The auditor doesn't have an opinion on your CI pipeline. They have an opinion on three things: is the thing in production the thing you built; was that thing required, reviewed and approved; can you prove it. If you can answer those three, the auditor goes home.
Most modern delivery pipelines already produce the evidence — signed artifact digests, deployment records that link production back to the source PR, an audit trail of any human bypasses. The gap is usually knowing where to point an auditor, not new tooling.
Fourth in a 5-post mini-arc on the four control points-of-focus that establish chain of custody of code.
https://t.co/btRdnNxadv
#compliance #devops #softwareengineering #cicd #aigovernance
"Why isn't your goal 100% code coverage?" is the audit question that most engineering teams answer wishy-washy. Pareto, branches versus paths, mutation testing — none of it actually answers the question, and the auditor knows it.
The honest answer: code coverage measures what the code does, not what the system is meant to do. Agree the second with your product owner, write it down, and "100%" stops being a moving target.
Third in a 5-post mini-arc on the four control points-of-focus that establish chain of custody of code.
https://t.co/ekTQkmo0x4
#compliance #devops #softwareengineering #cicd #aigovernance
"4-bit is good enough" — is it though?
Quantization shrinks LLMs to run on modest hardware, but you pay for it in capability. KL-Divergence is how you measure the cost. It's why your local model underperforms the benchmarks.
Checkout Vaibhav's post: https://t.co/1XV51h07Bc
#LLM #Quantization #LocalLLM #Ollama #MachineLearning
The auditor doesn't have an opinion on what good code looks like. They want to see that your team has a defined standard, applies it consistently, and that exceptions are visible.
Most modern engineering teams already have the tooling for all three — branch protection, a code standard, CI gates that block failures. The gap is configuration, not new tools.
Second in a 5-post mini-arc on the four control points-of-focus that establish chain of custody of code.
https://t.co/1Rt0M2wsca
#compliance #devops #softwareengineering #cicd #aigovernance
@covrovski I hope its that (and they fix it to be competitive), I used the whole $30 monthly credit in a little over 2hrs. Otherwise its an excellent model.
Qwen 3.7 max has dropped. It's available through Singapore and it's $$$$$!
I have to say, it's an incredible model, easily comparable to Claude Opus capability, far exceeds the best open-weight models I can run.
My challenge to it, was to refactor 1200 lines of python AI slop into a proper classes. It did it and did so quickly. I'm pretty happy with the code. Qwen3.6-27B and Qwen3.6-35B-A3B could not refactor this code (at least not with a 10 minute timeout on any single instruction).
Alibaba cloud for coding requires a team token subscription - I went with $30. That 10 minute or so refactor of 1200 lines of code cost 20% of my monthly allowance!
The models coming of China are as good as those coming out of the US - they also cost about as much!
#𝗔𝗜 #𝗤𝘄𝗲𝗻 #𝗔𝗜𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 #𝘀𝗼𝗳𝘁𝘄𝗮𝗿𝗲𝗲𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴
Sprint planning is already your audit's arbitration moment. You just have to write that down.
A one-page policy naming where work gets agreed — sprint planning, product-owner sign-off, or a documented delegation for routine tech work — closes the gap between "we agreed it" and "we can prove it." Most engineering teams have everything else (PRs that close tickets, immutable issue histories) without needing new tooling.
First in a 5-post mini-arc on the four control points-of-focus that establish chain of custody of code.
https://t.co/X9YHoqs4FU
#compliance #devops #softwareengineering #cicd #aigovernance
Most engineering teams already have the building blocks for continuous compliance — source control, signed artifacts, role-segregated approvals, immutable logs.
What's been missing is looking at them through a control lens as well as the engineering one. Once you define what the pipeline has to produce to satisfy the controls, compliance becomes a release-time output — not a six-week scramble.
