home.social

#shiftleft — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #shiftleft, aggregated by home.social.

fetched live
  1. Красное не мёржим: как мы внедрили e2e тесты в разработку

    Можно ли сделать e2e тесты мощным инструментом раннего отлова багов, не потопив при этом CI и не всем не разругавшись? Рассказываю, через что пришлось пройти, чтобы релизы были спокойные, пайплайны — зеленые, разработчики — довольные. Как мы это внедряли, сколько сопротивления получили и что из этого выжило спустя четыре месяца.

    habr.com/ru/articles/1070260/

    #shiftleft #тестирование #quality_gates #react_native #e2e #e2e_тестирование #e2eтесты #qa_automation #qa

  2. Your test suite is green. Your test data is fiction. Guess which one production believes.

    A suite built on stale or invented data reports green while real edge cases wait in production. Test data is a feedback loop, and a broken one lies to you.

    In the AI era it's also a compliance firewall: never hand a production dump to an external model. Mask it, synthesize it, then let AI in.

    A practice from my book: leanpub.com/CyberneticEnterpri

  3. Мобильное тестирование в 2026: от истоков к трендам

    Какова ситуация в мобильном тестировании в 2026-м году? На связи Ильнур – ведущий тестировщик: начал свой путь в ИТ 10 лет назад как специалист технической поддержки. Со временем понял, что хочу не просто «чинить», а понимать, как всё устроено. Так я пришёл в тестирование и уже через год стал тимлидом команды. На протяжении следующих 5 лет участвовал в запуске более 10 приложений – от MVP до многомиллионных. Я учился на ошибках, пропускал через себя сотни релизов, «съел собаку» в ручном тестировании, понял, как работают платформы, сети, железо. Хочу поделиться своими мыслями о мобильном тестировании как человек, который знает сферу изнутри. Читать полностью

    habr.com/ru/companies/sovcomba

    #qa #qa_mobile #qa_automation #ai #shiftleft #lowcode #тестирование #искусственный_интеллект #мобильная_разработка #мобильное_тестирование

  4. RE: mastodon.online/@myfear/116826

    "I still think the basic rule is simple: use AI to go faster on work you understand already. If you hand core business logic to a model and hope for the best, you are outsourcing the part you still need to own."

    Note that if you click the play link inline on Mastodon you'll only get the audio which isn't so useful. Click on the link to view the (5 minute) video. Noting that despite the title the message of this is not specific to Quarkus.

  5. RE: mastodon.online/@myfear/116826

    "I still think the basic rule is simple: use AI to go faster on work you understand already. If you hand core business logic to a model and hope for the best, you are outsourcing the part you still need to own." #shiftLeft #AI

    Note that if you click the play link inline on Mastodon you'll only get the audio which isn't so useful. Click on the link to view the (5 minute) video. Noting that despite the title the message of this is not specific to Quarkus.

  6. Тестирование требований с ИИ: что делать, когда контекст уже готов

    Привет, Хабр! Меня зовут Алена Метенева, я руководитель направления по тестированию в Росгосстрахе. А это третья статья цикла про внедрение ИИ в тестирование. В первой статье я рассказывала, зачем мы вообще пошли в пилот и почему начали с ручного режима в Cursor. Во второй разбирала подготовку контекста: от простого кейса до больших ТЗ с PDF, диаграммами и макетами. Теперь двигаемся дальше: контекст уже собран и актуализирован, значит пора переходить к следующему этапу — тестированию требований с помощью ИИ .

    habr.com/ru/companies/rgs_it/a

    #тестирование #требования #ии #shiftleft

  7. Unravel the meaning behind "treating data as an asset" in a data-driven world. Learn how embedding data quality, governance, and compliance practices early in the software development lifecycle can transform data management. Join us as we delve into the "Shift Left" approach and its significance on data quality. #DataAsset #DataQuality #ShiftLeft 👉 https://peterbaumann....
    community.datentreiber.com/202

  8. The only thing "right" about testing late is how wrong it always goes.

    In "The Cybernetic Enterprise" I explain why Shift Left is essential: move testing, security, and validation to the beginning, not the end.

    With AI generating code faster than ever, automated tests and security checks are the only way to keep quality intact.

    Shift Left is not a testing strategy. It is a survival strategy.

    cyberneticenterprise.com/

  9. DevSecOps Mindset

    Security isn't a gate you pass through; it's the road you build. As a DevSecOps Engineer, my goal is to bake security into the pipeline so deeply that it becomes invisible. Stop fixing vulnerabilities—start preventing them by design.

