OpenRewrite, AI, and chaining CVEs - patching Java apps in 2026 @VMwareTanzu
OpenRewrite, AI, and chaining CVEs - patching Java apps in 2026  @VMwareTanzu
Uploaded May 2026 | Updated September 2026, 8 hours ago
It's Monday morning. Your boss walks up, says "scrap the backlog, we've got a list of CVEs longer than that curved screen we bought you last year, the CISO is coming, fix them," and goes to brunch. A year ago you had 30 days to triage anything under a CVSS seven. Now two lows can chain into a nine, the exploit is already in the wild before policy catches up, and both sides of the fence have AI for finding more.

@dashaun joined @thecote and David Zendzian to walk through what that Monday actually looks like at the application developer level. DaShaun makes the case for the N-minus-zero life - never running anything that isn't the latest version - and the OpenRewrite recipes that make a Spring team's breaking changes shippable across a thousand repos at once. David adds in the systems-and-supply-chain view: what AI plus an MCP server does to a pen-test timeline, why a Linux DDoS the same week as a kernel CVE might not be a coincidence, and which parts of "auto-update" still give security people heartburn. Coté pushes on the metric question - how much of a developer's week should actually be security work, and what's the right number to measure instead.

Key topics:

- Why CVE scores were never standalone, and what chained-vulnerability math looks like when two lows add up to a nine
- How AI plus an MCP server compresses a week of risk analysis into an hour, and what the speedup is actually made of
- OpenRewrite, and what changes when a framework can ship the migration alongside the break
- The N-minus-zero life: why "always on the latest" is the new sane default and how Spring teams operate inside it
- What "software is soft for a reason" means in practice - the case for leaving a project and coming back to find it upgraded
- Why hours-per-developer is the wrong security metric, and what to measure instead - how fast you can react when a signal hits, at every layer of the stack
- Supply chain attacks, the Canonical DDoS, and the timing of upstream betrayals

Interested in a platform that can help you with enterprise-y excellence? Just TryTanzu.ai

Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.

Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r

Hosts: @thecote David Zendzian
OpenRewrite, AI, and chaining CVEs - patching Java apps in 2026The CFO is about to see the AI bill - and two other enterprise AI problemsThe DevEx Your App Teams Crave: AI-Ready PaaS for Private CloudAI Found More Security Bugs in Months Than We Did in YearsWhen the AI policy board is slowing everything downAre You Ready? Balancing Security and Compliance with Rapid AI InnovationRabbitMQ: Streams vs QueuesGood data management comes before good AIWhy Mature Platforms Win with AIDont defer the patches - the playbook for an AI-driven CVE floodReviewing a 150,000 line PRCode is cheap, software is not
VMware Tanzu |

OpenRewrite, AI, and chaining CVEs - patching Java apps in 2026

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER