Techlist.io - Korean Tech Blog Curator

gitlab2 min readCurated summary

GitLab Patch Release: 18.10.3, 18.9.5, 18.8.9 | GitLab Docs

GitLab released patch versions 18.10.3, 18.9.5, and 18.8.9 on April 8, 2026, addressing important security and bug fixes. Self-managed CE and EE installations should upgrade immediately, while GitLab.com is already patched and GitLab Dedicated customers need no action. The fixes cover unauthorized access, denial-of-service vulnerabilities, code injection, XSS, and information disclosure. ## Release Scope and Upgrade Guidance - The patches apply to GitLab Community Edition and Enterprise Edition. - Administrators should upgrade installations affected by the listed vulnerabilities to the latest supported patch release. - GitLab issues describing security vulnerabilities will become public 30 days after the release in which they were fixed. - Patch releases are generally issued on the second and fourth Wednesdays, with urgent ad-hoc releases for critical vulnerabilities. ## Authentication and Authorization Fixes - **CVE-2026-5173 (CVSS 8.5):** Authenticated users could invoke unintended server-side methods through WebSocket connections. - **CVE-2026-2619 (CVSS 4.3):** Auditor users could modify vulnerability flag data in private projects through the AI detection API. - **CVE-2026-1752 (CVSS 4.3):** Developers could modify protected environment settings through authorization flaws in the Environments API. - **CVE-2026-2104:** CSV exports could expose confidential issues assigned to other users because of insufficient authorization checks. ## Denial-of-Service Vulnerabilities - **CVE-2026-1092 (CVSS 7.5):** Unauthenticated attackers could crash or disrupt services through malformed JSON sent to the Terraform state lock API. - **CVE-2025-12664 (CVSS 7.5):** Repeated unauthenticated GraphQL queries could cause denial of service. - **CVE-2026-1403 (CVSS 6.5):** Authenticated users could disrupt Sidekiq workers by importing malformed CSV files. - **CVE-2026-1101 (CVSS 6.5):** Authenticated users could overload GitLab through improperly validated GraphQL SBOM queries. ## Code Execution and Cross-Site Scripting - **CVE-2026-1516 (CVSS 5.7):** Crafted Code Quality report content could leak the IP addresses of users viewing the report. - **CVE-2026-4332 (CVSS 5.4):** Authenticated users could execute arbitrary JavaScript in other users’ browsers through customizable analytics dashboards. ## Information Disclosure - **CVE-2025-9484 (CVSS 4.3):** Certain GraphQL queries could reveal other users’ email addresses to authenticated users. - The release also fixes CSV export authorization issues that could expose confidential issue data. Administrators of self-managed GitLab CE or EE instances should apply 18.10.3, 18.9.5, or 18.8.9 as soon as possible, depending on their supported release branch.

Read original(opens in new tab)
figma3 min readCurated summary

How Figmates Used Figma AI to Take Delight to the Next Level | Figma Blog

Figma’s 2026 April Fun Day project, “FigCade,” used Figma Make, Figma Weave, and the Figma MCP server to create six playable mini-games in only a few days. The tools helped the team rapidly prototype ideas, explore visual styles, produce media, and translate designs into code. The project demonstrated how AI can make design and development more collaborative and iterative. ## Building a playful canvas experience - April Fun Day is Figma’s annual tradition of adding playful surprises and Easter eggs for its community. - This year, the team brought six mini-games directly into the Figma canvas for one week. - The project also gave employees an opportunity to experiment beyond their usual roles and push Figma’s tools in new ways. - The resulting FigCade included games such as: - **2Fast2Figma**, a timed quiz about Figma facts. - **FigPalette** and **Diabolical Magic Square**, featured in the game menu. ## Rapid prototyping with Figma Make - Figma Make helped the team turn ideas into working prototypes quickly. - An early concept for 2Fast2Figma was created on a Sunday morning and became functional that afternoon. - The team generated multiple prototypes, tested them with others, and iterated based on feedback. - This established a fast workflow: build something quickly, review it, align with the team, and refine it. ## Exploring visuals with Figma Weave - Figma Weave helped designers generate and explore visual assets more efficiently. - Designer Lesley Moon used it to create felt-style textures and assets, including the project’s textured cursor. - Generating many variations quickly expanded the range of visual themes the team could consider. - Weave was also used to develop the April Fun Day trailer: - Product Manager Tara Nadella explored the initial concept. - Motion Designer Fifi Law used those explorations and Lesley’s visuals to produce the final trailer in one day. ## Connecting design and code with MCP - The Figma MCP server helped developers turn design explorations into implementation. - Engineer Steven Noto used Claude and GitHub Copilot with MCP authentication. - By sharing links to specific Figma components, the coding agents could access design context and generate code matching the intended specifications. - The team moved back and forth between design and development, using AI to reduce the distance between visual concepts and working software. ## Practical takeaway FigCade illustrates how combining rapid prototyping, generative visual tools, and design-aware coding assistance can help small teams create polished interactive experiences quickly. The strongest results came from treating AI as part of an iterative design-and-development process rather than as a replacement for human direction.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Cloudflare targets 2029 for full post-quantum security

