Ever discovered a legacy app nobody touched for 10 years — only to realize the business still depends on it daily? That’s how teams rediscover Struts today. @spoole167 explains why “just rewrite it” is fantasy in enterprise #Java systems.
Read: javapro.io/2026/06/16/1-why-…@HeroDevs
143 CVEs. 79 projects. One end-of-life release.
Spring Boot 2.7's last open-source version still carries every one of them, and no patch is coming.
#SpringBoot#OpenSource#AppSec#EOL
Nobody rewrites a working app on someone else's schedule.
React 16 and 17 no longer get upstream security patches. NES for React ships supported drop-in replacements with ongoing CVE fixes, so your app stays secured and compliant. 🔒
#React#OpenSourceSecurity#AppSec
You don't run code on people who haven't agreed to it. That norm has ended careers.
Claude uploaded live malware to PyPI in a botched eval and 15 real systems ran it.
It even worked around restrictions to squat a phantom dependency and breach 3 orgs.
bleepingcomputer.com/news/se…
The CRA is shifting legal responsibility for software security back to manufacturers. With mandatory vulnerability reporting starting September 2026, the clock is ticking.
Get ahead of compliance with the eBook, "Built to Last" by Sal Kimmich (OpenUK).
hubs.la/Q04qBft10
Counting down: 18 days until Spring Boot 3.5 EOL. ⏲
This is the dangerous kind — no compile error, no warning. Can you catch it:
True or false: In Jackson 3.0, JacksonException no longer extends IOException — it's now a RuntimeException.
#SpringBoot#Java#SoftwareEngineering
CVEs only track the vulnerabilities someone actually reported. So what happens when a package goes end-of-life and no one's looking anymore?
That's the "ghost in the dependency tree" — and it's exactly what Isaac Wuest, Product Line Leader at HeroDevs, unpacked on @openssf 's What's in the SOSS podcast.
Listen to the full podcast 🎧 openssf.org/podcast/2026/06/…#OpenSource#SoftwareSupplyChain#EndOfLife#CyberSecurity#AppSec
A book. Some code. One very frustrated developer. 🌱
That's how Spring started — as a pushback against the bloated, untestable mess that enterprise Java had become in the early 2000s. Rod Johnson didn't just propose an alternative; he shipped one.
Dependency injection went mainstream. App servers got lighter. And today, Spring quietly powers Netflix, Alibaba, and most of the enterprise software you'll never see.
▶️ piped.video/watch?v=0Gb1z-2S…#Java#Spring#SoftwareHistory#OpenSource#DevCommunity
Your laptop is the new perimeter! 💻⚔️ Steve Poole (@spoole167) is coming to DevBcn 2026 to reveal how "routine" scripts can hand over control of your machine.
🛡️ Learn to defend your lifecycle from the unseen dangers.
📅 June 16-17
🔗 buff.ly/ploAMrb#devbcn26
Check out my latest article: Planes, Trains, Automobiles — and CypherCon: My Travel Plans Were Pen Tested, But Resilience Ruled the Day linkedin.com/pulse/planes-tr… via @LinkedIn