Sign in

BellSoft

@bellsoft.bsky.social
141 followers 16 following 648 posts

Delivering #LibericaJDK: supported, #Java standard compatible binaries. Among Top-5 #OpenJDK contributors.

PostsRepliesMedia
BellSoft @bellsoft.bsky.social · 7h
Tomorrow at @devoxx.com: give your Java container images a security upgrade with @asm0dey.site. Join Mission Possible for practical Dockerfile changes and before/after scans. Oct 7 · 13:05–13:45 CEST · Room 3 See you there! m.devoxx.com/events/dvbe2...
m.devoxx.com
Mission Possible: The 45-Minute Path to Bullet-Proof Java Container Images - Devoxx Belgium 2026
By Pasha Finkelshtein. A lunch session on hardening Java container images by reducing CVE noise and operational risk. It covers choosing minimal base images, shrinking privileges, pinning versions, si...
010
BellSoft @bellsoft.bsky.social · 05/10/2026
Virtual threads work well for tasks that spend much of their time waiting. A shared Semaphore limits concurrent calls to a downstream service: each task gets its own virtual thread, and up to 10 tasks can enter the protected API at once. Java 21+.
010
BellSoft @bellsoft.bsky.social · 02/10/2026
Some buildpacks work outside the vendor’s platform, but their support contracts stop at the door. @edelveis.dev compares eight offerings and the details worth checking before you choose: bell-sw.com/blog/buildpa...
bell-sw.com
Buildpacks Comparison: CNB, Base OS, Security & Support
Compare Buildpacks and Cloud Native Buildpacks from Paketo, Heroku, Google, Tanzu, BellSoft, Cloud Foundry, Red Hat, and SAP by languages, base OS, security, and support.
020
BellSoft @bellsoft.bsky.social · 02/10/2026
Calling reversed() on an ArrayList does not create a copy. It returns a live reverse-ordered view backed by the original list. Change the view and the original changes too. If you need an independent mutable list in reverse order, create a new ArrayList from the reversed view. Java 21+.
000
BellSoft @bellsoft.bsky.social · 01/10/2026
Thanks to everyone who joined JRush Episode 8 live! 💙 We talked about the parts of AI development that don’t fit into a demo: trusting generated code, working with real Java systems, and figuring out where AI helps. Missed the session? The recording is now available:
youtube.com
JRush Ep 8 - Java in the Age of AI
YouTube video by CyberJAR
010
BellSoft @bellsoft.bsky.social · 01/10/2026
Gatherers.mapConcurrent() runs stream transformations concurrently on virtual threads, limiting concurrency and preserving stream order. In this example, up to four blocking product lookups can run concurrently, and the resulting list follows the order of the original IDs. Java 24+.
000
BellSoft @bellsoft.bsky.social · 30/09/2026
🎙 @asm0dey.site joined Allyson Klein on the podcast with one number from our Spring I/O survey: 64% had never considered whether a Dockerfile affects security. From there, the conversation lands on a much more uncomfortable metric: time from public disclosure to a patched production stack. Listen:
techarena.ai
BellSoft's Pasha Finkelshteyn on Dockerfile Security Risks
Pasha Finkelshteyn of BellSoft discusses production blind spots, CVE patch windows and the EU Cyber Resilience Act deadline.
010
BellSoft @bellsoft.bsky.social · 29/09/2026
We’re live! 💥 JRush Episode 8 has started. Tune in for real-world stories about AI in Java development: legacy modernization, AI agent workflows, and building a coding process you can trust. Watch live: www.youtube.com/watch?v=nw6C...
youtube.com
000
BellSoft @bellsoft.bsky.social · 28/09/2026
JEP 540 brings a simple JSON API to JDK 28 as an incubator module. The jdk.incubator.json module provides a small API for parsing, navigating, and generating JSON. No data binding or streaming APIs. It stays focused on straightforward JSON processing.
010
BellSoft @bellsoft.bsky.social · 28/09/2026
A lot of AI experiments never make it past the demo stage. Let’s talk about the ones that do. JRush Episode 8 · Sep 29: jrush.bell-sw.com/episode8
000
BellSoft @bellsoft.bsky.social · 28/09/2026
Planning your move to Spring Boot 4? Preview the work before you start. @edelveis.dev takes a demo app from 3.5 to 4.1, with practical fixes and before-and-after code to guide your upgrade. bell-sw.com/blog/how-to-...
bell-sw.com
How to Migrate to Spring Boot 4: Step-by-Step Guide
Learn how to migrate a Spring Boot 3.5 project to Spring Boot 4, including modular starters, Jackson 3, testing changes, deprecated APIs, and migration verification.
012
BellSoft @bellsoft.bsky.social · 26/09/2026
20 prompts later and you’re still trying to get AI to write the code you had in mind. @asm0dey.site spent months trying different approaches, moving from endless prompt tweaking to a workflow he uses today. He’ll share what changed in his JRush talk on September 29: jrush.bell-sw.com/episode8
020
BellSoft @bellsoft.bsky.social · 25/09/2026
One operation, 500 SQL queries. Would you spot it before production? @edelveis.dev shows how to catch N+1 queries in your logs and fix them without changing your service logic. Watch the Spring Data JPA crash course: youtu.be/jY0mmMcMwCA
032
BellSoft @bellsoft.bsky.social · 22/09/2026
You added AI to move faster. So why are you spending your time fixing its code? @edelveis.dev introduces JRush Episode 8 and Simon Martinelli’s talk on AI-driven modernization in enterprise #Java projects. Full details and registration: jrush.bell-sw.com/episode8
011
BellSoft @bellsoft.bsky.social · 22/09/2026
Every unnecessary rebuild adds time to a security update. Dmitry Chuyko writes in SD Times about cutting repeated work from CVE patching, especially when the same dependency runs across dozens of apps. sdtimes.com/security/ret...
sdtimes.com
Rethinking Application Updates: Solutions for Faster, More Efficient CVE Patching
It’s one thing to know about CVEs that affect your business’s applications. It’s quite another, however, to go about fixing CVEs quickly.
000
BellSoft @bellsoft.bsky.social · 21/09/2026
Martin Ladecký’s Spring I/O talk covers secret hygiene for Java and cloud-native systems, including credentials that can survive in Docker layers and build history. Liberica JDK gets a high five for zero CVEs too. Thanks, Martin ✋ Full talk: www.youtube.com/watch?v=RDqU...
youtube.com
The Complete Guide to Secret Hygiene for Java and Cloud-Native Engineers by Martin Ladecký @SpringIO
YouTube video by Spring I/O
000
BellSoft @bellsoft.bsky.social · 21/09/2026
Pasha Finkelshteyn (@asm0dey.site) went through a few AI coding setups before finding one he could trust. At JRush Episode 8, he’ll show the approaches he tested, the one he kept, and the changes that made AI-generated code fit into his own development standards: jrush.bell-sw.com/episode8
100
BellSoft @bellsoft.bsky.social · 18/09/2026
Baruch Sadogursky built a software factory with AI agents that shipped a real MVP in three days. 💥 The setup brought together rival coding agents, shared context, and review gates to see what happens when AI agents work as a team. Bring your AI questions to the live session:
jrush.bell-sw.com
JRush Episode 8: Java in the Age of AI
AI works in the demo, then falls apart on real code. Three practitioners show what actually works. Live, free, Sept 29. Register now.
000
BellSoft @bellsoft.bsky.social · 18/09/2026
Rebase can save you from repeatedly pulling the same gigabytes. A base-image patch doesn't always need a full rebuild. Dmitry Chuyko and @edelveis.dev wrote up where Docker and Buildpacks stand on it: bell-sw.com/blog/rebuild...
bell-sw.com
Rebuild vs Rebase Container Images: Docker and Buildpacks
Learn when to rebuild or rebase container images, how Docker Buildx and Buildpacks handle cache and rebasing, and why unchanged layer digests can reduce Kubernetes image pulls.