Cloudflare is accelerating its post-quantum security timeline and now aims to complete the transition by 2029, including post-quantum authentication. The company argues that recent advances in quantum algorithms, neutral-atom hardware, and error correction could bring “Q-Day”—when quantum computers can break today’s cryptography—as early as 2029–2030. While Cloudflare has largely addressed harvest-now/decrypt-later risks through post-quantum encryption, it now considers authentication the more urgent priority. ## Cloudflare’s Post-Quantum Roadmap - Cloudflare began preparing for post-quantum migration in 2019. - It enabled post-quantum encryption for all websites and APIs in 2022. - More than 65% of human traffic to Cloudflare is now post-quantum encrypted. - The remaining challenge is upgrading authentication, including certificates, signatures, and access credentials. - Cloudflare now targets 2029 for full post-quantum security. ## New Evidence That Q-Day May Arrive Earlier - Google announced a major improvement to an undisclosed quantum algorithm for breaking elliptic-curve cryptography. - Google provided a zero-knowledge proof of the algorithm rather than revealing its details. - Oratomic published estimates for breaking RSA-2048 and P-256 using neutral-atom quantum computers. - Its estimate for P-256 requires only about 10,000 qubits. - Important implementation details were intentionally omitted. - These developments led Google to move its own migration target to 2029. - Google has emphasized quantum-secure authentication, suggesting concern that Q-Day could arrive around 2030. - IBM Quantum Safe’s CTO has said that “moonshot attacks” against valuable targets might be possible as early as 2029. - Public progress estimates may become less reliable because researchers could stop disclosing details that would help adversaries. ## Progress Across Three Quantum-Computing Fronts ### Hardware - Competing approaches include: - Neutral atoms - Superconducting qubits - Ion traps - Photonics - Topological qubits - Most approaches have made substantial progress, although none has yet demonstrated the scalability needed to break deployed cryptography. - Neutral-atom systems appear particularly promising, and it would be risky to assume every competing approach will fail to scale. ### Error Correction - Quantum computers are inherently noisy and require error-correcting codes. - Conventional superconducting systems may need roughly 1,000 physical qubits per logical qubit because of noise and limited connectivity. - Neutral-atom systems offer highly connected, reconfigurable qubits that can use more efficient error-correcting codes. - Oratomic estimates that only about 3–4 physical neutral atoms may be needed per logical qubit. ### Quantum Software - Improvements to quantum algorithms can substantially reduce the resources required to break cryptography. - Google’s work reportedly accelerated attacks against P-256. - Oratomic added architecture-specific optimizations for reconfigurable neutral-atom systems. ## Why Authentication Requires Immediate Attention - Post-quantum encryption primarily protects against harvest-now/decrypt-later attacks: - Attackers collect encrypted traffic today. - They decrypt it later after obtaining a capable quantum computer. - This has been Cloudflare’s main focus since 2022. - Authentication presents a different threat: - Quantum computers could forge signatures, impersonate servers, or create unauthorized credentials. - If Q-Day were decades away, deploying post-quantum authentication would provide little immediate benefit. - If Q-Day could occur within a few years, authentication systems must be migrated before attackers can exploit them. Cloudflare’s recommendation is to treat post-quantum migration as an urgent, multi-year project rather than waiting for quantum computers to become publicly available. Organizations should continue protecting stored data with post-quantum encryption while prioritizing the migration of authentication, certificates, and digital signatures before 2029.

Read original(opens in new tab)
aws3 min readCurated summary

Launching S3 Files, making S3 buckets accessible as file systems | Amazon Web Services

Amazon S3 Files makes general-purpose S3 buckets accessible through a native NFS-based file system. It combines S3’s durability, cost, and broad service integration with interactive file operations, shared access, and low-latency performance. The post concludes that this reduces the need to choose between object storage and traditional file systems for many AWS workloads. ## Bridging Object Storage and File Systems - S3 Files presents S3 objects as files and directories. - Applications can use standard NFS v4.1+ operations, including creating, reading, updating, and deleting files. - Changes made through the file system are synchronized back to S3 as new objects or object versions. - Changes made directly in S3 generally appear in the file system within seconds, though synchronization can sometimes take longer. - Multiple compute resources can mount the same file system and share data without duplicating it. ## Performance and Data Access - S3 Files uses Amazon EFS underneath and provides approximately 1 ms latency for active data. - Frequently accessed metadata and file contents are placed on high-performance storage. - Large sequential reads can be served directly from S3 to maximize throughput. - Byte-range reads transfer only the requested portion of a file, reducing data movement and cost. - Intelligent prefetching anticipates access patterns. - Administrators can choose whether to cache complete files or metadata only. - NFS close-to-open consistency supports concurrent, interactive workloads such as ML pipelines and collaborative AI agents. ## Supported AWS Compute Services S3 Files can expose buckets to: - Amazon EC2 instances - Amazon ECS and EKS containers - AWS Fargate workloads - AWS Lambda functions This allows production applications, machine-learning systems, and agentic AI tools to access shared S3 data using ordinary file-system interfaces. ## Creating and Mounting an S3 File System The demonstration uses an EC2 instance and a general-purpose S3 bucket: - Create an S3 file system from the S3 console, AWS CLI, or infrastructure-as-code tools. - Configure or discover a mount target inside the relevant VPC. - Mount the file system on EC2 with commands such as: ```bash sudo mkdir /home/ec2-user/s3files sudo mount -t s3files fs-...:/ /home/ec2-user/s3files ``` - Files created in the mounted directory become visible in the S3 bucket after synchronization. - Standard commands such as `ls`, `echo`, and AWS CLI operations can verify that file contents are consistent between the mount and S3. ## Security, Permissions, and Monitoring - IAM identity and resource policies control access at both the file-system and object levels. - Data is encrypted in transit with TLS 1.3. - Data at rest uses SSE-S3 or customer-managed AWS KMS keys. - POSIX permissions rely on user IDs and group IDs stored as object metadata. - CloudWatch provides performance and update metrics. - CloudTrail records management events. - EC2 instances should use the latest `amazon-efs-utils` package, which is included in AWS-provided AMIs. S3 Files is best suited to workloads requiring shared, interactive file access while retaining data in S3. Teams should still evaluate access patterns and latency requirements, but the service offers a practical way to use familiar file operations without giving up S3’s centralized, durable storage model.

