 |
| 01 DPE Summit 2027 is set for February 2-3 |
| 02 Flaky tests are getting worse |
| 03 AI amplifies engineering rigor |
| 04 A hijacked pipeline signed malware |
| 05 Develocity 2026.2 fixes its own cache misses |
| 06 DPE & AI job openings |
|
Mark your calendars, DPE Summit 2027 is set!
DPE Summit, the only event fully dedicated to Developer Productivity Engineering and Developer Experience in the age of AI, is set for February 2-3, 2027 in San Francisco. 50-plus speakers, 30-plus sessions, and 600-plus attendees expected, you don't want to miss your chance to attend. Registration is open now, and the call for speakers is live if you or someone on your team has a session worth submitting.
Still need convincing? Check out our previous years' sessions from some of the biggest companies in the industry here. Early bird ticket pricing ends October 23, so don't miss out on your chance!
|
|
Flaky tests are getting worse, not better
Bitrise's Mobile Insights data, drawn from more than 10 million builds over three and a half years, found the share of teams experiencing test flakiness rose from 10% in 2022 to 26% in 2025, even as testing frameworks and CI tooling got smarter. Pipeline complexity grew 23% over the same stretch, which explains most of it. More steps, more environments, more chances for something to be non-deterministic.
TestDino's new Flaky Test Benchmark Report compiles what happens once flakiness takes hold at scale. Google reports that flaky failures account for 84% of its pass-to-fail transitions, and the math on pipeline impact is brutal: a single test with a 0.03% flake rate can cause 70% of pipelines to fail once you're running 4,000 tests per build. Atlassian's Flakinator processes 350 million test executions a day and catches 81% of flaky signals, but detection alone isn't the fix.
The teams that actually move the number do something unglamorous. Measure the flake rate first, then quarantine rather than ignore. Microsoft's policy is blunt: fix a flaky test within two weeks or remove it. That alone cut their overall flakiness by 18% in six months.
|
|
AI doesn't replace engineering rigor, it amplifies it
In a guest letter on Honeycomb's blog, Fin CTO Darragh Curran writes to engineering leaders who are under pressure to turn AI into magic results while their teams fight product competition on one side and AI induced burnout on the other. His argument is direct: AI is an amplifier, not a substitute, for whatever engineering practices already exist on a team.
Curran, who led engineering through the pivot that turned Intercom's customer service product into Fin, points back to a principle he wrote about more than a decade ago, that shipping is a company's heartbeat. His update for 2026 is that the habits which make shipping safe, fast feedback, honest observability, tight ownership, matter more once AI raises the volume of code moving through a team, not less.
The line worth sitting with is his warning to leaders treating AI adoption as inevitable magic. Teams that skip the rigor now are borrowing against a future that AI will only make more expensive to pay back.
|
|
A hijacked CI pipeline signed its own malware
GitGuardian's latest roundup tracks four supply chain attacks that hit npm and PyPI between early June and July 14: a Shai-Hulud worm variant that reached PyPI, typosquatted payment SDKs quietly harvesting CI secrets, a stolen npm publishing token that poisoned the Jscrambler package, and a hijacked GitHub Actions workflow at AsyncAPI.
The AsyncAPI case is the one worth remembering. An attacker exploited a pull_request_target weakness that a contributor had flagged 58 days earlier and that nobody had fixed, using it to steal a highly privileged bot token. From there, the compromised pipeline's own release workflow published the backdoored packages, complete with valid Sigstore and SLSA provenance. The signatures were entirely honest about where the package came from. They said nothing about whether the code inside it was safe to run.
Four different entry points, one shared target: the credentials sitting in developer environments and CI runners, not the source code itself.
|
|
Develocity 2026.2 ships an agent that fixes your own cache misses
Develocity 2026.2 shipped June 30, and its headline feature leans hard into letting AI agents do specialist level troubleshooting on their own. Build Caching Optimizer combines Build Scan data with build tool internals so an agent can diagnose exactly why a Gradle task or Maven goal missed the cache, then apply the fix, work that used to require someone with deep hands on familiarity with build internals.
The release also adds a Repository Stability dashboard that aggregates dependency download failures across every build and project, which makes it possible to tell a transient outage apart from a repository that's quietly degrading builds week over week. Setup Cache now covers buildSrc and included builds too, cutting Gradle configuration time on ephemeral CI agents even for projects that haven't adopted Build Cache.
On the governance side, Develocity Provenance Governor picked up Fact Connectors, which pull attestations from any HTTP API into a tamper proof Fact Store. That matters because Fact Connectors let you bring in facts beyond build provenance, like code review sign-off or security scan results, so Provenance Governor can require all of them together before an artifact ships. This is the kind of gap Fact Connectors is designed to close: the AsyncAPI packages had valid Sigstore and SLSA provenance showing exactly where they came from, but nothing in that provenance said a human had reviewed the change or that no anomalous token activity preceded the release.
|
| Career Opportunities |
12 openings |
The industry needs you! You might find your dream role among these job openings related to DPE, AI developer productivity, and engineering leadership.
NOTE: These postings are active at the time of sending but are subject to change.
|
CS
|
Platform Engineer
Clear Street · Build self-service developer platforms and golden paths for a low-latency trading firm's engineering org.
|
New York, NY |
|
GG
|
Senior Platform Engineer
GumGum · Architect an AI-powered, spec-driven development platform from the ground up for the whole engineering org.
|
Santa Monica, CA |
|
KO
|
Senior Cloud Platform Engineer
Koddi · Lead a Kubernetes and Terraform modernization effort for a high scale SaaS advertising platform.
|
Fort Worth, TX |
|
ED
|
Senior Platform Engineer
EDO · Own paved paths, reusable infrastructure modules, and self-service workflows for the whole engineering org.
|
Multiple US offices |
|
TS
|
Infrastructure Engineer
Tailscale · Build internal tooling and shared services, and improve observability and CI/CD for a fully-distributed networking company.
|
● Remote - UK |
|
CO
|
Senior DevOps Engineer
Copper.co · Build self-service CI/CD and blockchain node infrastructure for an institutional digital asset custody platform.
|
London |
|
RE
|
Senior DevOps Engineer
Regard · Build and scale the CI/CD pipelines and infrastructure as code behind an AI powered clinical documentation platform.
|
Multiple US offices |
|
CH
|
Cloud Infrastructure Engineer
Clover Health · Build the CI/CD, IaC, and Kubernetes lifecycle systems behind a globally distributed healthcare engineering team.
|
● Remote - US |
|
FL
|
Principal Platform Engineer
Flexential · Lead a team building engineering lifecycle platforms and CI/CD for high velocity, secure SDLC.
|
● Remote - US |
|
Develocity | 2261 Market Street | San Francisco, CA 94114
Privacy Policy · Unsubscribe
|
|