<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Application Security - News</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Application Security News feed</description>
    <item>
      <title>GitLab 19.0 Embeds Agentic AI in Secrets, Merge Requests, and Supply Chain Security</title>
      <link>https://www.infoq.com/news/2026/06/gitlab-19-agentic-ai/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/06/gitlab-19-agentic-ai/en/headerimage/header-1781418320600.jpeg"/&gt;&lt;p&gt;GitLab 19.0 extends agentic AI beyond code generation into securing credentials, reviewing and merging changes, and scanning dependencies, adding a public beta Secrets Manager, a full merge request Developer Flow, usage-based GitLab Duo billing, and generally available SBOM dependency scanning.&lt;/p&gt; &lt;i&gt;By Mark Silvester&lt;/i&gt;</description>
      <category>Application Security</category>
      <category>Agents</category>
      <category>Continuous Integration</category>
      <category>DevSecOps</category>
      <category>Continuous Delivery</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Fri, 19 Jun 2026 08:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/06/gitlab-19-agentic-ai/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</guid>
      <dc:creator>Mark Silvester</dc:creator>
      <dc:date>2026-06-19T08:00:00Z</dc:date>
      <dc:identifier>/news/2026/06/gitlab-19-agentic-ai/en</dc:identifier>
    </item>
    <item>
      <title>VS Code 1.123 Adds Two-Hour Extension Update Delay to Limit Supply Chain Attacks</title>
      <link>https://www.infoq.com/news/2026/06/vscode-extension-update-delay/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;VS Code 1.123 adds a two-hour delay before auto-updating extensions to newly published versions, creating a revocation window against supply chain attacks. The delay does not apply to trusted publishers like Microsoft, GitHub, and OpenAI. Similar cooldown mechanisms have now spread across pip, RubyGems, npm, pnpm, Yarn, and Bun.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Application Security</category>
      <category>Software Supply Chain</category>
      <category>Visual Studio Code</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Thu, 18 Jun 2026 10:15:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/06/vscode-extension-update-delay/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-06-18T10:15:00Z</dc:date>
      <dc:identifier>/news/2026/06/vscode-extension-update-delay/en</dc:identifier>
    </item>
  </channel>
</rss>