    🛡️💻 #DevSecOps #InfoSec #ShiftLeft

  10. DevSecOps Mindset

    Security isn't a gate you pass through; it's the road you build. As a DevSecOps Engineer, my goal is to bake security into the pipeline so deeply that it becomes invisible. Stop fixing vulnerabilities—start preventing them by design.

    🛡️💻 #DevSecOps #InfoSec #ShiftLeft

  11. Shifting Left delivers clean, reliable, and accessible data to everyone who needs it - right when they need it.

    The result? Less complexity, lower overhead, and far less break-fix work, freeing teams to focus on higher-value problems.

    At the core of a #ShiftLeft strategy are Data Products. They form the backbone of healthy data communication and ensure quality is built in - not patched on later.

    📖 Great insights from this #InfoQ article on rethinking the Medallion Architecture: bit.ly/3WHjxsf

    #SoftwareArchitecture #DataMesh #DataEngineering #DataLake #DataPipelines

  12. Shifting Left delivers clean, reliable, and accessible data to everyone who needs it - right when they need it.

    The result? Less complexity, lower overhead, and far less break-fix work, freeing teams to focus on higher-value problems.

    At the core of a strategy are Data Products. They form the backbone of healthy data communication and ensure quality is built in - not patched on later.

    📖 Great insights from this article on rethinking the Medallion Architecture: bit.ly/3WHjxsf

  13. Security (b)log: Urgency & priority
    Good planning beats last-minute panic. Have you ordered your Christmas gifts yet?
    #shiftleft

    News from the big bad world: password managers research | ransomware for phones | tax' move to M365 still controversial | more
    securityblogpatrick-english.bl

  14. Security (b)log: Urgentie en prioriteit
    Goed plannen is beter dan achteraf haast hebben. Heb jij al alle kerstcadeaus besteld?
    #shiftleft

    GBBW: onderzoek password managers | ransomware op telefoon | overstap Belastingdienst naar M365 nog steeds controversieel | meer
    securityblogpatrick.blogspot.c

  15. ✈️ Welcoming Amadeus as officially listed on Microcks' public adopter list!

    Amadeus leverages Microcks to strengthen its shift-left strategy for mocking and contract testing. Among their use cases are using Microcks to mock OIDC, helping enforce and automate zero-trust policies while supporting their migration to the public cloud. It is an inspiring example of how API simulation can drive both security and agility.

    #OpenSource #ShiftLeft #ZeroTrust #CloudNative #Community

  16. ✈️ Welcoming Amadeus as officially listed on Microcks' public adopter list!

    Amadeus leverages Microcks to strengthen its shift-left strategy for mocking and contract testing. Among their use cases are using Microcks to mock OIDC, helping enforce and automate zero-trust policies while supporting their migration to the public cloud. It is an inspiring example of how API simulation can drive both security and agility.

    #OpenSource #ShiftLeft #ZeroTrust #CloudNative #Community

  17. Co v IT oboru znamená #ShiftLeft ?

    Vysvětlím.
    HR oddělení šetří peníze a tak se jim nehlásí žádní kvalitní testeři či #security experti. Jenže ten požadavek na zabezpečení se nějak vyřešit musí. No a tak vznikl #buzzword Shit left. Prostě to udělá vývojář a ostatní jen budou hledat co ještě by vývojář mohl dělat.

    Jednou se zase vrátí termín #FullStack developer, bude drahej a přetíženej a tak znova přijde Shift Left.

    Manažeři přeci musí vykazovat nějakou čínnost...

    #ZmrdiVohnoutiAMy

  18. Co v IT oboru znamená #ShiftLeft ?

    Vysvětlím.
    HR oddělení šetří peníze a tak se jim nehlásí žádní kvalitní testeři či #security experti. Jenže ten požadavek na zabezpečení se nějak vyřešit musí. No a tak vznikl #buzzword Shit left. Prostě to udělá vývojář a ostatní jen budou hledat co ještě by vývojář mohl dělat.

    Jednou se zase vrátí termín #FullStack developer, bude drahej a přetíženej a tak znova přijde Shift Left.

    Manažeři přeci musí vykazovat nějakou čínnost...

    #ZmrdiVohnoutiAMy

  19. Пострелизная валидация данных как новый вид тестирования?