Read original(opens in new tab)
stripe3 min readCurated summary

How agents, digital wallets, and trust are rewriting checkout

The internet economy is reshaping checkout around mobile purchasing, digital wallets, local payment preferences, and AI-assisted shopping. Stripe’s analysis of nearly 20,000 B2C businesses shows that customers increasingly complete expensive purchases on mobile, expect region-specific payment options, and are becoming more open to buying through AI agents. Businesses that adapt checkout to local behavior and manage fraud intelligently can improve conversion while reducing unnecessary declines. ## Mobile Checkout Is Expanding to Higher-Value Purchases - Mobile dominates purchases under $50, but shoppers are increasingly using phones for purchases over $500. - This trend is strongest in APAC and EMEA, where mobile is already the preferred checkout device. - In the US, mobile gained share across every purchase range measured over the past two years. - Canada is an exception, with shoppers more likely to switch to desktop for purchases between $100 and $249. ## Digital Wallets Depend on Region and Generation - Digital wallets represent roughly 30% of global point-of-sale volume. - Sixty-one percent of surveyed shoppers said they would use a digital wallet. - Younger shoppers are especially likely to use wallets, including for purchases over $250. - Wallets cut average mobile checkout time in half, making speed a major advantage. - Preferences vary by market, from MB WAY in Portugal and MobilePay in Denmark to Alipay in China. - Businesses need to support the wallet mix that is actually popular in each region rather than relying only on Apple Pay, Google Pay, and similar global options. ## Localization Requires the Right Payment Mix - Forty-five percent of surveyed consumers made at least one international online purchase in the previous year. - International demand does not guarantee conversion; checkout must match local expectations for currency, payment methods, and presentation. - Markets such as Indonesia and Vietnam have fragmented preferences across wallets, bank transfers, debit-linked apps, and other local methods. - In more concentrated markets, conversion may depend heavily on supporting one dominant payment method. - Showing an irrelevant payment option can reduce conversion by up to 15%. - Supporting local leaders can significantly improve results: - BLIK increased Polish checkout conversion by an average of 46%. - Pix increased Brazilian checkout conversion by an average of 31%. ## AI Agents Are Changing Checkout and Payment Risk - Consumers are increasingly open to AI agents helping with purchase decisions. - Shopping and product discovery are moving into tools such as Google Gemini, Microsoft Copilot, visual search systems, and retailer-specific assistants. - Automated fraud, including card testing, is becoming easier to scale. - Overly strict risk controls can reject legitimate customers along with fraudulent transactions. - New payment models use more real-time signals, selective authentication, and improved routing and retries to balance fraud prevention with conversion. - Stripe reports that its AI-driven interventions can reduce fraud by 30% without lowering conversion. ## Checkout Becomes a Verification Layer Checkout is evolving beyond a final payment screen into a system that verifies identity, purchase intent, and authorization. Businesses should prioritize mobile performance, offer payment methods that reflect each market’s behavior, and prepare for transactions initiated by AI agents. The strongest checkout experiences will be fast, locally relevant, and capable of distinguishing legitimate buyers from automated fraud.

