Trends

Teams Built Quality And Security Infrastructure Around The Repository And That Is Now Breaking
A pull request used to be where a change became real. An engineer wrote the code, pushed it, and opened the PR; that was the moment the rest of the...
What Is an AgBOM? Inventorying the Autonomous Coding Agents in Your Pipeline
Your team probably knows who merged the last pull request. But do you know which AI agent wrote it, what tools it invoked, what credentials it used,...
Pre-Commit vs CI Quality Gates: When Fast-Shipping Moves The Checks Upstream
Teams that ship dozens of pull requests a week eventually run into the same wall: CI-stage quality gates turn into a queue. A developer opens a PR,...
Malicious intent - code agents
Detecting Malicious Intent Across AI-Generated Pull Requests: A Governance Framework for Engineering Leaders
No single pull request has to look malicious to create a serious security problem. One adds logging. Another introduces a background job. A third...
AI Code Review is not enough
AI Code Review Is Not Enough: How Engineering Leaders Should Gate AI-Generated Code
The easiest pull requests to approve are often the ones that deserve the closest inspection. AI-generated code tends to arrive well formatted, well...
Why Engineering Teams Keep Building In-House AI Code Review Tools, and What It Really Costs
LLMs made internal AI code review tools easy to prototype. They did, however, not make them easy to operate.
1 2 3 4 5

Subscribe to our blog

Stay updated with our monthly newsletter.