 days ago

REAL and Redstone Collaborate to Enhance Data Integrity for Tokenized Assets

REAL partners with Redstone to enhance data transparency and risk intelligence in its ecosystem for tokenized assets.
Information security
fromInfoWorld
2 days ago

Claude Code leak puts enterprise trust at risk as security, governance concerns mount

Leaks threaten Anthropic's market position and raise security concerns about its AI coding tools.
#claude-code
Software development
fromArs Technica
4 days ago

Entire Claude Code CLI source code leaks thanks to exposed map file

Claude Code's complexity and architecture provide valuable insights for competitors and pose security risks for Anthropic.
Information security
fromSecurityWeek
2 days ago

Critical Vulnerability in Claude Code Emerges Days After Source Leak

Anthropic's Claude Code source code was leaked, revealing operational details but not compromising sensitive data like model weights or customer information.
Information security
fromTheregister
4 days ago

Claude Code's source reveals extent of system access

Claude Code has significant control over devices, raising concerns about data retention and potential misuse in sensitive environments.
fromTheregister
4 days ago

Contracts are in C++26 despite disagreement over their value

Contracts are a means of setting preconditions and postconditions on function declarations, and adding assertion statements within functions. The feature is intended to help make C++ code safer and more reliable.
Intellectual property law
Software development
fromDevOps.com
4 days ago

The Trust Tax Framework: Measuring Developer Confidence in CI/CD Systems - DevOps.com

Test infrastructure credibility is crucial; developers lose trust when re-run rates exceed 30% and override rates surpass 5%.
DevOps
fromDevOps.com
1 week ago

Security as Code is Becoming the New Baseline: Continuous Compliance in DevOps - DevOps.com

Compliance must be integrated into the delivery pipeline as a continuous practice rather than a periodic checkpoint.
Higher education
fromTheregister
3 weeks ago

GitHub removes some models from free Copilot student plan

GitHub removed premium AI models from its free Copilot Student plan to reduce costs, keeping only lower-tier models while discontinuing GPT-5.4, Claude Opus, and Claude Sonnet.
Web frameworks
fromMedium
3 weeks ago

My 8-Year-Old Open-Source Project was a Victim of a Major Cyber Attack

A popular open-source project fell victim to a supply-chain attack through a development workflow loophole, threatening years of work and project reputation.
#ai-in-open-source
fromZDNET
3 weeks ago
Miscellaneous

Why AI is both a curse and a blessing to open-source software - according to developers

AI can benefit open source when properly applied for security analysis, but causes harm when generating low-quality automated bug reports that overwhelm maintainers with false positives.
fromZDNET
3 weeks ago
Artificial intelligence

Why AI is both a curse and a blessing to open-source software - according to developers

AI can benefit open source when properly applied for security analysis, but causes harm when generating low-quality automated bug reports that overwhelm maintainers with false positives.
fromZDNET
3 weeks ago
Miscellaneous

Why AI is both a curse and a blessing to open-source software - according to developers

Artificial intelligence
fromZDNET
3 weeks ago

Why AI is both a curse and a blessing to open-source software - according to developers

AI can benefit open source when properly applied for security analysis, but causes harm when generating low-quality automated bug reports that overwhelm maintainers with false positives.
Business
fromHelen Min
1 month ago

Software isn't dying, but it is becoming more honest - Helen Min

SaaS's subscription-based billing model is evolving beyond fixed seat-based pricing toward usage-based and outcome-based billing models that better align costs with actual value delivered.
#git
Information security
fromSecurityWeek
5 days ago

Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise

OAuth tokens pose significant security risks, especially when long-lived, as they can lead to widespread breaches across multiple organizations.
Intellectual property law
fromArs Technica
3 weeks ago

AI can rewrite open source code-but can it rewrite the license, too?