011
BellSoft @bellsoft.bsky.social · 17/09/2026
You still need to determine if a vulnerability is exploitable in your product. But if it stems from the base image, you have complete data about base image contents and a defined remediation process from the image vendor. Learn more about BellSoft Hardened Images: bell-sw.com/bellsoft-har...
000
BellSoft @bellsoft.bsky.social · 17/09/2026
BellSoft Hardened Images can simplify this task for the base image layer. Each image comes with an SBOM, BellSoft continuously monitors the images for newly discovered CVEs, and commercial plans provide SLA-backed remediation.
100
BellSoft @bellsoft.bsky.social · 17/09/2026
Under the CRA, if an actively exploited vulnerability is in a third-party component integrated in your product, it can become your reporting responsibility if this vulnerability can be exploited in your product. This is why visibility into third-party components is important for timely response.
100
BellSoft @bellsoft.bsky.social · 17/09/2026
Sometimes, you end up being responsible for vulnerable code you didn't even write. A vulnerable JDK. A compromised package. An outdated base image. Third-party components become part of your product the moment they are shipped with it.
120
BellSoft @bellsoft.bsky.social · 16/09/2026
Simon Martinelli has spent the last two years applying AI to large #Java systems. At JRush Episode 8, he’ll share lessons from real modernization work: the approaches that helped, the ones that had to be dropped, and the places where AI still needs a careful human hand: jrush.bell-sw.com/episode8
010
BellSoft @bellsoft.bsky.social · 16/09/2026
Liberica JDK 27 is out. 🚀 9 JEPs in this release: G1 as the default GC everywhere, post-quantum hybrid key exchange for TLS 1.3, compact object headers by default, JFR data redaction, and more. Plus 2,542 fixes across JDK and JavaFX. Details and downloads: bell-sw.com/blog/liberic...
bell-sw.com
Liberica JDK 27 builds are generally available
Find out about the improvements in JDK 27 and downloads the new builds
010
BellSoft @bellsoft.bsky.social · 15/09/2026
So, severity alone does not decide whether a vulnerability has to be reported under Article 14. Evidence of actual malicious exploitation does. ENISA covers more reporting cases in its FAQ: www.enisa.europa.eu/topics/produ...
enisa.europa.eu
Frequently Asked Questions | ENISA
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
000
BellSoft @bellsoft.bsky.social · 15/09/2026
Severe security incidents are a separate reporting track. If an incident seriously affects, or could seriously affect, the security of the product, it needs to be reported.
100
BellSoft @bellsoft.bsky.social · 15/09/2026
A proof of concept with no evidence of malicious exploitation? No mandatory Article 14 vulnerability report. A zero-day found by a testing lab, but no evidence that anyone has exploited it? Same answer.
100
BellSoft @bellsoft.bsky.social · 15/09/2026
For manufacturers, a vulnerability becomes mandatorily reportable when there is reliable evidence that a malicious actor has actually exploited it. Severity alone does not trigger the reporting obligation.
100
BellSoft @bellsoft.bsky.social · 15/09/2026
A critical CVE lands in your product. Do you need to report it within 24 hours under the CRA? Not necessarily. 🔽
100
BellSoft @bellsoft.bsky.social · 15/09/2026
Two separately created ValuePoint instances with the same fields are indistinguishable, while regular objects still keep identity-based comparison. First preview.
000
BellSoft @bellsoft.bsky.social · 15/09/2026
After years of Project Valhalla work, value objects are coming to JDK 28 as a preview feature. JEP 401 introduces objects without identity. For value objects, == compares their values instead of object identity.
100
BellSoft @bellsoft.bsky.social · 14/09/2026
JRush Episode 8 brings three engineers sharing what they learned from using AI for modernization, coding workflows, and building with AI agents. Free live event · September 29 Register: jrush.bell-sw.com/episode8
001
BellSoft @bellsoft.bsky.social · 14/09/2026
AI is moving from experiments into real Java projects. But what happens when it hits legacy systems, production constraints, and teams that need predictable results?
jrush.bell-sw.com
JRush Episode 8: Java in the Age of AI
AI works in the demo, then falls apart on real code. Three practitioners show what actually works. Live, free, Sept 29. Register now.
