Autonomous Development and AI: Speed vs. Security

AI-assisted development is changing how software gets built. What began as a productivity boost is quickly becoming something bigger ... Read More
Grounded Intelligence Is Key to Safe AI Software Development at Scale

Grounded Intelligence Is Key to Safe AI Software Development at Scale

One experience has become nearly universal as AI systems move deeper into software development, their confidence when they're wrong ... Read More
Golden Pull Requests: Automating Trusted Remediation Without Breaking Builds

Golden Pull Requests: Automating Trusted Remediation Without Breaking Builds

Modern software development runs on open source. Nearly every application is built from a combination of third-party components, transitive dependencies, and rapidly evolving package ecosystems ... Read More

Accelerate Secure Releases With Microsoft Copilot and Sonatype Guide

AI coding assistants, such as Microsoft Copilot, are fundamentally transforming the process of software development. Developers can generate scaffolding, draft functions, update dependencies, and even build full applications in seconds. The speed is real, and so is the productivity boost ... Read More

Modern Vulnerability Management in the Age of AI

Vulnerability management today is not failing because teams stopped scanning. It's failing because the ground underneath it shifted. The approach we've relied on — complete advisory data, upstream fixes on demand, and fast upgrades — no longer holds up ... Read More

Why LLMs Make Terrible Databases and Why That Matters for Trusted AI

Large language models (LLMs) are now embedded across the SDLC. They summarize documentation, generate code, explain vulnerabilities, and assist with architectural decisions ... Read More
Power Secure Swift Development at Scale With Sonatype Nexus Repository

Power Secure Swift Development at Scale With Sonatype Nexus Repository

From its beginnings as a language for Apple platforms, Swift Package Manager has expanded its reach considerably. It now powers a wide range of mobile, desktop, and server-side applications, as well as shared libraries, and is frequently adopted by large, distributed teams ... Read More
The Future of Dependency Management in an AI-Driven SDLC

The Future of Dependency Management in an AI-Driven SDLC

AI coding assistants now power a growing share of modern software delivery. They span the SDLC, helping teams move faster from idea to implementation, expanding what individual developers can deliver, and accelerating release cycles across the enterprise ... Read More
Secure, Reliable Terraform At Scale With Sonatype Nexus Repository

Secure, Reliable Terraform At Scale With Sonatype Nexus Repository

Terraform has become the de facto standard for infrastructure as code (IaC). From cloud-native startups to global enterprises, teams rely on Terraform to define, provision, and manage infrastructure with speed and consistency across cloud and on-prem environments ... Read More

OWASP Top 10: Application Security Meets AI Risk

The OWASP Top 10 has long served as a reality check for development teams: a concise, community-driven snapshot of the most critical web application security risks organizations face today ... Read More