Read original(opens in new tab)
gitlab3 min readCurated summary

Pipeline security lessons from March supply chain incidents

Between March 19 and 31, 2026, attacks on Trivy, KICS, LiteLLM, and axios demonstrated that CI/CD pipelines are valuable supply-chain targets. The incidents exploited trusted tools, stolen credentials, packaging mistakes, and malicious dependencies to steal secrets or leak proprietary code. The article argues that centralized, mandatory pipeline policies can detect and block these patterns before they reach production. ## Recent Supply-Chain Incidents - **Trivy:** Attackers compromised GitHub Action tags and distributed a trojanized binary that harvested environment variables, cloud tokens, SSH keys, and CI/CD secrets. - **Checkmarx KICS:** Malicious versions of KICS GitHub Actions exfiltrated API keys, database passwords, cloud credentials, and service-account secrets. - **LiteLLM:** Backdoored PyPI releases executed payloads during installation or Python startup, stealing sensitive files and credentials. - **AI coding assistant package:** A 59.8 MB source map unintentionally exposed more than 1,900 TypeScript files, internal feature flags, model codenames, and a system prompt. - **axios:** Compromised maintainer credentials enabled malicious releases containing a cross-platform Remote Access Trojan through a poisoned dependency. ## Three Attack Patterns ### Poisoned Tools and Actions - Pipelines often implicitly trust security scanners, GitHub Actions, package versions, and container images. - Mutable tags can be changed after approval, causing future pipeline runs to execute malicious code. - Recommended controls: - Pin actions and tools to commit SHAs or image digests. - Verify checksums or signatures. - Block execution when integrity checks fail. ### Packaging Errors That Expose Intellectual Property - Incorrect `.npmignore` files or `files` settings can include source maps, internal configuration, and other debugging artifacts in published packages. - Pre-publish validation should compare package contents against an allowlist. - Builds should flag unexpected source maps, `.env` files, and internal files, then block publication when violations occur. ### Malicious Transitive Dependencies - A compromised dependency can affect users who never directly selected it. - Unexpected lockfile changes or newly introduced packages can spread attacks across an organization. - Recommended controls: - Compare dependency checksums with known-good lockfile state. - Detect unexpected dependency or version changes. - Reject unverified packages during builds. ## GitLab Pipeline Execution Policies - GitLab Pipeline Execution Policies inject mandatory CI/CD jobs into pipelines across an organization. - Policy-defined jobs cannot be bypassed through `[skip ci]` or `[no_pipeline]`. - Jobs can run in reserved pre- and post-pipeline stages, surrounding developer-defined jobs. - GitLab’s open-source Supply Chain Policies project provides independently deployable policies and sample violations for testing the three attack patterns. The practical recommendation is to make supply-chain validation mandatory and centralized: pin trusted inputs, inspect published artifacts, verify dependency changes, and block builds or releases when policy checks fail.

Read original(opens in new tab)
datadog1 min readCurated summary

How we built a real-world evaluation platform for autonomous SRE agents at scale

The provided content does not include the blog post itself. It contains Datadog navigation links and a page title announcing that Datadog was named a Leader in the 2026 Gartner® Magic Quadrant™ for Observability Platforms, but no substantive discussion of the evaluation platform or its conclusions. ## Available Information - Datadog’s page promotes its recognition as a Gartner Magic Quadrant Leader. - The navigation lists products across: - Infrastructure and application monitoring - Logs, databases, and data observability - Security - Digital experience monitoring - CI/CD and software delivery - Incident and service management - AI capabilities, including Bits AI Agents and Bits Investigation - The referenced URL path suggests the intended article may concern Datadog’s “Bits AI eval platform,” but the article text is not included. ## Conclusion Please provide the full blog post content for a meaningful section-by-section summary.

Read original(opens in new tab)
toss3 min readCurated summary

Layers of your time : Celebrating the time spent with Toss

The article argues that effective internal branding is not about making attractive company merchandise, but about designing meaningful experiences around employees’ time and contributions. Through an eight-month redesign of Toss’s work-anniversary gift, the designer created a layered light that visually represents accumulated years, protected quality despite production delays, and carefully designed the delivery experience. The project concludes that strong internal branding requires a clear reason, end-to-end experience design, and unwavering standards. ## From Merchandise to a Celebration of Time - Toss celebrates employees’ work anniversaries with annual gifts such as medals, wine, and cubes. - Over time, some employees began giving the gifts away, suggesting they had become clutter rather than meaningful keepsakes. - The redesign aimed to: - Sincerely celebrate each employee’s time at the company. - Show appreciation for the six-month gap while the gift was being redesigned. ## Three Criteria for the New Gift The new product had to: - Avoid being immediately stored away in a drawer. - Physically show the accumulation of time. - Remain beautiful whether celebrating one year or ten years. A layered lamp was chosen because employees could add one disk for each anniversary. As the disks accumulated, the layers of light became deeper, making the passage of time visible through the object’s structure. ## Hardware Development and Quality Control - The designer had no previous hardware or lighting-production experience. - The team repeatedly tested: - Disk thickness, including differences as small as 0.5 mm. - The spacing between the lamp body and disks. - Light intensity as more disks were added. - The product was divided into two versions: - White for years 1–10. - Black from year 11 onward, symbolizing the beginning of a new period. - Dozens of defects appeared during final factory inspection. - Rather than compromise quality to meet the schedule, distribution was delayed. - Approximately 5,000 lamps were individually inspected and improved. ## Giving the Product a Warm Voice - The lamp was named **Layered Lighting**. - The phrase **“Layers of your time at toss”** was engraved on the lamp and packaging. - The communication emphasized remembrance and celebration rather than corporate motivation. - Serif typography, carefully matched packaging, and handwritten name cards created a warmer, more personal experience. ## Designing the Moment of Delivery - Instead of asking employees to pick up their gifts, the team placed them directly at employees’ desks. - The redesigned process gave employees the correct number of disks for their accumulated tenure. - The intended experience was: - Discovering the gift on a Monday morning. - Opening the box and reacting with surprise. - Taking photos and sharing the moment with colleagues. - Over one weekend, the team placed gifts at 2,500 desks among approximately 3,900 employees. - The operation took 26 hours. - Employee photos and reactions spread across Slack and Instagram, including one memorable comment: “I now have a reason to stay another year.” ## Principles of Good Internal Branding - **Start with the reason:** Every object or graphic should clearly communicate why it exists. - **Design the experience, not just the object:** The interaction begins before the product is opened and includes how it is received and shared. - **Protect the standard until the end:** Internal projects are easy to compromise because their results may not be immediately visible, making a clear standard essential. Good internal branding helps employees feel that they belong to a good team. That sense of belonging can strengthen engagement and ultimately improve the quality of the work they create.

