<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Continuous Delivery</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Continuous Delivery feed</description>
    <item>
      <title>GitHub Hardens npm and Actions Defaults, Drawing Debate over Delays versus Signing</title>
      <link>https://www.infoq.com/news/2026/08/github-npm-actions-defaults/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Continuous+Delivery</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/08/github-npm-actions-defaults/en/headerimage/generatedHeaderImage-1785830307506.jpg"/&gt;&lt;p&gt;GitHub consolidated the npm and Actions changes it shipped from March to July 2026 against supply chain attacks, several of which alter defaults rather than add options. Hacker News discussion focused less on the individual controls than on whether waiting periods are the right instrument, or a substitute for author-side package signing.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Software Supply Chain</category>
      <category>Automation</category>
      <category>GitHub Actions</category>
      <category>Open Source</category>
      <category>github</category>
      <category>Continuous Delivery</category>
      <category>Security</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Sat, 08 Aug 2026 07:45:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/08/github-npm-actions-defaults/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Continuous+Delivery</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-08-08T07:45:00Z</dc:date>
      <dc:identifier>/news/2026/08/github-npm-actions-defaults/en</dc:identifier>
    </item>
    <item>
      <title>Presentation: Rewriting All of Spotify's Code Base, All the Time</title>
      <link>https://www.infoq.com/presentations/spotify-ai-codebase-migration-agent/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Continuous+Delivery</link>
      <description>&lt;img src="https://res.infoq.com/presentations/spotify-ai-codebase-migration-agent/en/mediumimage/medium-1784809804876.jpg"/&gt;&lt;p&gt;Jo Kelly-Fenton and Aleksandar Mitic explain how Spotify created "Honk," an AI coding agent, to handle complex fleet-wide codebase migrations. They share key architectural insights on decoupling CI verification runtimes from AI agents, dealing with automated pull request bottlenecks, and driving aggressive standardization across thousands of engineering repositories.&lt;/p&gt; &lt;i&gt;By Jo Kelly-Fenton, Aleksandar Mitic&lt;/i&gt;</description>
      <category>QCon London 2026</category>
      <category>AI Coding</category>
      <category>Continuous Improvement</category>
      <category>migration</category>
      <category>Large language models</category>
      <category>Standardization</category>
      <category>Agents</category>
      <category>Continuous Delivery</category>
      <category>Transcripts</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>presentation</category>
      <pubDate>Fri, 07 Aug 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/presentations/spotify-ai-codebase-migration-agent/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Continuous+Delivery</guid>
      <dc:creator>Jo Kelly-Fenton, Aleksandar Mitic</dc:creator>
      <dc:date>2026-08-07T11:00:00Z</dc:date>
      <dc:identifier>/presentations/spotify-ai-codebase-migration-agent/en</dc:identifier>
    </item>
  </channel>
</rss>