A developer rewrote open-source code using AI while having prior exposure to the original codebase, claiming the AI-generated version is structurally independent and not a derivative work despite not following traditional clean room practices.
fromDanielwestheide
1 week ago
Software development

Pair Programming Considered Unnecessary: The Costs of Productive Solitude

JetBrains is discontinuing Code With Me due to declining demand for remote collaborative coding post-pandemic.
#open-source-funding
fromTechCrunch
1 month ago
Non-profit organizations

A VC and some big-name programmers are trying to solve open source's funding problem, permanently | TechCrunch

fromTechCrunch
1 month ago
Non-profit organizations

A VC and some big-name programmers are trying to solve open source's funding problem, permanently | TechCrunch

Miscellaneous
fromTheregister
1 month ago

Open source package repositories face sustainability crisis

Open source repositories face unsustainable demand from companies misusing them as CDNs, prompting consideration of tiered payment systems where heavy users pay while individual developers remain free.
Software development
fromInfoQ
2 weeks ago

Stripe Engineers Deploy Minions, Autonomous Agents Producing Thousands of Pull Requests Weekly

Minions are autonomous coding agents at Stripe that generate production-ready pull requests with minimal human intervention.
Python
fromRealpython
4 weeks ago

How to Use Git: A Beginner's Guide Quiz - Real Python

A 14-question quiz tests understanding of Git fundamentals including repository initialization, staging changes, commits, and project history inspection.
Philosophy
fromMedium
1 month ago

Why code is not the source of truth

Design specifications and blueprints, not implementation code, are the authoritative source of truth; implementation is derived from and judged against originating design authority.
fromMedium
1 month ago

AI writes the code and humans still write the rules

A new generation of tools that let anyone - designers, marketers, founders, students - describe an app in plain English and watch it get built in real time. No compiler knowledge. No debugging in terminals. No Stack Overflow. Just a conversation with a machine that builds things.
Artificial intelligence
Software development
fromInfoWorld
3 weeks ago

Claude Code adds code reviews

Anthropic launched Code Review for Claude Code, a multi-agent system that identifies bugs in pull requests with high accuracy, finding issues in 84% of large pull requests while maintaining less than 1% false positive rate.
#ai-assisted-development
Software development
fromInfoWorld
3 weeks ago

Pity the developers who resist agentic coding

Future software developers will never experience manual coding, missing the struggle, mastery, and profound satisfaction that defined traditional software development.
Software development
fromInfoWorld
1 month ago

An ode to craftsmanship in software development

Senior developers are transitioning from writing code to orchestrating AI-assisted development, trading hands-on coding satisfaction for architectural oversight and process management.
Software development
fromInfoWorld
3 weeks ago

Pity the developers who resist agentic coding

Future software developers will never experience manual coding, missing the struggle, mastery, and profound satisfaction that defined traditional software development.
Software development
fromInfoWorld
1 month ago

An ode to craftsmanship in software development

Senior developers are transitioning from writing code to orchestrating AI-assisted development, trading hands-on coding satisfaction for architectural oversight and process management.
#agentic-workflows
#ai-driven-development
fromInfoWorld
3 weeks ago
Software development

Coding for agents

AI agents reward explicit, consistent, well-documented code over clever or personally-preferred approaches, fundamentally changing software engineering standards toward machine-legibility.
fromTechRepublic
1 month ago
Software development

OpenAI Reportedly Eyes a GitHub Alternative - TechRepublic

OpenAI is building an internal GitHub alternative to optimize for AI-driven development, reduce vendor dependency, and offer customers a specialized repository platform.
Software development
fromTechRepublic
1 month ago

OpenAI Reportedly Eyes a GitHub Alternative - TechRepublic

OpenAI is building an internal GitHub alternative to optimize for AI-driven development, reduce vendor dependency, and offer customers a specialized repository platform.
fromTechzine Global
1 month ago

AI code undermines control over open source and IP

While AI tools are lowering the barrier to development, the gap between speed and manageability is growing. In just over a year and a half, AI code assistants have grown from an experiment to an integral part of modern development environments. They are driving strong productivity growth, but organizations are not keeping up with the associated security and governance issues.
Information security
fromTheregister
1 month ago