    Что делать если шаткие предположения о логике работы легаси проектов используют как фундамент для новой логики? Как обезопасить легаси проект от рисков, которые не может покрыть стандартное тестирование? Как все это сделать быстро и дешево? И при чем тут, возможно, новый вид тестирования?

    habr.com/ru/articles/963860/

    #тестирование_по #теория_тестирования #тестирование_данных #data_validation #shiftleft

  20. От Jest к Vitest на backend тестах: как мы мигрировали тестовый фреймворк для ускорения CI и повышения стабильности

    Привет! Я Максим Кузьмин, старший инженер по автоматизации в команде Т-Путешествий. Строю и развиваю процессы автоматизации и разрабатываю инструменты тестирования. Для внутренних нужд мы разработали фреймворк для изолированного тестирования бэкенда. Он написан на TypeScript, обеспечивает гибкость, масштабируемость и интеграцию с разными внутренними системами. Выступает как единое решение для написания, запуска и поддержки тестов в стабильной и предсказуемой среде. В статье будет история миграции с Jest на Vitest. Расскажу, какие проблемы подтолкнули нас к переходу, как мы адаптировали окружение и какие результаты получили. Поделюсь опытом улучшения скорости запуска тестов и стабильности результатов. Надеюсь, что наш опыт поможет кому-то превратить автотесты из источника проблем в устойчивый инструмент контроля качества.

    habr.com/ru/companies/tbank/ar

    #тестирование #backend #qa_automation #автоматизация_тестирования #javascript #typescript #shiftleft #улучшение_процессов #quality_assurance #process_improvement

  21. Внедрение автоматизированного AppSec конвейера за пару дней без смс и регистрации

    Работоспособность любого приложения может быть подвержена угрозам: от сбоев в работе до кражи персональных данных. С этими рисками следует работать через регулярные и комплексные проверки кода на уязвимости, которые должны быть полностью автоматизированными. Несмотря на то, что тема актуальная, в интернете до сих пор сложно найти практические примеры, которые бы позволили построить независимый конвейер, не привязанный к системе контроля версий. Меня зовут Алексей Исламов, я администратор СИБ в Точка Банк. В статье предлагаю готовый вариант реализации такой системы из open‑source инструментов, которым может воспользоваться каждый.

    habr.com/ru/companies/tochka/a

    #appsec #devsecops #shiftleft #opensourse

  22. Portable tests run anywhere, not just in QA. @spoole167 makes the case for shared test ownership—without slowing devs down. His model weighs runtime, flakiness & bug yield. Want faster feedback loops?

    Read: javapro.io/2025/08/20/a-10x-ap

    @EclipseFdn #ShiftLeft #SoftwareTesting #Java

  23. Portable tests run anywhere, not just in QA. @spoole167 makes the case for shared test ownership—without slowing devs down. His model weighs runtime, flakiness & bug yield. Want faster feedback loops?

    Read: javapro.io/2025/08/20/a-10x-ap

    @EclipseFdn #ShiftLeft #SoftwareTesting #Java

  24. Как ускорить свою доставку и прокачать этим бизнес и команду

    🚀 Как перестать бояться релизов и начать жить: практический гайд для тимлидов Сбор практик для тех, кто хочет сделать доставку кода не болью, а удовольствием Знакомая ситуация? Ваши релизы похожи на прыжок с парашютом без парашюта? Команда нервничает при каждом деплое, а бизнес теряет деньги из-за медленной доставки фич? Эта статья для вас. Актуальность статьи: в современном мире скорость доставки фич — это не просто модный тренд, а вопрос выживания на рынке. Компании с быстрой доставкой обгоняют конкурентов по доходам на 20–40%. Цель исследования — показать, как технические и управленческие практики влияют на ключевые бизнес-метрики и уровень счастья команды. Мы делимся реальным опытом из агротех-разработки. Методология основана на практическом применении DevOps-практик и измерении результатов через метрики DORA. Мы покажем, как: Trunk-Based Development сокращает время доставки на 30% Feature Toggles делают релизы безопасными Left-shifting тестирование снижает время восстановления с 15–20 часов до 1 часа Kanban превращает хаос в прозрачную систему Основные результаты демонстрируют, что быстрые релизы = быстрые проверки гипотез, маленькие партии изменений = дешёвые ошибки, частые деплои = счастливая команда. P.S. Если вы всё ещё релизите раз в квартал — эта статья поможет вам пересмотреть свои подходы к разработке. 🎯

    habr.com/ru/articles/949288/

    #devops #enps #dora #tbd #shiftleft #kanban #vsm #приоритизация

  25. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Pushing Left, Like a Boss”
    📽️ twp.ai/4iporz

    #CyberSecurity #SecurityAwareness #appsec #shiftleft

  26. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Pushing Left, Like a Boss”
    📽️ twp.ai/4iporz