Read original(opens in new tab)
datadog3 min readCurated summary

How we built a real-world evaluation platform for autonomous SRE agents at scale

Bits AI SRE improved in isolated scenarios but lacked a way to detect regressions across the broader range of production incidents. The team found that tool-level tests and live replays could not capture failures caused by multi-step reasoning or changing telemetry. They built a replayable evaluation platform combining realistic investigation labels, scalable orchestration, and longitudinal performance tracking. ## Subtle Regressions from Well-Intentioned Features - Adding a monitor’s service name to the agent’s initial context improved some internal investigations. - Across broader scenarios, it introduced irrelevant signals that confused the agent and degraded unrelated investigations. - Because there was no representative evaluation set, the team could not measure the change’s wider impact before internal misses exposed it. - The incident demonstrated the need to evaluate every change across diverse investigation types. ## Limits of Tool Tests and Live Replay - Testing tools individually failed to capture errors caused by incorrect interactions between valid tool outputs. - Live investigation replay was difficult to scale because: - Results were not consistently aggregated. - Production environments changed. - Telemetry expired, making investigations unreplayable. - Standard evaluation frameworks assumed clean inputs and static datasets, unlike agents operating over production telemetry. - The team needed controlled, offline replay of realistic end-to-end investigations. ## Evaluation Labels and World Snapshots - Each label represents one production-style investigation. - It contains: - **Ground truth:** the issue’s actual root cause. - **World snapshot:** the queries and signals available when the issue occurred. - The agent is never shown the root cause directly; it must reason from the preserved signals. - Labels must cover varied technologies and failure modes, including: - Kubernetes pod failures - Kafka lag - Bad-code deployments - Complex multi-service business failures - A narrow or overly clean dataset would make performance appear better than it really is. ## Orchestrating Evaluations at Scale - The platform runs Bits against labels, scores the outcomes, and tracks quality over time. - It supports comparisons across: - Investigation categories - Model variants - Configuration versions - Evaluation runs - The architecture consists of a shared label set, an orchestration layer, and reporting infrastructure. - This allows teams to determine whether improvements in one domain, such as Kafka, regress another, such as Kubernetes. ## Scaling Label Creation - The team initially created labels manually from Datadog alerts. - Manual labeling provided early coverage but consumed engineering time and remained far from representative. - They embedded label generation into Bits itself: - Customer feedback and investigation data are used to derive root causes. - Relevant queries are preserved as the world snapshot. - Each user interaction becomes a potential evaluation case. - This increased label creation rates by an order of magnitude and allowed coverage to grow with product usage. ## Agent-Assisted Validation - Early labels required extensive human review, especially when feedback was ambiguous or reconstructed signals were uncertain. - As ingestion grew, manual review became a bottleneck. - Bits was then used to assist with validation by aggregating related signals, identifying relationships, and resolving ambiguous feedback before human review. ## Practical Conclusion Reliable agent improvement requires more than testing individual tools or replaying live incidents. A representative, production-derived label set combined with reproducible end-to-end evaluations makes regressions visible and enables safer iteration.

Read original(opens in new tab)
gitlab3 min readCurated summary

Streamline test management with SmartBear QMetry GitLab component

The SmartBear QMetry GitLab Component automates the transfer of test results from GitLab CI/CD pipelines into QMetry Test Management Enterprise. By publishing JUnit, TestNG, and other supported results automatically, it removes manual uploads and provides a centralized, traceable view of testing. The integration helps teams accelerate release decisions while supporting compliance and audit requirements. ## Why Integrate GitLab with QMetry? - **Eliminate manual uploads:** Test results are transferred automatically after pipeline execution, reducing effort and preventing outdated or inconsistent records. - **Improve traceability:** Teams can connect requirements, test cases, executions, commits, builds, and pipelines in a single audit trail. - **Accelerate feedback:** QA teams, product managers, and stakeholders gain access to results immediately after tests finish. - **Support regulated development:** Centralized, versioned test records help organizations in aerospace, financial services, automotive, and medical-device industries demonstrate test coverage and compliance. - **Enable AI-driven insights:** QMetry can analyze execution history to identify flaky tests, predict failures, and suggest optimization opportunities. ## GitLab–SmartBear Integration - The component is part of a broader partnership connecting GitLab’s CI/CD and DevSecOps capabilities with SmartBear’s testing and quality-management tools. - The integration is intended for organizations that need centralized visibility across complex or regulated software-development lifecycles. - QMetry acts as the system of record for test planning, execution, tracking, and reporting. ## Requirements and Test Result Flow Before configuring the integration, teams need: - A GitLab project with automated tests that generate JUnit XML, TestNG XML, or another supported format. - A QMetry Test Management Enterprise account with API access enabled. - A QMetry API key with permission to upload test results. - An existing QMetry project. - Basic knowledge of GitLab CI/CD and `.gitlab-ci.yml`. - Optionally, a configured QMetry test suite for better organization. The automated flow is: - GitLab runs unit, integration, end-to-end, or other automated tests. - The tests generate result files. - The QMetry component runs as a pipeline job. - It reads the result files and uploads them to QMetry through the API. - QMetry processes the results for reporting and analysis. ## Obtaining QMetry API Credentials - Log in to QMetry Test Management Enterprise. - Open the user profile and navigate to **Settings** or **API Access**. - Generate a named API key, such as `GitLab CI/CD Integration`. - Grant the key write access for test-result uploads. - Copy the key immediately because it is displayed only once. - Record the QMetry instance URL, typically in the form `https://your-company.qmetry.com`. The API key should be treated like a password. It should not be committed to `.gitlab-ci.yml` or stored in plain text; GitLab CI/CD variables should be used to protect it. The component provides a practical way to make QMetry the centralized source of truth for pipeline testing. Organizations should secure the API credentials, configure the component in their GitLab pipeline, and continuously publish results so teams can improve visibility, traceability, and release confidence.

Read original(opens in new tab)
gitlab2 min readCurated summary

GitLab Duo CLI: Agentic AI now in the terminal

GitLab Duo CLI brings GitLab’s agentic AI capabilities into the terminal, extending AI assistance beyond interactive coding in an IDE. Its public beta supports both human-guided sessions and unattended automation across the software development lifecycle, including coding, CI/CD, testing, and troubleshooting. GitLab emphasizes security through approvals, prompt-injection detection, auditing, and configurable permissions. ## Terminal-Based Agentic Development - The CLI is designed for work outside the IDE and GitLab UI. - Terminals are well suited to: - Automation and scripting - Piping and chaining commands - Portable workflows - Reproducible debugging - IDEs remain better for interactive, context-rich development, while Duo CLI targets automation and machine-driven workflows. ## Installation - Users with GitLab’s `glab` CLI can start Duo CLI with: ```bash glab duo cli ``` - GitLab Duo CLI can also be installed as a standalone tool. ## Capabilities and Operating Modes - Duo CLI can build, modify, refactor, and modernize code. - It can access agents and flows defined in GitLab Duo Agent Platform. - Potential uses include: - Creating and optimizing CI/CD configurations - Running multi-step development tasks - Debugging failed pipelines - Integrating AI into unattended workflows ### Interactive Mode - Provides editor-independent terminal chat. - Keeps a human in the loop by requiring approval before actions. - Supports codebase exploration, code creation, error fixing, and pipeline troubleshooting. ### Headless Mode - Runs without user interaction. - Designed for CI/CD runners, scripts, and automated workflows. - Enables agents to operate in environments where no developer is present. ## Security and Governance - Interactive actions require human approval by default. - Prompt-injection detection is built into the Duo Agent Platform. - Composite identity controls agent access and makes AI-driven actions auditable. - Instruction files such as `chat-rules.md`, `AGENTS.md`, and `SKILL.md` define permitted tasks, resources, context, and actions. - These controls apply least-privilege principles to AI agents. ## Availability - Duo CLI is available through a free trial of GitLab Duo Agent Platform. - Free-tier GitLab users can sign up for the platform. - GitLab Premium and Ultimate subscribers can enable Duo Agent Platform and use included GitLab Credits. GitLab Duo CLI is best suited to teams that want AI assistance across the full development lifecycle rather than only inside an editor. Its combination of interactive approvals, headless execution, and platform-level security makes it useful for both developer support and automated DevSecOps workflows.

Read original(opens in new tab)
netflix4 min readCurated summary

Stop Answering the Same Question Twice: Interval-Aware Caching for Druid at Netflix Scale

Netflix’s Druid deployment now exceeds 10 trillion rows and can ingest 15 million events per second, but repetitive dashboard queries became a scaling problem. Its new experimental caching layer handles rolling time windows by reusing settled historical results and querying Druid only for recent, changing data. Netflix accepts up to five seconds of additional staleness in exchange for substantially lower query load. ## The Scaling Problem - A dashboard with 26 charts can issue 64 queries per load. - Viewed by 30 people and refreshed every 10 seconds, that becomes roughly 192 queries per second. - Druid’s full-result cache misses whenever a rolling time interval changes. - Druid avoids caching realtime segments to preserve result correctness and determinism. - Per-segment caching reduces historical scans but still requires brokers to gather and merge results for every request. - Adding hardware to handle this redundant workload would be prohibitively expensive. ## Caching Only the Unsettled Data - In a three-hour query, most data is already stable; only the newest minutes are likely to change. - The cache stores previously returned historical portions and sends Druid only the uncached interval. - This approach is designed for time-grouped queries such as timeseries and groupBy queries. ## Deliberate Staleness - The cache can make the newest data up to five seconds stale. - This is acceptable because dashboards typically refresh every 10–30 seconds. - Netflix’s pipeline already has up to roughly five seconds of latency at P90. - Many queries also intentionally end at `now-1m` or `now-5s` to avoid unstable, newly arriving data. ## Exponential TTLs - Cache lifetimes increase with the age of each data point because older data is less likely to change. - Data under two minutes old has a minimum TTL of five seconds. - After that, TTL doubles for each additional minute: - 10 seconds at two minutes old - 20 seconds at three minutes - 40 seconds at four minutes - TTLs are capped at one hour. - Fresh data is refreshed frequently to account for late-arriving events, while older data remains cached longer. ## Time-Based Bucketing - A single cache entry per query and interval would still miss whenever a rolling window shifted. - Netflix instead uses a map-of-maps: - The outer key is a hash of the query excluding its time interval. - Inner keys represent timestamps bucketed by query granularity or at least one minute. - Big-endian timestamp encoding preserves chronological order for efficient range scans. - A three-hour query at one-minute granularity becomes 180 independently cached buckets. - When the window moves, most buckets can be reused and only the newly exposed range must be fetched. ## Router-Integrated Cache Service - The cache currently operates as an external service behind the Druid Router. - Cacheable requests are intercepted transparently: - Fully cached requests are answered directly. - Partially cached requests are narrowed to the missing interval and sent to Druid. - Metadata queries and queries without time-based grouping bypass the cache. - The proxy can be enabled or disabled without changing clients. - Netflix views this as an interim design while exploring deeper integration with Druid. ## Query Identification and Lookup - Incoming queries are parsed to extract their interval, granularity, and structure. - A SHA-256 hash is generated from the query’s logical contents, including datasource, filters, aggregations, and relevant context properties, while excluding the time interval. - The cache looks for buckets within the requested range. - Lookup requires cached buckets to be contiguous from the beginning of the requested interval; the provided article text ends while explaining the handling of expired or missing buckets. Netflix’s approach is best suited to frequently repeated rolling-window dashboards where a small, slightly stale tail is acceptable. Segmenting results by time and assigning age-based TTLs allows the system to preserve freshness where it matters while eliminating most redundant Druid work.

