惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
Scott Helme
Scott Helme
爱范儿
爱范儿
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
博客园 - Franky
V
V2EX
腾讯CDC
博客园_首页
博客园 - 司徒正美
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog
雷峰网
雷峰网
Stack Overflow Blog
Stack Overflow Blog
IT之家
IT之家
罗磊的独立博客
Recorded Future
Recorded Future
博客园 - 聂微东
O
OpenAI News
S
Secure Thoughts
Hacker News: Ask HN
Hacker News: Ask HN
S
Schneier on Security
Hacker News - Newest:
Hacker News - Newest: "LLM"
Y
Y Combinator Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Project Zero
Project Zero
宝玉的分享
宝玉的分享
K
Kaspersky official blog
N
Netflix TechBlog - Medium
T
The Exploit Database - CXSecurity.com
Google Online Security Blog
Google Online Security Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Webroot Blog
Webroot Blog
云风的 BLOG
云风的 BLOG
Simon Willison's Weblog
Simon Willison's Weblog
C
Check Point Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
L
LINUX DO - 热门话题
美团技术团队
L
Lohrmann on Cybersecurity

2024 Sonatype Blog

Miasma Returns: Leo Platform Compromise in npm The Rise of Collective Defense for Open Source Signal Over Noise: Reachability Analysis Is the Reality Check SCA Has Been Missing Software Security Has to Start at Assembly easy-day-js Targets Mastra, Dependency Attacks Grow Open Publishing, Commercial Scale Software Dependency Cooldowns Are a Symptom, Not a Strategy Atomic Arch npm Campaign Adds Malicious Dependency From SBOMs to AI BOMs: Why SPDX 3.0 Matters Mythos Found 10,000 Vulnerabilities. The Bigger Challenge Is Fixing Them New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages Lazarus Group's Latest: Brandjacking Campaign on npm 5 Steps to Turn Your RMF Backlog Into a Continuous ATO: The CSRMC Migration Playbook The AI Race Is Becoming a Remediation Race Red Hat Cloud Services npm Packages Hijacked Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies AI Is Making Software Autonomous, and Governance Must Follow Your Outdated Repository Still Works, But It May Not Be Safe Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT AppSec Tools Explained: SAST vs SCA vs DAST | Sonatype Managing Open Source Software Risks With the HeroDevs EOL Dashboard Shai-Hulud is Back: Maintainer Accounts Are Still the Soft Target Building Trusted AI Development With Kiro and Sonatype Guide How to Build a Software Supply Chain Security Playbook The Evolution of Open Source Malware: From Volume to Trust Abuse The Mythos AI Vulnerability Storm: What to Do Next Malicious PyTorch Lightning Packages Found on PyPI Open is Not Costless: Reclaiming Sustainable Infrastructure Q1 Updates in Nexus Repository: More Formats, Stronger Operations, and a Better Day-to-Day Experience Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths The Time Is Now to Prepare for CRA Enforcement Sonatype Innovate: Real Peer Connections, Real Product Influence, Real Recognition Mythos and the AI Vulnerability Storm: Exploring the Control Point When AI Writes Code, Who Governs the Dependencies? Why Software Supply Chain Security Requires a New Playbook Q1 2026 Open Source Malware Index: Adaptive Attacks Exploit Trust Modernizing Nexus Repository: Moving Beyond OrientDB AI, DevSecOps, and the Future of Application Security: The Gartner® Report How Sonatype's Container Scanning Protects You From Zero-Days Axios Compromise on npm Introduces Hidden Malicious Package Is Your Repository Ready for What's Next? Autonomous Development and AI: Speed vs. Security Grounded Intelligence Ensures Safe AI Software Development Compromised litellm PyPI Package Delivers Multi-Stage Credential Stealer Golden Pull Requests: Automating Trusted Remediation Without Breaking Builds Sonatype Discovers Two Malicious npm Packages
Why Developer Experience Is the Foundation of DevSecOps Success
Aaron Linskens · 2026-04-29 · via 2024 Sonatype Blog

Application security is evolving. But for many organizations, execution still lags behind intent.

AI is accelerating development, security responsibilities are shifting toward developers, and tools are converging into broader platforms. These changes reshape how application security works in practice, exposing a growing gap between what teams can detect and what they can actually fix.

For most organizations, the issue is not a lack of tools or data. It's the inability to act on what they already have. Increasingly, that comes down to developer experience.

Application Security Has a Signal Problem, And AI Is Scaling It

Most application security programs already generate findings at scale. The problem isn't detection. It's volume.

As AI accelerates development, it also increases:

  • Code output.

  • Dependency usage.

  • Vulnerability volume.

At the same time, release cycles are shrinking, leaving less time to review and remediate. This creates noise. And noise creates friction, especially for developers responsible for fixing issues.

Traditional approaches built around scanning and triage don't scale in this environment.

The challenge isn't more tools but a better signal that would make it easier for developers to act on what matters most.

Developer Experience Is Now a Security Control

As security shifts left, developers are increasingly responsible for fixing vulnerabilities. That makes developer experience a key factor in security effectiveness.

If workflows are slow, noisy, or disconnected from how developers work, they won't be followed. Issues get delayed or ignored.

When security is embedded into existing workflows, it becomes easier to adopt and scale.

Approaches like application security posture management (ASPM) help by focusing on:

  • Prioritization to highlight what actually matters.

  • Automation to reduce effort and speed remediation.

  • Ownership to route issues to the right teams.

In this model, developer experience isn't just about usability. It's a core security control.

Prioritization Matters More Than Detection

Most organizations don't struggle to find vulnerabilities. They struggle to decide what to do about them. That's why prioritization is becoming more important than detection.

Not every vulnerability carries the same level of risk. Context matters:

  • Is the vulnerable code actually reachable?

  • Is it being actively exploited?

  • Does it impact a critical application?

Without this context, developers treat everything as urgent, which usually results in nothing being addressed efficiently.

By focusing on reachability, exploitability, and business impact, organizations can reduce noise and make it easier for developers to act.

Platform Consolidation Is Inevitable, but Not Without Risk

As application security evolves, consolidation is becoming a natural next step.

Bringing together testing, posture management, and supply chain security into unified platforms can simplify workflows, reduce tool sprawl, and improve visibility across the SDLC.

But consolidation comes with tradeoffs.

Not all platforms deliver on the promise of integration. Some introduce new complexity, limit flexibility, or create dependency on a single vendor.

More importantly, not all platforms improve the developer experience.

The key is not consolidation for its own sake but consolidation that reduces friction and helps developers move faster.

Software Supply Chain Risk Is the Foundation

One trend that cuts across all of these shifts is the growing importance of software supply chain security.

Modern applications are built on open source. That means risk doesn't start in proprietary code — it starts in the components that code depends on.

This is where developer experience becomes even more critical.

If developers don't have clear visibility into dependency risk — or if controls are too restrictive — issues either slip through or slow development unnecessarily.

Managing dependencies, enforcing policy, and identifying vulnerable components must happen in a way that supports developers, not blocks them.

What High-Performing Teams Will Do Differently

These trends don't just reshape the landscape. They change how effective teams operate. Instead of reacting to volume, high-performing teams focus on clarity and enabling developers to act.

In practice, that means:

  • Governing AI usage with clear guardrails instead of blocking it.

  • Using AI to accelerate remediation, not just generate code.

  • Prioritizing real risk over volume to reduce noise.

  • Embedding security into developer workflows to minimize friction.

  • Consolidating tools strategically, based on developer outcomes.

The common thread: security works best when it works the way developers do.

The Future of Application Security Depends on Developer Experience

Application security is becoming more complex.

AI is increasing the speed and scale of development. Platforms are reshaping how tools are delivered. And developers are taking on more responsibility for security outcomes.

But complexity alone doesn't determine success.

The organizations that improve application security maturity won't be the ones with the most tools or the most alerts. They'll be the ones that reduce noise, prioritize effectively, and make it easier for developers to fix what matters.

For a deeper look at how developer experience, AI, and platform consolidation are reshaping application security, explore the full Application Security Strategy 2026 report from Gartner®.

Gartner, Application Security Strategy 2026: AI, DevSecOps and Platform Consolidation, Dionisio Zumerle, 18 September 2025

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Tags