    #CyberSecurity #SecurityAwareness #appsec #shiftleft

  27. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Pushing Left, Like a Boss”
    📽️ twp.ai/4intEp

    #CyberSecurity #SecurityAwareness #appsec #shiftleft

  28. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Pushing Left, Like a Boss”
    📽️ twp.ai/4intEp

    #CyberSecurity #SecurityAwareness #appsec #shiftleft

  29. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Pushing Left, Like a Boss”
    📽️ twp.ai/4in9rw

    #CyberSecurity #SecurityAwareness #appsec #shiftleft

  30. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Pushing Left, Like a Boss”
    📽️ twp.ai/4in9rw

    #CyberSecurity #SecurityAwareness #appsec #shiftleft

  31. 🎙️ When AI writes code, builds models, and simulates threats… who checks the checker?

    In this last On Location Conversation from #RSAC2025, Alex Kreilein and John Sapp Jr. join Sean Martin, CISSP to explore what trust actually means in the age of AI-generated security tooling — and how modern #AppSec teams must rethink validation, #resiliency, and #risk.

    This episode cuts deep into:

    Why “trust the output” is not enough in AI-driven workflows
    How #AI security debt is becoming the new tech debt
    Why we need #zerotrust thinking applied to models and agents
    The real shift: from patching CVEs to building resilient architecture
    The role of traceability, governance, and context-driven decision-making

    If you’re serious about secure AI, application security, and shifting AppSec left (the right way), this conversation will challenge what you think you know — and help reframe what secure development actually looks like.

    🎥 Watch the full video:
    👉 youtu.be/kJdQz9LmT6s

    🎧 Listen to the audio podcast:
    👉 eventcoveragepodcast.com/episo

    ✨ Thank you to our Full Coverage Sponsors:
    ThreatLocker 👉 itspm.ag/threatlocker-r974
    Akamai Technologies 👉 itspm.ag/akamailbwc
    BLACKCLOAK 👉 itspm.ag/itspbcweb
    SandboxAQ 👉 itspm.ag/sandboxaq-j2en
    Archer Integrated Risk Management 👉 itspm.ag/rsaarchweb
    ISACA 👉 itspm.ag/isaca-96808
    Object First 👉 itspm.ag/object-first-2gjl
    Edera 👉 itspm.ag/edera-434868

    🎙️ Explore more RSAC 2025 coverage:
    👉 itspmagazine.com/rsa-conferenc

    🎧 Catch all of our event conversations:
    👉 itspmagazine.com/technology-an

    🎤 Want to tell your Brand Story Briefing as part of our coverage?
    👉 itspm.ag/evtcovbrf

    📆 Want Sean Martin, CISSP and Marco Ciappelli to cover your event or moderate your panel?
    👉 itspmagazine.com/contact-us

    #RSAC2025 #cybersecurity #AppSec #AIsecurity #zerotrust #infosec #securityleadership #riskmanagement #technology #eventcoverage #secureAI #shiftleft #CISO

  32. 🎙️ When AI writes code, builds models, and simulates threats… who checks the checker?

    In this last On Location Conversation from #RSAC2025, Alex Kreilein and John Sapp Jr. join Sean Martin, CISSP to explore what trust actually means in the age of AI-generated security tooling — and how modern #AppSec teams must rethink validation, #resiliency, and #risk.

    This episode cuts deep into:

    Why “trust the output” is not enough in AI-driven workflows
    How #AI security debt is becoming the new tech debt
    Why we need #zerotrust thinking applied to models and agents
    The real shift: from patching CVEs to building resilient architecture
    The role of traceability, governance, and context-driven decision-making

    If you’re serious about secure AI, application security, and shifting AppSec left (the right way), this conversation will challenge what you think you know — and help reframe what secure development actually looks like.

    🎥 Watch the full video:
    👉 youtu.be/kJdQz9LmT6s

    🎧 Listen to the audio podcast:
    👉 eventcoveragepodcast.com/episo

    ✨ Thank you to our Full Coverage Sponsors:
    ThreatLocker 👉 itspm.ag/threatlocker-r974
    Akamai Technologies 👉 itspm.ag/akamailbwc
    BLACKCLOAK 👉 itspm.ag/itspbcweb
    SandboxAQ 👉 itspm.ag/sandboxaq-j2en
    Archer Integrated Risk Management 👉 itspm.ag/rsaarchweb
    ISACA 👉 itspm.ag/isaca-96808
    Object First 👉 itspm.ag/object-first-2gjl
    Edera 👉 itspm.ag/edera-434868

