Sign in

BellSoft

@bellsoft.bsky.social
137 followers 16 following 642 posts

Delivering #LibericaJDK: supported, #Java standard compatible binaries. Among Top-5 #OpenJDK contributors.

PostsRepliesMedia
BellSoft @bellsoft.bsky.social · 8h
🎙 @asm0dey.site joined Allyson Klein on the podcast with one number from our Spring I/O survey: 64% had never considered whether a Dockerfile affects security. From there, the conversation lands on a much more uncomfortable metric: time from public disclosure to a patched production stack. Listen:
techarena.ai
BellSoft's Pasha Finkelshteyn on Dockerfile Security Risks
Pasha Finkelshteyn of BellSoft discusses production blind spots, CVE patch windows and the EU Cyber Resilience Act deadline.
010
BellSoft @bellsoft.bsky.social · 29/09/2026
We’re live! 💥 JRush Episode 8 has started. Tune in for real-world stories about AI in Java development: legacy modernization, AI agent workflows, and building a coding process you can trust. Watch live: www.youtube.com/watch?v=nw6C...
youtube.com
000
BellSoft @bellsoft.bsky.social · 28/09/2026
JEP 540 brings a simple JSON API to JDK 28 as an incubator module. The jdk.incubator.json module provides a small API for parsing, navigating, and generating JSON. No data binding or streaming APIs. It stays focused on straightforward JSON processing.
010
BellSoft @bellsoft.bsky.social · 28/09/2026
A lot of AI experiments never make it past the demo stage. Let’s talk about the ones that do. JRush Episode 8 · Sep 29: jrush.bell-sw.com/episode8
000
BellSoft @bellsoft.bsky.social · 28/09/2026
Planning your move to Spring Boot 4? Preview the work before you start. @edelveis.dev takes a demo app from 3.5 to 4.1, with practical fixes and before-and-after code to guide your upgrade. bell-sw.com/blog/how-to-...
bell-sw.com
How to Migrate to Spring Boot 4: Step-by-Step Guide
Learn how to migrate a Spring Boot 3.5 project to Spring Boot 4, including modular starters, Jackson 3, testing changes, deprecated APIs, and migration verification.
011
BellSoft @bellsoft.bsky.social · 26/09/2026
20 prompts later and you’re still trying to get AI to write the code you had in mind. @asm0dey.site spent months trying different approaches, moving from endless prompt tweaking to a workflow he uses today. He’ll share what changed in his JRush talk on September 29: jrush.bell-sw.com/episode8
020
BellSoft @bellsoft.bsky.social · 25/09/2026
One operation, 500 SQL queries. Would you spot it before production? @edelveis.dev shows how to catch N+1 queries in your logs and fix them without changing your service logic. Watch the Spring Data JPA crash course: youtu.be/jY0mmMcMwCA
032
BellSoft @bellsoft.bsky.social · 22/09/2026
You added AI to move faster. So why are you spending your time fixing its code? @edelveis.dev introduces JRush Episode 8 and Simon Martinelli’s talk on AI-driven modernization in enterprise #Java projects. Full details and registration: jrush.bell-sw.com/episode8
011
BellSoft @bellsoft.bsky.social · 22/09/2026
Every unnecessary rebuild adds time to a security update. Dmitry Chuyko writes in SD Times about cutting repeated work from CVE patching, especially when the same dependency runs across dozens of apps. sdtimes.com/security/ret...
sdtimes.com
Rethinking Application Updates: Solutions for Faster, More Efficient CVE Patching
It’s one thing to know about CVEs that affect your business’s applications. It’s quite another, however, to go about fixing CVEs quickly.
000
BellSoft @bellsoft.bsky.social · 21/09/2026
Martin Ladecký’s Spring I/O talk covers secret hygiene for Java and cloud-native systems, including credentials that can survive in Docker layers and build history. Liberica JDK gets a high five for zero CVEs too. Thanks, Martin ✋ Full talk: www.youtube.com/watch?v=RDqU...
youtube.com
The Complete Guide to Secret Hygiene for Java and Cloud-Native Engineers by Martin Ladecký @SpringIO
YouTube video by Spring I/O
000
BellSoft @bellsoft.bsky.social · 21/09/2026
Pasha Finkelshteyn (@asm0dey.site) went through a few AI coding setups before finding one he could trust. At JRush Episode 8, he’ll show the approaches he tested, the one he kept, and the changes that made AI-generated code fit into his own development standards: jrush.bell-sw.com/episode8
100
BellSoft @bellsoft.bsky.social · 18/09/2026
Baruch Sadogursky built a software factory with AI agents that shipped a real MVP in three days. 💥 The setup brought together rival coding agents, shared context, and review gates to see what happens when AI agents work as a team. Bring your AI questions to the live session:
jrush.bell-sw.com
JRush Episode 8: Java in the Age of AI
AI works in the demo, then falls apart on real code. Three practitioners show what actually works. Live, free, Sept 29. Register now.
000
BellSoft @bellsoft.bsky.social · 18/09/2026
Rebase can save you from repeatedly pulling the same gigabytes. A base-image patch doesn't always need a full rebuild. Dmitry Chuyko and @edelveis.dev wrote up where Docker and Buildpacks stand on it: bell-sw.com/blog/rebuild...
bell-sw.com
Rebuild vs Rebase Container Images: Docker and Buildpacks
Learn when to rebuild or rebase container images, how Docker Buildx and Buildpacks handle cache and rebasing, and why unchanged layer digests can reduce Kubernetes image pulls.
011
BellSoft @bellsoft.bsky.social · 17/09/2026
Sometimes, you end up being responsible for vulnerable code you didn't even write. A vulnerable JDK. A compromised package. An outdated base image. Third-party components become part of your product the moment they are shipped with it.
120
BellSoft @bellsoft.bsky.social · 16/09/2026
Simon Martinelli has spent the last two years applying AI to large #Java systems. At JRush Episode 8, he’ll share lessons from real modernization work: the approaches that helped, the ones that had to be dropped, and the places where AI still needs a careful human hand: jrush.bell-sw.com/episode8
010
BellSoft @bellsoft.bsky.social · 16/09/2026
Liberica JDK 27 is out. 🚀 9 JEPs in this release: G1 as the default GC everywhere, post-quantum hybrid key exchange for TLS 1.3, compact object headers by default, JFR data redaction, and more. Plus 2,542 fixes across JDK and JavaFX. Details and downloads: bell-sw.com/blog/liberic...
bell-sw.com
Liberica JDK 27 builds are generally available
Find out about the improvements in JDK 27 and downloads the new builds
010
BellSoft @bellsoft.bsky.social · 15/09/2026
A critical CVE lands in your product. Do you need to report it within 24 hours under the CRA? Not necessarily. 🔽
100
BellSoft @bellsoft.bsky.social · 15/09/2026
After years of Project Valhalla work, value objects are coming to JDK 28 as a preview feature. JEP 401 introduces objects without identity. For value objects, == compares their values instead of object identity.
100
BellSoft @bellsoft.bsky.social · 14/09/2026
AI is moving from experiments into real Java projects. But what happens when it hits legacy systems, production constraints, and teams that need predictable results?
jrush.bell-sw.com
JRush Episode 8: Java in the Age of AI
AI works in the demo, then falls apart on real code. Three practitioners show what actually works. Live, free, Sept 29. Register now.
100
BellSoft @bellsoft.bsky.social · 14/09/2026
September 11 has passed. If a reportable event showed up tomorrow, would your team know what to do? If you had to think about it, we pulled the reporting process into a six-page cheat sheet for EU Cyber Resilience Act reporting.
100
BellSoft @bellsoft.bsky.social · 11/09/2026
Selling software in the EU? Today the rules changed. Article 14 of the Cyber Resilience Act is now in force, and for manufacturers that means a new reporting obligation with a first deadline of just 24 hours. What actually needs to be reported? Who is responsible? Watch here: youtu.be/IQkzg7quc58
000
BellSoft @bellsoft.bsky.social · 11/09/2026
CRA reporting starts today. As of September 11, the first reporting obligations under the Cyber Resilience Act are in effect, and ENISA's Single Reporting Platform is now live.
100
BellSoft @bellsoft.bsky.social · 10/09/2026
Who actually needs to care about the CRA? If your company puts software or hardware on the EU market under its own name, September 11 is a date worth knowing about.
100
BellSoft @bellsoft.bsky.social · 09/09/2026
Java 27 is almost here, and JEP 536 adds in-process redaction to JFR. JFR can now redact command-line arguments, initial values of environment variables, and system properties before they reach the recording. Default filters cover common sensitive names such as passwords and tokens.
000
BellSoft @bellsoft.bsky.social · 08/09/2026
Is your software sold in the EU? September 11 may change how you handle security incidents. 🔽
100
BellSoft @bellsoft.bsky.social · 08/09/2026
Working on Java cold starts? Watch this before you spend a day benchmarking everything in sight. @edelveis.dev goes through AppCDS, AOT Cache, Native Image, and CRaC with one goal: figuring out what is worth trying first for your workload. youtu.be/RLuknIY2rUo
010
BellSoft @bellsoft.bsky.social · 03/09/2026
Missed Catherine Edelveis and DaShaun Carter last week? They discussed hardened builders, buildpacks, and container security. The full recording is absolutely worth catching up on. Watch here: youtu.be/3ElGTo5hlzE
youtu.be
How Do You Know It’s Hardened? Anatomy of a Hardened Builder
YouTube video by CyberJAR
000
BellSoft @bellsoft.bsky.social · 02/09/2026
Why are hardened images getting so much attention again? TechTarget connects the dots between supply chain risk, compliance, vulnerability management, and the cost of bloated base images: www.techtarget.com/it-infrastru...
000
BellSoft @bellsoft.bsky.social · 01/09/2026
Java 27 goes GA on September 15. JEP 537 re-incubates Vector API for the twelfth time without substantial changes.
100
BellSoft @bellsoft.bsky.social · 31/08/2026
A package approved today might not be the same package you can trust six months later. Maintainers change. Build systems change. New risks appear. This episode looks at how to keep dependencies under control from adoption to production: youtu.be/5CzDhaG1oEg
010
BellSoft @bellsoft.bsky.social · 28/08/2026
We’re live with Catherine Edelveis and DaShaun Carter! Today’s question: what really makes a container image hardened? They’re digging into buildpacks, container security, and the design choices behind BellSoft Hardened Builder for Paketo Buildpacks. Join us: youtu.be/3ElGTo5hlzE
youtu.be
How Do You Know It’s Hardened? Anatomy of a Hardened Builder
YouTube video by CyberJAR
000
BellSoft @bellsoft.bsky.social · 26/08/2026
Compact Object Headers will be enabled by default in JDK 27. Every Java object has a header. For workloads creating large numbers of small objects, that could mean increased memory overhead.
110
BellSoft @bellsoft.bsky.social · 26/08/2026
35 years ago, Linux started as a small hobby project. Today, it runs everything from laptops to clouds, servers, containers, and much of the infrastructure we rely on every day. Happy 35th birthday! 🍰
131
BellSoft @bellsoft.bsky.social · 25/08/2026
What makes a builder for buildpacks hardened? This Friday, @edelveis.dev joins @dashaun.com on Coffee + Software to talk through buildpacks, container security, and what goes into BellSoft Hardened Builder for Paketo Buildpacks. Set a reminder so you don’t miss it: youtu.be/3ElGTo5hlzE
youtu.be
How Do You Know It’s Hardened? Anatomy of a Hardened Builder
YouTube video by CyberJAR
021
BellSoft @bellsoft.bsky.social · 24/08/2026
What has to be true before an open-source dependency is allowed into production? A clean CVE scan is one answer. A signature is another. Neither is the whole answer. @edelveis.dev breaks down what other evidence is worth checking: youtu.be/Z5jJQz1YM3U
youtu.be
How to Apply Zero Trust to Open Source Dependencies
YouTube video by CyberJAR
000
BellSoft @bellsoft.bsky.social · 19/08/2026
The August Liberica JDK CSPU builds are available for JDK 6, 7, 8, 11, 17, 21, 25, and 26. The release addresses 4 CVEs and includes 29 fixes overall, with BellSoft contributing to 11 resolved issues. Full security summary: bell-sw.com/blog/liberic...
bell-sw.com
Liberica JDK CSPU builds are released
Download Liberica JDK CSPU versions 6, 7, 8, 11, 17, 21, 25 and 26 with improved security.
012
BellSoft @bellsoft.bsky.social · 19/08/2026
Yesterday, @edelveis.dev joined Josh Long on Coffee + Software to talk buildpacks, hardened images, and container security. They also got into BellSoft Hardened Builder for Paketo Buildpacks and why buildpacks are becoming relevant to security conversations, not just build automation.
youtube.com
BellSoft's Catherine Edelveis
YouTube video by Coffee + Software
030
BellSoft @bellsoft.bsky.social · 18/08/2026
@asm0dey.site discovered Docker Bake during JRush and immediately saw where it fit into his own builds. Bake defines multiple image targets in one HCL file and runs them together. One practical find from an episode full of ideas for safer build pipelines: www.youtube.com/live/AsGmInC...