Gentoo moves to Codeberg amid GitHub Copilot concerns

Gentoo's official migration from Microsoft-owned GitHub to Codeberg is underway, as the Linux distribution fulfills a pledge to ditch the code shack due to "continuous attempts to force Copilot usage for our repositories." The decision was made public last month, when Gentoo confirmed it intended to migrate repository mirrors and pull request contributions to the new home. On February 16, the organization revealed it now had a presence on Codeberg, where contributions could be submitted.
Miscellaneous
fromTechzine Global
1 month ago

Go developer questions effectiveness of Dependabot

Dependabot sounded the alarm on a large scale. Thousands of repositories automatically received pull requests and warnings, including a high vulnerability score and signals about possible compatibility issues. According to Valsorda, this shows that the tool mainly checks whether a dependency is present, without analyzing whether the vulnerable code is actually accessible within a project.
Information security
Software development
fromInfoQ
1 month ago

GitHub's Points to a More Global, AI-Challenged Open Source Ecosystem in 2026

Open source faces unprecedented scale with 36 million new developers joining GitHub in 2025, requiring formal governance structures and strategies to manage AI-generated low-quality contributions.
fromInfoWorld
1 month ago

Open source maintainers are being targeted by AI agent as part of 'reputation farming'

The important shift is that software contribution itself is becoming programmable,
Artificial intelligence
Software development
fromZDNET
1 month ago

Linux explores new way of authenticating developers and their code - here's how it works

The Linux kernel is transitioning from PGP-based developer identification to a more efficient system that addresses privacy concerns and streamlines the cumbersome face-to-face key-signing verification process.
Python
fromInfoWorld
2 months ago

Visual Studio Code previews incoming/outgoing changes graph

Visual Studio Code 1.91 adds an experimental incoming/outgoing changes graph and a Rust-based python-environment-tools for faster Python environment discovery.
Artificial intelligence
fromInfoQ
1 month ago

Working with Code Assistants: The Skeleton Architecture

Combining Vertical Slice architecture with Dependency Inversion and a Skeleton of base classes constrains AI code assistants' context, producing safer, consistent, and maintainable generated code.
#ai-generated-code
Information security
fromTechzine Global
2 months ago

Misuse of VS Code tasks poses risk to developers

VS Code tasks.json can automatically run commands when a folder is opened, enabling supply-chain attacks that execute malicious, persistent code across platforms.
fromSecurityWeek
1 month ago

How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development

This extends to the software development community, which is seeing a near-ubiquitous presence of AI-coding assistants as teams face pressures to generate more output in less time. While the huge spike in efficiencies greatly helps them, these teams too often fail to incorporate adequate safety controls and practices into AI deployments. The resulting risks leave their organizations exposed, and developers will struggle to backtrack in tracing and identifying where - and how - a security gap occurred.
Artificial intelligence
Artificial intelligence
fromFast Company
1 month ago

Developers are still weighing the pros and cons of AI coding agents

AI coding tools often produce buggy, hard-to-maintain code by losing context in complex projects, though testing and validation features are emerging to catch problems.
fromTechCrunch
1 month ago

For open-source programs, AI coding tools are a mixed blessing | TechCrunch

AI coding tools have caused as many problems as they have solved, according to industry experts. The easy-to-use and accessible nature of AI coding tools has enabled a flood of bad code that threatens to overwhelm projects. Building new features is easier than ever, but maintaining them is just as hard and threatens to further fragment software ecosystems. The result is a more complicated story than simple software abundance.
Software development
fromInfoQ
1 month ago

GitHub Reworks Layered Defenses After Legacy Protections Block Legitimate Traffic

GitHub engineers recently traced user reports of unexpected "Too Many Requests" errors to abuse-mitigation rules that had accidentally remained active long after the incidents that prompted them. According to GitHub, the affected users were not generating high-volume traffic; they were "making a handful of normal requests" that still tripped protections. The investigation found that older incident rules were based on traffic patterns that were strongly associated with abuse at the time, but later began matching some legitimate, logged-out requests.
Information security
Software development
fromInfoWorld
2 months ago

