The Provenance Gap in Agent-Written Code
Attestations of agent-written code capture only the terminal verification run — the controls that ran, their results, the governing configuration, and the final commit — while discarding the failed at…
Attestations of agent-written code capture only the terminal verification run — the controls that ran, their results, the governing configuration, and the final commit — while discarding the failed at…
Google separated pre-integration verification from merge coordination more than 15 years ago, with its monorepo handling 40,000 commits per day by early 2015, including 24,000 from automated systems, …
CircleCI's 2026 State of Software Delivery report, analyzing 28 million workflows, found throughput up 59% year over year while main-branch success rates dropped to 70.8%, a five-year low, and recover…
Teams with mature continuous delivery practices are adopting AI agent workflows more successfully, while those without such discipline struggle as AI accelerates feedback loops. Chainguard is phasing …
Practices built to compensate for today's AI model have a half-life determined by the model's improvement rate, according to Stack's analysis of agent engineering trends. The last year saw labels shif…
Engineering leaders who delay AI adoption because of concerns about output quality, cost, or risk are focusing on symptoms rather than the real problem, argues Paul Stack in an open letter. Stack asse…
Software engineering teams that have embraced AI are compounding productivity gains, while others actively reject AI or remain stuck in evaluation, creating a widening gap in how work gets done. A CEO…
A security team used an AI agent to build a CVE scanner that queries NVD, GitHub Advisory DB, and CISA KEV, classifies vulnerabilities by type, and scores actionability. The agent was removed from the…
Swamp, initially built for infrastructure automation, has evolved into a domain-agnostic automation primitive as users applied it to security scanning, cost analysis, and infrastructure validation. Th…
Pulumi co-founder Paul Stack argues that infrastructure-as-code (IaC) tools have historically failed to deliver on their promise of supporting "any system" because their provider ecosystems rely on hu…
Companies must first capture and encode the undocumented operational knowledge held by their most critical engineers before deploying AI agents into production infrastructure. The "Brent" problem — wh…
The sovereign cloud movement is forcing organizations to migrate off US hyperscalers like AWS, driven by regulatory requirements and the US CLOUD Act's data access provisions. Gartner projects $80 bil…
Infrastructure-as-code tools like Terraform and Kubernetes impose a "200% learning tax" by requiring users to master both the tool's abstraction and the underlying cloud API, with knowledge failing to…
A five-person team at Swamp builds and ships product improvements daily using AI agents, operating without human approval gates between decisions and deployment. VP Product Paul Stack and his colleagu…
Engineers who have not yet adopted AI agents for production work face growing pressure as major tech companies restructure around the technology. Shopify, Fiverr, and Block have each cut thousands of …
Five engineers building a software platform called "swamp" no longer write any code themselves, as AI agents now handle all implementation, review, and testing. The team's work has shifted entirely to…
GitHub has moved to per-token billing, ending the era of flat-rate pricing that absorbed AI agent inefficiency. A team of five developers using structured agent tooling spends $3,000 per month on AI c…
Open source maintainers are drowning in AI-generated pull requests where contributors submit code without understanding the codebase, inverting the economics of review. The traditional PR model, which…