000
BellSoft @bellsoft.bsky.social · 17/08/2026
Two service calls run in parallel. If one fails, the other should not keep doing useless work. JEP 533 in #Java27 re-previews Structured Concurrency: default StructuredTaskScope cancels unfinished subtasks on failure, and join() reports it as ExecutionException. Seventh preview.
000
BellSoft @bellsoft.bsky.social · 13/08/2026
Already using slim or distroless images? Then this is where things get interesting: what still separates a smaller image from one you can verify, patch, and enforce in production. @edelveis.dev shows what to look for and where hardened images fit into a real security pipeline: youtu.be/YYw8hmYuoUs
youtu.be
Hardened vs Distroless vs Slim: What's the Real Difference?
YouTube video by CyberJAR
010
BellSoft @bellsoft.bsky.social · 10/08/2026
Artifact signing is one question. JRush Episode 7 goes much further: SBOMs, provenance, buildpacks, hardened images, CVE response, and the practical trade-offs between them. Plenty to take back to your pipeline. Episode: www.youtube.com/live/AsGmInC... Checklist: jrush.bell-sw.com/container-se...
020
BellSoft @bellsoft.bsky.social · 06/08/2026
JEP 538 brings the PEM API back for a third preview in #Java27. PEMEncoder encodes keys, certificates, and CRLs as PEM. PEMDecoder reads them back into typed Java objects, without manual Base64 handling, header parsing, or KeyFactory setup.
020
BellSoft @bellsoft.bsky.social · 04/08/2026
September 2026 is almost here, and Oracle JDK 21 users have a decision to make. Updates released after that point are planned to move from NFTC to OTN. Your applications will keep running, but keeping them securely updated may no longer be free. 🧵
110
BellSoft @bellsoft.bsky.social · 03/08/2026
Alpine or not? Small size is the easy part of the answer. This video gets into everything that can change it once the image meets a real workload. youtu.be/37tnF-THIkE
020
BellSoft @bellsoft.bsky.social · 31/07/2026
Hardened images remove the package manager, curl, and other handy tools. Great for the attack surface. Less great when production breaks. JRush Episode 7 gets into that trade-off and plenty more around signing, SBOMs, provenance, buildpacks, and CVE response: www.youtube.com/live/AsGmInC...
000
BellSoft @bellsoft.bsky.social · 30/07/2026
Buildpacks remove a lot of repetitive containerization work, but they also trade some control for automation. @edelveis.dev breaks down that trade-off in seven minutes, including where a Dockerfile still makes more sense: youtu.be/19ZDEvnjtDI
071
BellSoft @bellsoft.bsky.social · 29/07/2026
JEP 532 in #Java27 brings exact conversion checks to primitive patterns in switch and instanceof. A pattern matches only when the value can be converted without losing information. No manual range checks or lossy casts. Fifth preview.
021
BellSoft @bellsoft.bsky.social · 28/07/2026
CyberJAR is now in the Foojay Java in Education Catalog. A useful collection of Java courses, videos, books, and tools, now including our channel: education.foojay.social
education.foojay.social
Foojay Java in Education Catalog
A community-driven catalog of Java learning resources with websites, tutorials, videos, books, and tools for students, educators, coding clubs, and developers.
000
BellSoft @bellsoft.bsky.social · 27/07/2026
There is no Ubuntu OS inside an Ubuntu container. A container is an isolated process running on the host kernel, where memory, CPU, PIDs, mounts, and permissions are enforced. @edelveis.dev breaks it down: bell-sw.com/blog/linux-i...
bell-sw.com
Linux in Containers vs. Linux OS
Learn why a Linux container is not a full Linux operating system. Understand how Docker containers share the host kernel, use OS libraries, and where compatibility problems arise.
001
BellSoft @bellsoft.bsky.social · 24/07/2026
Built on BellSoft Hardened Images, our hardened builder for Paketo gives Java, Native Image, Python, Go, Node.js, and Ruby teams secure-by-design low-to-zero-CVE base images at release time. The new guide covers adoption from buildpacks or Dockerfiles: bell-sw.com/blog/bellsof...
bell-sw.com
How to Improve the Security of container Images with BellSoft's Hardened Builder for Paketo Buildpacks
BellSoft released a Hardened Builder for Paketo Buildpacks. Find out how it can help you improve the security of your containerized workloads.
010