Welcome to curated list of handpicked free online resources related to IT, cloud, Big Data, programming languages, Devops. Fresh news and community maintained list of links updated daily. Like what you see? [ Join our newsletter ]

Top new features of Cucumber JVM v6

Categories

Tags testing-and-quality backend-development software-engineering frontend-and-mobile

Behavior Driven Development or BDD is one of the magical terms that many organizations are looking for today. The influence of the BDD methodology has significantly impacted the way the development model works. Its powerful business-driven approach has helped many teams collaborate with different stakeholders to define a better requirement. By Giridhar Rajkumar.

One of the well-known tools that help to automate the requirements for the BDD projects is Cucumber. In this article, you will learn about some of the coolest features available as part of Cucumber 6 (cucumber-jvm) & previous versions and how you can leverage them with your automation pack and business discussions:

  • Rules & examples
  • Other useful keywords
  • Online cucumber reports

One of the major features released in cucumber-jvm 6.0.0 is the usage of the Rule keyword. In general, the Rule keyword will help the team members to think of the scenarios as examples of acceptance criteria or business rules. Examples are different types of scenarios in which the requirement has to be mapped.

The new features in Cucumber 6 will be of great help to the business stakeholders who like to define their requirements more understandably. You will also get link to Cucumber example video demo and links to further resources. Good read!

[Read More]

Microsoft, Google to invest $30 billion in cybersecurity over next 5 years

Categories

Tags miscellaneous security-and-privacy cloud-and-infrastructure leadership-and-career

Google and Microsoft said they are pledging to invest a total of $30 billion in cybersecurity advancements over the next five years, as the U.S. government partners with private sector companies to address threats facing the country in the wake of a string of sophisticated malicious cyber activity targeting critical infrastructure, laying bare the risks to data, organizations, and governments worldwide. Ravie Lakshmanan.

The big tech sector is also rallying behind with a roster of initiatives, including —

  • Microsoft will invest $20 billion over the next five years to deliver advanced security solutions, in addition to making available $150 million in technical services to help federal, state, and local governments with upgrading security protections.
  • Google will invest over $10 billion to bolster cybersecurity, including expanding zero-trust programs, helping secure the software supply chain and enhancing open-source security. It’s worth noting that the search giant, earlier this June, announced a framework called the Supply chain Levels for Software Artifacts (SLSA or “salsa”) to safeguard the integrity of software supply chains.
  • Apple will work with more than 9,000 of its suppliers to push for mass adoption of multi-factor authentications, vulnerability remediation, event logging, and security training.
  • IBM will train 150,000 people in cybersecurity skills over the next three years, and will partner with 20 Historically Black Colleges & Universities to establish a more diverse cyber workforce.
  • Amazon will make available to all Amazon Web Services account holders a multi-factor authentication device to protect against phishing and password theft at no extra cost.

While it remains to be seen how these efforts will unfold in practice, the commitments demonstrate the urgency in prioritizing and elevating cybersecurity after a relentless stretch of high-profile cyber attacks targeting SolarWinds, Microsoft, Colonial Pipeline, JBS, and Kaseya in recent months. Nice one!

[Read More]

Fortifying APIs with advanced security

Categories

Tags devops-and-ci-cd architecture-and-apis frontend-and-mobile product-and-design security-and-privacy

In F5’s The State of Application Strategy in 2021 report, 58% of respondents said they are building a layer of APIs to modernize applications. Increasingly, though, breaches are taking the form of attacks on APIs. By Karthik Krishnaswamy.

This article then describes:

  • Introducing the NGINX Controller App Security add‑on for API management
  • Distributed API Security in any environment
  • Enhanced visibility and analytics
  • Flexible and fine-tuned policies
  • DevOps friendly API security

The NGINX Controller API Management Module provides a variety of mechanisms to protect your APIs, including rate limiting, authentication and authorization. With Controller App Security, you now can now deploy a web application firewall (WAF) to protect your APIs across a multi‑cloud, distributed environment.

Built on F5’s proven security expertise, Controller App Security provides out-of-the-box protection against OWASP API Security Top 10 vulnerabilities, as well as common vulnerabilities like SQL injection and remote command execution (RCE). The add‑on checks for malformed cookies, JSON, and XML, and also validates allowed file types and response status codes. It ensures compliance with HTTP RFCs and detects evasion techniques used to mask attacks. How interesting!

[Read More]

The dos and don'ts of machine learning research

Categories

Tags data-and-analytics how-to ai-and-machine-learning leadership-and-career

Machine learning is becoming an important tool in many industries and fields of science. But ML research and product development present several challenges that, if not addressed, can steer your project in the wrong direction. By Ben Dickson.

Here are some takeaways from the article:

  • Pay extra attention to data
  • Know your models (as well as those of others)
  • Know the final goal and its requirements
  • Know what to measure and report
  • Applied machine learning

When it comes to data, machine learning engineers must consider an extra set of considerations before integrating them into products. Some include data privacy and security, user consent, and regulatory constraints. Many a company has fallen into trouble for mining user data without their consent. Nice one!

[Read More]

Python's ChainMap: Manage multiple contexts effectively

Categories

Tags backend-development software-engineering product-and-design

Sometimes when you’re working with several different dictionaries, you need to group and manage them as a single one. In other situations, you can have multiple dictionaries representing different scopes or contexts and need to handle them as a single dictionary that allows you to access the underlying data following a given order or priority. In those cases, you can take advantage of Python’s ChainMap from the collections module. By Leodanis Pozo Ramos.