GitHub Artifact Attestations sign and verify software artifacts

Artifact Attestations in GitHub Actions is now generally available to secure artifacts and verify provenance using Sigstore, Kubernetes Policy Controller, and gh attestation verify.
Software development
fromInfoWorld
1 month ago

GitHub previews support for Claude and Codex coding agents

GitHub agents run inside repositories and tools to surface trade-offs, keep context, and create draft pull requests for standard code review.
fromInfoWorld
2 months ago

For agentic AI, other disciplines need their own Git

Software engineering didn't adopt AI agents faster because engineers are more adventurous, or the use case was better. They adopted them more quickly because they already had Git. Long before AI arrived, software development had normalized version control, branching, structured approvals, reproducibility, and diff-based accountability. These weren't conveniences. They were the infrastructure that made collaboration possible. When AI agents appeared, they fit naturally into a discipline that already knew how to absorb change without losing control.
Software development
fromTheregister
1 month ago

VS Code for Linux may be secretly hoarding trashed files

The reason for this is Snap - a Linux application packaging format - creates a local Trash folder for each VS Code version, one that's separate from the system-managed Trash, according to a VS Code bug report dating back to November 11, 2024. Not only that, but Snap keeps older versions of VS Code after updates, potentially multiplying the number of local Trash folders and the trashed-but-not-deleted files therein. Emptying the system Trash folder doesn't affect the local instances.
Software development
Software development
fromInfoQ
1 month ago

Agent Trace: Cursor Proposes an Open Specification for AI Code Attribution

Agent Trace defines a vendor-neutral JSON specification to attribute AI and human contributions in version-controlled codebases, supporting multiple VCS and extensible metadata.
Software development
fromDbmaestro
1 year ago

Why Do You Need Database Version Control?

Database version control tracks schema and code changes, enabling CI/CD integration, collaboration, rollback, and faster, more reliable deployments across multiple databases.
Software development
fromgithub.com
1 month ago

gitton-dev/gitton: Git Client for Vibe Coding

Gitton is a terminal-first Git client with deep GitHub integration, AI-powered commit messages, code review and PR generation, and JavaScript-extensible plugins.
Software development
fromMedium
1 year ago

How Bit Reduces Development Costs

A composable, well-documented codebase increases reuse, reduces bugs, and enables AI and non-technical stakeholders to contribute effectively.
Software development
fromInfoWorld
2 months ago

GitLab unveils GitLab 17, AI for devsecops

GitLab 17 adds a reusable CI/CD catalog, AI impact dashboard, and GitLab Duo Enterprise to detect vulnerabilities, resolve CI/CD issues, and boost developer productivity.
fromQuinnkeast
1 month ago

What, then, are we paying for?

Generative AI exponentially brings down the cost of building solutions. It lets people build exactly what they need to solve an exact problem in an exact moment. It lets people own their own solutions. This is great for a lot of specific problems that need specific solutions that wouldn't normally get solved easily. This has been the evergreen promise of computers and programming and hacking. But there's a difference between solving your specific problem, and owning a problem domain.
Software development
Software development
fromPybites
2 months ago

7 Software Engineering Fixes To Advance As A Developer - Pybites

Finish one practical project and adopt system-level skills, feedback loops, and mindset shifts to move from hobbyist coding to professional software engineering.
Software development
fromMedium
4 months ago

The Architect and the Apprentice: Retaining Control in the Age of Code Generation

Uncontrolled AI coding agents increase code churn and duplicated code, accelerating technical debt and forcing developers to spend more time cleaning and maintaining code.
Software development
fromTheregister
2 months ago

Vibe coding may be hazardous to open source

AI coding tools reduced Tailwind documentation traffic by about 40%, cutting commercial exposure and causing Tailwind Labs to lay off three workers.
[ Load more ]