Why AI Demands a New Approach to Shift Left

From the source: Sonatype Blog

AI has chang ed the pace of software development . It i s also changing the conditions under which application security programs have to operate.

Read the full story on Sonatype Blog
Originally published by Sonatype Blog on 15 Sept 2026. Techarda links to the original rather than republishing it. Read the full article →

Have you worked with this?

The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.

Start the discussion

More from Sonatype

Recent updates from Sonatype, so you can tell whether this is a one-off or part of a pattern.

All Sonatype news →
DevOps & Platform Engineering

The New Engineering Problem: Managing What AI Decides to Import

AI makes it faster to turn an idea into working software. A developer describes a feature, integration, or service and receives an implementation in minutes. Coding agents go further by editing files, running tests, troubleshooting failures, and preparing changes for review.

Sonatype·via Sonatype Blog
DevOps & Platform Engineering

Sonatype Is Now Awardable on the Platform One Solutions MarketPlace

Software delivery across th e Department of War (DoW) dep ends on speed, but growing use of open source, third-party components, and AI-assisted development makes the software supply chain harder to control. DoW teams need to identify and address risk early without introducing manual gates that slow mission delivery.

Sonatype·via Sonatype Blog
DevOps & Platform Engineering

Why Are OSS Attackers Always After CI/CD Credentials?

CI/CD credentials are a prime target of malicious open source packages because of the sheer authority those credentials carry. Depending on their privileges, they can provide access to source code, build systems, package registries, cloud infrastructure, and production delivery.

Sonatype·via Sonatype Blog

More in DevOps & Platform Engineering

What other companies in DevOps & Platform Engineering are doing. The category page shows who’s active, side by side.

Compare companies in DevOps & Platform Engineering →
DevOps & Platform EngineeringWhy it matters

Secure AI agents with HashiCorp Boundary

Enable AI agents to securely access your resources while operating within enterprise identity, access, and audit controls.

HashiCorp·via HashiCorp Blog
DevOps & Platform Engineering

Terraform provider for Google Cloud 8.0 now generally available

The Terraform provider for Google Cloud 8.0 builds on expanded infrastructure discovery workflows, modernizes provider defaults, removes support for retired Google Cloud services, and improves consistency between Terraform configurations and Google Cloud APIs.

HashiCorp·via HashiCorp Blog
DevOps & Platform EngineeringWhy it matters

AI agents need continuity, not just context

Pulumi Neo works on infrastructure the way an engineer does: it clones repositories, edits files, installs dependencies, runs previews, and produces intermediate work along the way. A task is not only a conversation with a model. It is also a working directory that has to survive long enough for the agent to keep making progress. Imagine asking an agent to upgrade a Pulumi provider version across…

Pulumi·via Pulumi Blog
DevOps & Platform EngineeringHow-to

CI/CD Security Best Practices: A 2026 Pipeline Checklist

CI/CD security best practices for 2026: secrets management, scoped access, dependency scanning, signed artifacts, and audit logging in one checklist. | Blog

Harness·via Harness Blog