Uploaded May 2026 | Updated September 2026, 8 hours ago
It's Monday morning. Your boss walks up, says "scrap the backlog, we've got a list of CVEs longer than that curved screen we bought you last year, the CISO is coming, fix them," and goes to brunch. A year ago you had 30 days to triage anything under a CVSS seven. Now two lows can chain into a nine, the exploit is already in the wild before policy catches up, and both sides of the fence have AI for finding more.
@dashaun joined @thecote and David Zendzian to walk through what that Monday actually looks like at the application developer level. DaShaun makes the case for the N-minus-zero life - never running anything that isn't the latest version - and the OpenRewrite recipes that make a Spring team's breaking changes shippable across a thousand repos at once. David adds in the systems-and-supply-chain view: what AI plus an MCP server does to a pen-test timeline, why a Linux DDoS the same week as a kernel CVE might not be a coincidence, and which parts of "auto-update" still give security people heartburn. Coté pushes on the metric question - how much of a developer's week should actually be security work, and what's the right number to measure instead.
Key topics:
- Why CVE scores were never standalone, and what chained-vulnerability math looks like when two lows add up to a nine
- How AI plus an MCP server compresses a week of risk analysis into an hour, and what the speedup is actually made of
- OpenRewrite, and what changes when a framework can ship the migration alongside the break
- The N-minus-zero life: why "always on the latest" is the new sane default and how Spring teams operate inside it
- What "software is soft for a reason" means in practice - the case for leaving a project and coming back to find it upgraded
- Why hours-per-developer is the wrong security metric, and what to measure instead - how fast you can react when a signal hits, at every layer of the stack
- Supply chain attacks, the Canonical DDoS, and the timing of upstream betrayals
Interested in a platform that can help you with enterprise-y excellence? Just TryTanzu.ai
Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.
Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r
Hosts: @thecote David Zendzian
It's Monday morning. Your boss walks up, says "scrap the backlog, we've got a list of CVEs longer than that curved screen we bought you last year, the CISO is coming, fix them," and goes to brunch. A year ago you had 30 days to triage anything under a CVSS seven. Now two lows can chain into a nine, the exploit is already in the wild before policy catches up, and both sides of the fence have AI for finding more.
@dashaun joined @thecote and David Zendzian to walk through what that Monday actually looks like at the application developer level. DaShaun makes the case for the N-minus-zero life - never running anything that isn't the latest version - and the OpenRewrite recipes that make a Spring team's breaking changes shippable across a thousand repos at once. David adds in the systems-and-supply-chain view: what AI plus an MCP server does to a pen-test timeline, why a Linux DDoS the same week as a kernel CVE might not be a coincidence, and which parts of "auto-update" still give security people heartburn. Coté pushes on the metric question - how much of a developer's week should actually be security work, and what's the right number to measure instead.
Key topics:
- Why CVE scores were never standalone, and what chained-vulnerability math looks like when two lows add up to a nine
- How AI plus an MCP server compresses a week of risk analysis into an hour, and what the speedup is actually made of
- OpenRewrite, and what changes when a framework can ship the migration alongside the break
- The N-minus-zero life: why "always on the latest" is the new sane default and how Spring teams operate inside it
- What "software is soft for a reason" means in practice - the case for leaving a project and coming back to find it upgraded
- Why hours-per-developer is the wrong security metric, and what to measure instead - how fast you can react when a signal hits, at every layer of the stack
- Supply chain attacks, the Canonical DDoS, and the timing of upstream betrayals
Interested in a platform that can help you with enterprise-y excellence? Just TryTanzu.ai
Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.
Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r
Hosts: @thecote David Zendzian










