@dashauni
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Husband, father, volunteer, athlete, continuous learner. Tweets are mine. Spring Developer Advocate @VMwareTanzu #JUICE #LiftAsWeClimb @Testcontainers Champion
KC MO
Joined March 2008
- Tweets24.8K
- Following4K
- Followers5.6K
- Likes39.3K
Pinned Tweet
Each new CVE is the dinner bell for bad actors all over the world. If they don't act on it immediately, they might not get dinner.
What Are Buildpacks? Build OCI Images Without Dockerfiles
bell-sw.com/blog/what-are-bu…
Very good article by @cat_edelveis
St Louis JUG! Thursday! Don't meet me there. Beat me there!
"Agentic AI Workflows with Embabel"
meetup.com/gatewayjug/events…
DaShaun retweeted
Spring Office Hours: S5E25 - Future of Software Development with Josh Long nitter.cf/i/broadcasts/1nxnRBQRA…
DaShaun retweeted
Spring Cloud Bus has been consolidated into Spring Cloud Stream. The 5.0.x branch remains in the Bus GitHub repo until OSS support for it ends at the end of July 2027. github.com/spring-cloud/spri…
The docs in the new location.
docs.spring.io/spring-cloud-…
Taste is what differentiates us from machines and from each other. That's why humans stay in the loop: somebody has to know what good looks like. #Taste #AICoding #DevExperience @brunoborges & @starbuxman
A coding agent triggered by every new GitHub issue is prompt injection bait. One prompt-jacked issue and your secrets are gone. Guardrails exist. #PromptInjection #GitHubActions #Security @brunoborges & @starbuxman
Netflix @pbakker telling @starbuxman how much it costs to get some really valuable performance improvements.
Scope swapping attacks work because OAuth requests pass through the browser. PAR pushes them over the back channel instead. Here's how it works. #OAuth2 #SpringSecurity #AppSec @joe_grandja & @starbuxman
Hardened images ship with no shell, no package manager, no download utilities. Immutable and near-zero CVEs, kept clean by a maintainer who patches on release. #HardenedImages #CVE #Containers
Gartner says the semantic layer will be critical infrastructure by 2030, on par with cybersecurity. The problems we wait for the next model to solve? Solved at the data level. #AI #SemanticLayer
One line in setup-java caches your Maven, Gradle, or sbt deps in GitHub Actions. No more downloading all artifacts on every CI run. Still fully reproducible. #GitHubActions #Java #CI @brunoborges & @starbuxman
A stolen access token is useless with DPoP. RFC 9449 stops token replay attacks, now in Spring Authorization Server 1.5 and Spring Security 7. #SpringSecurity #DPoP #OAuth2 @joe_granda & @starbuxman
github.com is his new IDE. He hasn't opened VS Code as an editor in months. Coding is intent-driven now: state the intent, review the code, shape the result. #GitHub #Copilot #AI @brunoborges & @starbuxman
Spring Authorization Server is now part of Spring Security 7. Why? It matured, has a full feature set, and one unified release cycle changes everything. #SpringSecurity #OAuth2 #Java @joe_grandja & @starbuxman
Tomorrow, you should join me, @therealdanvega, and @starbuxman for the next episode of #SpringOfficeHours
We are going to talk about the future of software development, in the age of AI.
youtube.com/live/NQK6gdbCWDQ