    🎙️ Explore more RSAC 2025 coverage:
    👉 itspmagazine.com/rsa-conferenc

    🎧 Catch all of our event conversations:
    👉 itspmagazine.com/technology-an

    🎤 Want to tell your Brand Story Briefing as part of our coverage?
    👉 itspm.ag/evtcovbrf

    📆 Want Sean Martin, CISSP and Marco Ciappelli to cover your event or moderate your panel?
    👉 itspmagazine.com/contact-us

    #RSAC2025 #cybersecurity #AppSec #AIsecurity #zerotrust #infosec #securityleadership #riskmanagement #technology #eventcoverage #secureAI #shiftleft #CISO

  33. Keynote von Martin Haunschmid: Security ist so schlimm wie vor 20 Jahren
    Die Keynote von Martin Haunschmid zeigt drastisch, wie wichtig es ist, Cybersecurity frühzeitig in der Entwicklung zu berücksichtigen.
    se-trends.de/keynote-martin-ha
    #Anforderungen #Veranstaltungen #Angriffssicherheit #DSGVO #MartinHaunschmid #OWASP #ReConf #ShiftLeft #ThreatModel

  34. Shifting Left isn’t just a buzzword - it’s the foundation for efficiency in your organization!

    By making clean, reliable, and accessible data available across your organization, you reduce complexity and unlock time to focus on higher-value work.

    💡 Data products are the foundation of this #ShiftLeft, enabling healthy, scalable data communication.

    📖 Dive into the details in the #InfoQ article: bit.ly/3WHjxsf

    #SoftwareArchitecture #DataMesh #DataLake #DataPipelines #ETL

  35. Shifting Left isn’t just a buzzword - it’s the foundation for efficiency in your organization!

    By making clean, reliable, and accessible data available across your organization, you reduce complexity and unlock time to focus on higher-value work.

    💡 Data products are the foundation of this , enabling healthy, scalable data communication.

    📖 Dive into the details in the article: bit.ly/3WHjxsf

  36. A approach to relies on data products, which form the basis of data communication across the business.

    This addresses many flaws in traditional data processing and makes data more relevant, complete, and trustworthy.

    article: bit.ly/3WHjxsf

  37. Testing should shift left! But what if we’ve been thinking about it all wrong? What if the answer isn’t "earlier" but "smarter"? A 10x perspective on QA that might change how you see testing forever. Read Steve Pool: javapro.io/2025/01/27/thinking

    #SoftwareTesting #Java #DevOps #ShiftLeft #QualityAssurance #JAVAPRO #DevOps

  38. Me: Alright, everyone from the C-suite down is excited about this whole shit-left business, so the CI system is going to flag any changes you make that increase the number of warnings. The idea is that we don’t let it get to be overwhelming and start having real issues pop up from easily preventable stuff.
    Team lead: hey, I’m gonna need to turn that off. It’s slowing us down too much to evaluate whether each of these warnings is worth investigating.
    Me: So, you want to wait until we have a time-critical release and Release Engineering is screaming about being overdue to go through the whole backlog?
    Them: Well, no, I wouldn’t put it that way.
    Me: So, you’re going to schedule regular issue pruning in the HIP sprints?
    Them: *looking uncomfortable* Maybe? We were hoping to use those to catch up on other stuff.
    #ShiftLeft #DevOps

  39. Geht das zusammen? 3 Strategien für Cybersecurity und agiles Systems Engineering
    In diesem Artikel werden 3 Strategien vorgestellt, um Cybersecurity und agiles Systems Engineering zusammenzubringen.
    se-trends.de/3-strategien-fuer
    #Agilitt #Wissen #Angriffssicherheit #Cybersecurity #DevSecOps #ShiftLeft #ZeroTrust

  40. In this week's #ITOps Query #podcast, Adrian Sanabria and I discuss the recent #CISA report that raised doubts about the basis for #shiftleft and #securebydesign movements in #devsecops, and where the industry goes from here. itopsquery.podbean.com/e/quest

  41. It’s Time To Start Shifting Left

    thenewstack.io/its-time-to-sta

    "Companies need to incorporate quality into their product development process from the start." -- #JuanRodriguez

    #api360 #sdlc #shiftLeft

  42. A DevOps Concept: #ShiftLeft

    The practice of employing techniques to ensure the readiness of code before it hits production environments.

    For example: Teams may add #Loadtesting of their code in their deployment pipeline. #Scrum teams might add this to their Definition of Done.