In this tutorial, you’ll learn how to:

  • Create ChainMap instances in your Python programs
  • Explore the differences between ChainMap and dict
  • Use ChainMap to work with several dictionaries as one
  • Manage key lookup priorities with ChainMap

Python’s ChainMap from the collections module provides an efficient tool for managing several dictionaries as a single one. This class is handy when you have multiple dictionaries representing different scopes or contexts and need to set access priorities to the underlying data. Good read!

[Read More]

Introduction to Akka Streams

Categories

Tags architecture-and-apis data-and-analytics software-engineering backend-development

Akka Streams is a library to process and transfer a sequence of elements. It is built on top of Akka Actors to make the ingestion and processing of streams easy. As it is build on top of Akka Actors, it provide a higher-level abstraction over Akka’s existing actor model. By Asbin Bhadra.

Akka streams consist of 3 major components in it – Source, Flow, Sink – and any non-cyclical stream consist of at least 2 components Source, Sink and any number of Flow element.

The article deals with:

  • Features of Akka Streams
  • Terminology in Akka-Streams (Source, Sink, Flow, RunnableGraph)
  • Akka Streams in action

You should now better understand the basics of Akka Streams and there is also example code to help you. Informative read!

[Read More]

First look at Akka Serverless

Categories

Tags architecture-and-apis data-and-analytics product-and-design backend-development devops-and-ci-cd

Akka Serverless exposes part of the open-source battle-tested Akka framework as an as-a-service offering. If you ever wondered what a fully managed version of Akka Cluster+Sharding+Persistence would look like, here’s the answer! If you don’t know what Akka is at all, don’t worry — we’ll cover all the necessary details. By Adam Warski.

Akka serverless, programming model

Source: https://softwaremill.com/first-look-at-akka-serverless/#case-study-user-registration

The main points in this article:

  • Programming model
  • Technicalities ()
  • State models
  • Actions
  • Effects
  • Views
  • Inter-service communication
  • Case study: user registration

… and more. The basic unit of deployment in Akka Serverless is a service written in any of the supported languages (there are official SDKs for Java and JavaScript, with more community SDKs available and more official ones coming). Very interesting read!

[Read More]

Refactoring JavaScript — 5 Common problems to look out for and how to fix them

Categories

Tags software-engineering product-and-design leadership-and-career frontend-and-mobile

Refactoring is like the NeverEnding Story: you might think you’re done, but as long as the plot (the project) is ongoing, there is always room for more changes. By Fernando Doglio.

The problem though, comes when we focus on the wrong aspect of our code looking for things to refactor. After all, a good refactor normally means running the risk of breaking a working feature, so you better make damn sure that whatever you’re trying to change, is worth it.

The article covers:

  • Magic values
  • Abusing primitive values
  • Duplicated code
  • Callback hell or unending promise chains
  • Spread responsibility

Keeping your code clean through refactor is a never-ending task, and that’s why author covers it as a completely separate topic in his latest book, Code Well With Others. Good read!

[Read More]

Everything you need to know about submitting to the App Store (and avoiding rejections)

Categories

Tags product-and-design leadership-and-career miscellaneous frontend-and-mobile

A rejection from the App Store review team is a frustrating setback for any developer, and definitely something you want to avoid. Before you send your precious app off to Apple, you’ll need to make sure you’ve taken care of all of the crucial things the software giant expects. There are a lot of mistakes developers make when submitting an app to the App Store, and many can be easily avoided or rectified. By Grace Njoroge.

Before you begin you’ll need to create an iOS App Store Package (or .ipa file) for your app. This package contains everything needed for Apple to install the app on a device: not just the app file itself, but various other information and assets like the app name, developer name and ID, bundle identifier, copyright information, certain app icons, and so on.

In this article, we’ll give you a refresher on the entire process of submitting your app, focusing on the various app info, metadata, and assets required along the way:

  • App information: name, description, and more
  • App icons
  • Screenshots and previews
  • Make use of keywords and categories
  • Update your app regularly
  • Common App Store rejection reasons
  • Consider automation: App Store Connect API

Hopefully you now have a newfound or refreshed understanding of how the App Store submission process works, and of the common pitfalls that could lead to App Store review rejections! Good read.

[Read More]

PC: Personal computing comes of age

Categories

Tags cloud-and-infrastructure leadership-and-career miscellaneous

It wasn’t the first personal computer. Nor was it the most advanced. But shortly after the IBM ® Personal Computer arrived in 1981, it became the leading platform in the revolution that brought computing out of the glass house and into daily life. By IBM.

But it almost didn’t happen. When the concept first came up at IBM corporate headquarters, a senior executive asked the simple question: “Why would anyone want to take a computer home with them?”

In the late 1970s, when the office closed, you turned off your terminal—if you had one—and went home. If you had work to finish up in the evening, you carried a briefcase filled with papers. A handful of aggressive young companies set out to take computing out of back offices and give it to the people. Commodore, Apple, Tandy, Atari and Digital Research had been putting together the pieces that make up a personal computer: a microprocessor (a central processing unit on a single chip), a BIOS (the system boot code), read-only memory (usually a solid-state ROM for controlling the PC), a floppy disk drive, a motherboard and an operating system.

In those days, an entry-level computer at IBM meant a US$90,000 IBM System/38 minicomputer (forefather of today’s IBM Power Systems™ servers) or the barely luggable 50-pound IBM Portable Computer, selling at US$9000. Typical margins were 20 percent to 60 percent on these machines plus the software and services that went with them. IBM at the time was a US$23 billion enterprise with 337,000 employees.

For the details and to learn moore about history of personal computing please follow the link to the full article. Excellent read!

[Read More]