What the Dev?
Download on the App Store

What the Dev? episodes

  • 369: npm v12 Shifts the Risk to the Runtime

    Dave discusses npm version 12’s decision to disable lifecycle scripts by default to improve security while potentially shifting malicious-package execution from installation time to runtime. Joining him is Darren Meyer , security leader at  Checkmarx. Darren explained that lifecycle scripts, including post-install scripts, have been a common way for attackers to execute malicious code in development environments. With scripts disabled by default, attackers may move deployment and infection code into module-loading behavior, such as execution during require or import. The change is a useful barrier, but it does not eliminate the underlying threat.


    12 min
  • 368: The Future of QA ... or, 'We Don't Need No Stinking Scripts!' (With Wei Wei Wu of Momentic)

    Dave discusses the evolution of quality assurance in an AI-driven development life cycle with Wei Wei Wu, CEO of Momentic.  Wei Wei argues that traditional test scripts like Selenium and Playwright are becoming obsolete as AI agents increasingly write code. Instead, he proposes a future where independent agents act as verifiers to close the feedback loop autonomously. Wei Wei suggests the role of QA is shifting toward "context engineering," where humans provide business logic and edge cases to AI.

    17 min
  • 367: AI is Turning Developers into Development Managers (With Cassie Shum)

    Dave welcomes Cassie Shum, RelationalAI adviser Cassie Shun, former VP ecosystem, product engineering there and formerly at Thoughtworks, to discuss the evolving role of developers in the era of AI. Shum highlights that while AI handles commoditized coding, developers are still essential for design patterns, testing and validation. She identifies two types of organizations: those with weak foundations and those with strong ones. Shum emphasizes the importance of documenting architectural intent and onboarding developers quickly using AI. She suggests that junior developers should focus on understanding design principles and working with AI, rather than just coding.

    14 min
  • 366: Tokenomics: The costs of using AI (With Sreenivasan Rajagopal of Broadcom ValueOps)

    Dave and Sreenivasan Rajagopal discuss the rising costs of AI in organizations, emphasizing the role of the Tokenomics Foundation, a Linux foundation formed by industry leaders, including Broadcom. Sreenivasan explains that AI spend is often exceeding budgets quickly, and the foundation aims to measure and optimize AI investments. They highlight Broadcom's Value Ops AI Tokenomics, which integrates AI costs into infrastructure management, focusing on governance, security, and value realization. The discussion also touches on the importance of understanding AI architecture costs and the need for effective AI governance to ensure productivity and value.

    17 min
  • 365: The Rise of the Personal AI Assistant (With Gavriel Cohen of NanoCo)

    Dave Rubinstein interviews Gavriel Cohen, creator of NanoClaw, about the state of the project, an open-source multi-agent orchestration tool released in February. NanoClaw quickly gained popularity, with over 30,000 stars and 13,000 forks on GitHub, and a community of 5,000 in Discord. Cohen emphasizes the project's focus on agent isolation, credential management, and policy enforcement to prevent agents from going rogue. He discusses the importance of continuous testing and end-to-end frameworks to adapt to rapidly changing AI models. Cohen also highlights the need for robust security measures, including dedicated AI security agents, to protect against sophisticated attacks and zero-day vulnerabilities.

    22 min
  • 364: AI is Changing Who Builds Software

    Dave Rubinstein discusses with Tim Qi, lead data analyst at Linear, how AI is changing who builds software. Linear's study found that AI is accelerating team velocity and changing behavior on platforms. Companies are adopting AI in two main ways: top-down, tightly controlled rollouts, and bottom-up, allowing experimentation. Training varies, often evolving with use cases. AI adoption is similar across company sizes. The study also revealed that AI tools are making previously cumbersome tasks more manageable, leading to higher quality outputs. The industry is still figuring out how to manage the shadow AI issue.


    15 min
  • 363: The Role of AI in Mainframe Modernization

    Dave Rubinstein and Matt Whitbourne discuss the evolution and potential of mainframe modernization, particularly with the integration of AI. They highlight the long-standing challenge of maintaining legacy systems, such as COBOL, and the role of AI in enhancing innovation and efficiency. Whitbourne emphasizes the importance of understanding business logic before modernizing and the potential for AI to assist in this process. He also notes the benefits of AI in improving code serviceability, risk management, and compliance. The conversation underscores the need for a strategic approach to mainframe modernization, focusing on business goals and the unique characteristics of mainframe workloads.

    16 min
  • 362: The Disconnect Between AI-generated Code and Security

    Dave Rubinstein interviews Ilya Kabanov, a former Google AI security manager, about the disconnect between AI's rapid code generation and security measures. Kabanoff, who leads the Weather Report and is a research affiliate at MIT, discusses the significant progress AI has made in writing functional code, citing a 4x increase in security over a year. However, security checks cost five times more than code writing, posing economic challenges. Kabanov emphasizes the need for education, understanding AI's limitations, and prioritizing fundamental security practices to ensure secure AI-generated code.


    26 min
  • 361: The AI Adoption Maturity Model (With Ipek Ozkaya of CMU SEI)

    Dave and Ipek Ozkaya discuss the AI adoption maturity model created by Carnegie Mellon's Software Engineering Institute and Accenture. The model addresses issues like mismatched expectations, untested implementations, and misaligned applications that hinder AI investment returns. It includes eight core dimensions: organizational change, workforce and culture, workflow reengineering, risk and governance, data engineering, operations, technology ecosystem, and AI lifecycle engineering. The model progresses from exploratory AI to scaled AI, emphasizing the importance of strategic alignment, workflow reengineering, and ecosystem partnerships.

    19 min
  • 360: How do you nurture junior developers in an AI world? (With Barun Singh of Andela)

    SD Times editor-in-chief Dave Rubinstein and Barun Singh of tech talent company Andela discuss the impact of AI on nurturing future developers. Singh emphasizes that while AI automates coding basics, core knowledge and critical thinking are still essential. He highlights the importance of code review, planning, and security, which require senior experience. Singh believes colleges should focus on foundational knowledge, and boot camps remain relevant due to their immersive learning approach. He notes a shift towards retraining existing talent rather than just recruiting new workers. 

    16 min

About What the Dev?

From the publisher's feed

What the Dev? is a podcast by the SD Times editorial team. We cover the biggest and newest topics in software development.