Read original(opens in new tab)
github3 min readCurated summary

GitHub Copilot CLI combines model families for a second opinion

GitHub Copilot CLI’s experimental Rubber Duck feature adds an independent reviewer from a different AI model family to catch mistakes before they compound. When Claude models orchestrate a task, GPT-5.4 reviews plans, implementations, and tests at key checkpoints. On SWE-Bench Pro, Claude Sonnet 4.6 with Rubber Duck closed 74.7% of the performance gap with Claude Opus 4.6 alone, particularly on complex, multi-file tasks. ## The Problem with Self-Review - Coding agents typically assess a task, plan, implement, test, and iterate. - Early assumptions can create downstream dependencies and make small mistakes expensive to fix. - Self-reflection helps, but a model reviewing its own work may retain the same training biases and blind spots. ## Cross-Family Review with Rubber Duck - Rubber Duck is a focused review agent powered by a complementary model family. - Claude orchestrators currently use GPT-5.4 as the reviewer. - It produces a short list of high-value concerns, including: - Missed details - Questionable assumptions - Architectural risks - Relevant edge cases ## Evaluation Results - On SWE-Bench Pro, Sonnet 4.6 plus Rubber Duck approached the resolution rate of Opus 4.6 running alone. - Benefits were strongest for problems involving at least three files and 70 or more steps. - Sonnet plus Rubber Duck scored: - 3.8% above the Sonnet baseline on difficult tasks - 4.8% higher on the hardest tasks across three trials - Examples included detecting: - A scheduler that would start and immediately exit - A loop overwriting one dictionary key and dropping Solr facet categories - Cross-file Redis references that would silently break email confirmation flows ## When Reviews Happen Rubber Duck can be invoked automatically, reactively, or on request: - After a plan is drafted, to prevent flawed decisions from spreading. - After complex implementation work, to identify edge cases. - After tests are written but before they run, to expose coverage gaps or weak assertions. - When the primary agent is stuck or repeating an unproductive loop. - Any time the user asks Copilot to critique its work. Copilot incorporates the feedback and explains what changed. Reviews are intentionally infrequent and targeted at checkpoints where they provide the most value. ## Availability and Use Cases - Rubber Duck is available in Copilot CLI’s experimental mode through `/experimental`. - It works with Claude Opus, Sonnet, and Haiku as orchestrator models, provided the user has GPT-5.4 access. - It is especially suited to: - Complex refactors and architectural changes - High-stakes coding tasks - Test coverage review - Getting a second opinion before committing to a plan Rubber Duck is a practical way to reduce model-specific blind spots by combining different AI families. Developers can enable it experimentally in Copilot CLI and use automatic or on-demand critiques for difficult work.

