Delivering #LibericaJDK: supported, @Java standard compatible binaries. Among Top-5 @OpenJDK contributors.

San Jose, CA
JEP 540 brings a simple JSON API to JDK 28 as an incubator module. The jdk.incubator.json module provides a small API for parsing, navigating, and generating JSON. No data binding or streaming APIs. It stays focused on straightforward JSON processing.
1
11
30
1,722
A lot of AI experiments never make it past the demo stage. Let’s talk about the ones that do. JRush Episode 8 · Sep 29: jrush.bell-sw.com/episode8
1
124
20 prompts later and you’re still trying to get AI to write the code you had in mind. @asm0di0 spent months trying different approaches, moving from endless prompt tweaking to a workflow he uses today. He’ll share what changed in his JRush Episode 8 talk on September 29: jrush.bell-sw.com/episode8
1
2
217
One operation, 500 SQL queries. Would you spot it before production? @cat_edelveis shows how to catch N+1 queries in your logs and fix them without changing your service logic. Watch the Spring Data JPA crash course: piped.video/jY0mmMcMwCA
1
8
292
You added AI to move faster. So why are you spending your time fixing its code? @cat_edelveis introduces JRush Episode 8 and Simon Martinelli’s talk on AI-driven modernization in enterprise #Java projects. Simon spent two years working with AI on large applications. He’ll share what teams learned from applying AI to real systems, including what to hand over and what still needs a human review. Full details and registration: jrush.bell-sw.com/episode8
1
2
7
234
Scaling Java Without Overloading Your Database: Meet Open J Proxy 1.0 nitter.net/i/broadcasts/1vJpPNWEb…
150
Martin Ladecký’s Spring I/O talk covers secret hygiene for Java and cloud-native systems, including credentials that can survive in Docker layers and build history. Liberica JDK gets a high five for zero CVEs too. Thanks, Martin ✋ Full talk: piped.video/watch?v=RDqUVQEf…
1
4
246
Pasha Finkelshteyn (@asm0di0) went through a few AI coding setups before finding one he could trust. At JRush Episode 8, he’ll show the approaches he tested, the one he kept, and the changes that made AI-generated code fit into his own development standards. The stream is free. Save your spot: jrush.bell-sw.com/episode8
2
4
211
Baruch Sadogursky built a software factory with AI agents that shipped a real MVP in three days. 💥 The setup brought together rival coding agents, shared context, and review gates to see what happens when AI agents work as a team. @jbaruch is Head of Developer Relations at Port.io and a Java Champion. At JRush Episode 8, he’ll share the process behind the experiment and the lessons from building it. Bring your AI questions to the live session: jrush.bell-sw.com/episode8
1
1
2
274
Sometimes, you end up being responsible for vulnerable code you didn't even write. A vulnerable JDK. A compromised package. An outdated base image. Third-party components become part of your product the moment they are shipped with it. Under the CRA, if an actively exploited vulnerability is in a third-party component integrated in your product, it can become your reporting responsibility if this vulnerability can be exploited in your product. This is why visibility into third-party components is important for timely response. BellSoft Hardened Images can simplify this task for the base image layer. Each image comes with an SBOM, BellSoft continuously monitors the images for newly discovered CVEs, and commercial plans provide SLA-backed remediation. You still need to determine if a vulnerability is exploitable in your product. But if it stems from the base image, you have complete data about base image contents and a defined remediation process from the image vendor. Learn more about BellSoft Hardened Images: bell-sw.com/bellsoft-hardene…
5
193
Simon Martinelli has spent the last two years applying AI to large #Java systems. At JRush Episode 8, he’ll share lessons from real modernization work: the approaches that helped, the ones that had to be dropped, and the places where AI still needs a careful human hand. 🏆 @simas_ch is a Java Champion and creator of the AI Unified Process. Don’t miss the live session: jrush.bell-sw.com/episode8
2
7
347
Liberica JDK 27 is out. 🚀 9 JEPs in this release: G1 as the default GC everywhere, post-quantum hybrid key exchange for TLS 1.3, compact object headers by default, JFR data redaction, and more. Plus 2,542 fixes across JDK and JavaFX. Details and downloads: bell-sw.com/blog/liberica-jd…
9
25
747
A critical CVE lands in your product. Do you need to report it within 24 hours under the CRA? Not necessarily. For manufacturers, a vulnerability becomes mandatorily reportable when there is reliable evidence that a malicious actor has actually exploited it. Severity alone does not trigger the reporting obligation. A proof of concept with no evidence of malicious exploitation? No mandatory Article 14 vulnerability report. A zero-day found by a testing lab, but no evidence that anyone has exploited it? Same answer. Severe security incidents are a separate reporting track. If an incident seriously affects, or could seriously affect, the security of the product, it needs to be reported. So, severity alone does not decide whether a vulnerability has to be reported under Article 14. Evidence of actual malicious exploitation does. ENISA covers more reporting cases in its FAQ: enisa.europa.eu/topics/produ…
Made with AI
1
2
8
401
After years of Project Valhalla work, value objects are coming to JDK 28 as a preview feature. JEP 401 introduces objects without identity. For value objects, == compares their values instead of object identity. Two separately created ValuePoint instances with the same fields are indistinguishable, while regular objects still keep identity-based comparison. First preview.
1
14
70
2,183
AI is moving from experiments into real Java projects. But what happens when it hits legacy systems, production constraints, and teams that need predictable results? JRush Episode 8 brings three engineers sharing what they learned from using AI for modernization, coding workflows, and building with AI agents. Free live event · September 29 Register: jrush.bell-sw.com/episode8
1
6
413
September 11 has passed. If a reportable event showed up tomorrow, would your team know what to do? If you had to think about it, we pulled the reporting process into a six-page cheat sheet for EU Cyber Resilience Act reporting. It starts with the prep work worth doing before anything happens, then follows the reporting flow through the 24-hour notification, the 72-hour update, user communication, and the final report. It also covers the less obvious setup around Assigned Representatives, CSIRT selection, and the product information you need to have ready. There’s a checklist at the end for the things you don’t want to be figuring out under a 24-hour deadline: bell-sw.com/cra-reporting-gu…
1
158
Selling software in the EU? Today the rules changed. Article 14 of the Cyber Resilience Act is now in force, and for manufacturers that means a new reporting obligation with a first deadline of just 24 hours. What actually needs to be reported? Who is responsible? And what should be in place before that timer starts? Watch here: piped.video/IQkzg7quc58
1
1
12
347