100
BellSoft @bellsoft.bsky.social · 14/09/2026
There’s a checklist at the end for the things you don’t want to be figuring out under a 24-hour deadline: bell-sw.com/cra-reportin...
bell-sw.com
CRA Vulnerability & Incident Reporting: Step-by-Step Guide | BellSoft Java
Learn how to report vulnerabilities and incidents under EU CRA Article 14. Free cheat sheet covers scope, CSIRT selection, ENISA SRP, and 24/72-hour deadlines.
000
BellSoft @bellsoft.bsky.social · 14/09/2026
It starts with the prep work worth doing before anything happens, then follows the reporting flow through the 24-hour notification, the 72-hour update, user communication, and the final report.
100
BellSoft @bellsoft.bsky.social · 14/09/2026
September 11 has passed. If a reportable event showed up tomorrow, would your team know what to do? If you had to think about it, we pulled the reporting process into a six-page cheat sheet for EU Cyber Resilience Act reporting.
100
BellSoft @bellsoft.bsky.social · 11/09/2026
Selling software in the EU? Today the rules changed. Article 14 of the Cyber Resilience Act is now in force, and for manufacturers that means a new reporting obligation with a first deadline of just 24 hours. What actually needs to be reported? Who is responsible? Watch here: youtu.be/IQkzg7quc58
000
BellSoft @bellsoft.bsky.social · 11/09/2026
ENISA Single Reporting Platform: www.enisa.europa.eu/topics/produ...
enisa.europa.eu
Single Reporting Platform (SRP) | ENISA
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
001
BellSoft @bellsoft.bsky.social · 11/09/2026
The final deadline depends on what happened. For an actively exploited vulnerability, the final report is due within 14 days after a corrective measure becomes available. For a severe incident, it is due within one month after the 72-hour notification.
100
BellSoft @bellsoft.bsky.social · 11/09/2026
The reporting sequence has several deadlines to keep straight. An early warning is due within 24 hours of becoming aware of a reportable event, followed by a more detailed notification within 72 hours.
100
BellSoft @bellsoft.bsky.social · 11/09/2026
Manufacturers can use it to report actively exploited vulnerabilities and severe security incidents affecting products with digital elements on the EU market.
100
BellSoft @bellsoft.bsky.social · 11/09/2026
CRA reporting starts today. As of September 11, the first reporting obligations under the Cyber Resilience Act are in effect, and ENISA's Single Reporting Platform is now live.
100
BellSoft @bellsoft.bsky.social · 10/09/2026
So the useful question to ask now is pretty simple: what role does your company have in the products it makes available in the EU? More details in the ENISA CRA Single Reporting Platform FAQ: www.enisa.europa.eu/topics/produ...
enisa.europa.eu
Frequently Asked Questions | ENISA
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
000
BellSoft @bellsoft.bsky.social · 10/09/2026
The distinction matters because the CRA places reporting responsibilities on these roles, while ordinary open-source contributors are generally outside its scope.
100
BellSoft @bellsoft.bsky.social · 10/09/2026
A developer who simply contributes code to an open-source project generally does not fall into this category.
100
BellSoft @bellsoft.bsky.social · 10/09/2026
Then there are open-source software stewards. This category covers legal entities that systematically and sustainably support the development of open-source software intended for commercial activity and play a main role in ensuring its viability.
110
BellSoft @bellsoft.bsky.social · 10/09/2026
That could be a company selling its own application, an operating system vendor, or a manufacturer putting a connected device on the market with its own software.
100
BellSoft @bellsoft.bsky.social · 10/09/2026
A manufacturer is a company or individual that develops a product, or has it developed, and makes it available on the EU market under its own name or trademark.
100
BellSoft @bellsoft.bsky.social · 10/09/2026
For the new reporting obligations, two groups are particularly relevant: manufacturers and in-scope open-source software stewards.
100