Read original(opens in new tab)
cloudflare3 min readCurated summary

How we built Organizations to help enterprises manage Cloudflare at scale

Cloudflare’s new Organizations feature helps enterprises centrally manage users, policies, accounts, and analytics across multiple Cloudflare Accounts. It preserves least-privilege access by allowing teams to remain separated while giving designated organization administrators broader oversight. Initially available in public beta for enterprise customers, Organizations is designed to reduce administrative complexity without granting unauthorized access. ## Why Enterprises Use Multiple Accounts - Separate accounts help teams manage their own resources and limit permissions. - Fine-grained RBAC can still be cumbersome when administrators must enumerate individual resources. - Central administrators currently need access to every account for reporting and policy management. - This setup is fragile because account-level administrators can remove those central administrators. ## Organization Structure and Account Management - Organizations add a management layer above individual Cloudflare Accounts. - The core feature is a flat list of accounts onboarded into the organization. - An account can be added only by someone who is a Super Administrator for that account. - Organizations are built on Cloudflare’s existing Tenant system, originally developed for partners. ## Organization Super Administrators - Org Super Administrators have Super Administrator permissions across every account in the organization. - They do not need memberships in child accounts and do not appear in account-level user interfaces. - The new role is the first of several planned organization-level roles. - Cloudflare consolidated legacy authorization paths into domain-scoped roles. - The permissions overhaul added approximately 133,000 lines of code and removed 32,000. - Permission checks for enumeration endpoints such as `/accounts` and `/zones` became 27% faster, especially for users with access to thousands of accounts. ## Organization-Wide Analytics - Org Super Administrators can view aggregated HTTP traffic analytics. - The dashboard combines data across all accounts and zones in the organization. - Cloudflare plans to add analytics for additional products over time. ## Shared Configurations - Organizations allow centrally managed policy sets to be shared across accounts. - Initial examples include WAF and Gateway policies. - Authorized users in the source account can update shared policies for the broader enterprise. - Security analysts can therefore manage enterprise-wide WAF rules without becoming organization or account administrators everywhere. ## Roadmap and Availability - The beta initially targets enterprise customers. - Cloudflare plans to expand access to pay-as-you-go and other customers, followed by the partner ecosystem. - Planned capabilities include: - Organization-level audit logs - Billing reports - More analytics dashboards - Additional organization user roles - Self-service account creation ## Security-First Rollout - Cloudflare will not automatically create organizations through account backfilling. - A self-service invitation process ensures that no user gains access without approval from a relevant Super Administrator. - The first eligible Super Administrator to claim the company’s organization can add other accounts where they also hold Super Administrator access. - If another employee has already claimed the organization, administrators must coordinate invitations or account-level approval. - Cloudflare Support will not configure organizations on customers’ behalf. Enterprise customers can claim an organization from the Cloudflare Dashboard’s Organizations tab at no additional cost. Companies should coordinate internally with their Super Administrators to ensure all relevant accounts are added securely.

Read original(opens in new tab)
aws3 min readCurated summary

AWS Weekly Roundup: AWS DevOps Agent & Security Agent GA, Product Lifecycle updates, and more (April 6, 2026) | Amazon Web Services

The April 6, 2026 AWS Weekly Roundup highlights the general availability of AWS DevOps Agent and AWS Security Agent, autonomous “frontier agents” designed to handle complex operational and security tasks. It also reviews AWS service lifecycle changes and summarizes notable product launches and technical updates from the previous week. The overall message is that AWS is expanding agentic automation while helping customers manage service transitions and adopt new capabilities. ## AWS DevOps Agent and Security Agent Reach GA - **AWS DevOps Agent** - Investigates incidents, accelerates resolution, and helps prevent recurring problems. - Works continuously across multiple steps until an operational goal is complete. - Customers report up to **75% lower mean time to resolution (MTTR)** and **3–5 times faster incident resolution**. - Western Governors University reduced resolution times from hours to minutes. - **AWS Security Agent** - Provides continuous, context-aware penetration testing during the software development lifecycle. - Operates similarly to a human penetration tester. - LG CNS reported testing that was more than **50% faster**, approximately **30% less expensive**, and produced fewer false positives. - **Deployment flexibility** - Both agents support AWS, multicloud, and on-premises environments. - They are intended to automate repetitive investigative and testing work while allowing teams to focus on higher-value activities. ## AWS Service Lifecycle Changes AWS updated its Product Lifecycle Changes guidance on March 31, 2026, including migration recommendations and alternative services. - Services with availability changes or maintenance guidance include: - AWS App Runner - AWS Audit Manager - AWS CloudTrail Lake - AWS Glue Ray jobs - AWS IoT FleetWise - Amazon Application Recovery Controller Readiness Check - Amazon Comprehend features such as Topic Modeling and Prompt Safety Classification - Amazon Rekognition streaming and batch moderation features - Amazon SNS Message Data Protection - Services listed as entering sunset include: - AWS Service Management Connector - Amazon RDS Custom for Oracle - Amazon WorkMail - Amazon WorkSpaces Thin Client - **Amazon Chime SDK Proxy Sessions** is reaching sunset. AWS recommends reviewing the relevant service documentation or contacting Support to reduce operational disruption. ## Notable AWS Launches - Amazon ECS introduced **Managed Daemons for ECS Managed Instances**. - The AWS Sustainability console now consolidates **Scope 1–3 emissions reporting**. - **Amazon Bedrock AgentCore Evaluations** became generally available. - AWS Transform added generally available automated codebase analysis. - CloudWatch introduced OpenTelemetry Container Insights for Amazon EKS in preview. - Amazon Lightsail added compute-optimized bundles with up to **72 vCPUs**. - Amazon CloudFront added **SHA-256 support** for signed URLs and signed cookies. ## Additional AWS Resources The roundup also points readers to material on: - Architecting agentic AI applications on AWS. - Reducing data-transfer costs with Network Load Balancers. - Preventing hallucinations in production AI agents. - The AWS World Sports Innovation Cup. - Exploring AWS communities through an interactive 3D globe. AWS also encourages readers to participate in Builder Center discussions, community events, AWS Summits, and developer-focused programs. AWS teams should review the lifecycle notices for services they depend on, while developers and operations groups may benefit from evaluating the new agents and launches for automation, security testing, and observability improvements.

Read original(opens in new tab)