New essay on the four properties that close the gap, using tools you already run. Read on LinkedIn or on my blog https://t.co/YtUhRICi8W
#𝗰𝗼𝗺𝗽𝗹𝗶𝗮𝗻𝗰𝗲 #𝗱𝗲𝘃𝗼𝗽𝘀 #𝘀𝗼𝗳𝘁𝘄𝗮𝗿𝗲𝗲𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 #𝗰𝗶𝗰𝗱 #𝗮𝗶𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲
I have come to realize that WhatsApp basically disconnected me with half of my contacts - this happened around Feb 2026 when I killed my UK number!
𝗜 𝗰𝗮𝗻 𝗮𝘀𝘀𝘂𝗿𝗲 𝘆𝗼𝘂 𝗶𝘁 𝘄𝗮𝘀𝗻'𝘁 𝗶𝗻𝘁𝗲𝗻𝘁𝗶𝗼𝗻𝗮𝗹 - 𝗣𝗹𝗲𝗮𝘀𝗲 𝗗𝗠 𝗺𝗲 𝗼𝗻 𝘀𝗼𝗰𝗶𝗮𝗹 𝗺𝗲𝗱𝗶𝗮 𝘁𝗼 𝗴𝗲𝘁 𝗿𝗲𝗰𝗼𝗻𝗻𝗲𝗰𝘁𝗲𝗱!
Paul
@davepl1968 This has very interesting implications for systems that have either lost source code or have so much mess, they cannot attribute the binary to source. This could finally unlock platforms that have been untouchable for decades.
Ten years, hundreds of deliveries. One extraordinary engineering culture.
Last week was my final day at UBS. Best time of my career. We proved what's possible in a large org with trust instead of fear. Over-engineered. Fixed what wasn't broke. Phenomenal results.
To the hundreds who bought in: thank you. To the friends I've made: thank you. Life-long connections. We seriously had some fun, right!
Stepping into the biggest tech revolution in history. Bittersweet. Boundless energy.
#AIRevolution #EngineeringExcellence #TechLeadership #OpenSource
@steipete@FanaHOVA@AlexReibman@KernelLabs_ai Brilliant! From the man himself. I have two claws running on a tiny VPS that cost $200 for two years! Can probably run 4 or 5 more on the same server
If your AI is 'for entertainment purposes only,' you better make sure you have a Mr. Bucket on the payroll to handle the actual production!
Did you know, at time of writing, the T&C's of co-pilot say precisely this:
Copilot is for entertainment purposes only. It can make mistakes, and it may not work as intended. Don’t rely on Copilot for important advice. Use Copilot at your own risk.
Because nothing is funnier and more entertaining than most important technical innovation in the history of humankind, going wrong!
Check it for yourself: https://t.co/I3Ifz9Pnd7
Note: This post is for entertainment purposes only
#TheBucketEffect #SoftwareEngineering #AIRevolution #TechHumor #FutureOfWork2026
1/ The biggest myth about AI? That it reduces the need for humans. 🧵
2/ In "Charlie and the Chocolate Factory," Mr. Bucket is replaced by a machine. But he ends up back in the factory to fix the machine. Why? Because a machine can do the wrong thing 100x faster than a human.
3/ Look at the image below. The machine is "efficiently" sealing the wrong end of the toothpaste tubes. This is the Jevons Paradox in action: cheaper code = more code = more complexity. 📉➡️📈
4/ Data from the World Economic Forum suggests a net gain of 78 million jobs thanks to AI. We aren't running out of work; we’re running out of people who can maintain the "AI Machine."
https://t.co/okn4XH1S0i.
5/ The bottleneck isn't writing the code anymore—it's validating it. Welcome to the Era of the Maintainer. 🛠️✨
#AIRevolution #JevonsParadox #TechJobs #Coding #MrBucket
I needed accurate GPU monitoring across an AI cluster. Every tool I tried got the NVIDIA metrics wrong.
So I built nv-monitor. One binary, any arch, correct numbers. Built-in Prometheus exporter. Ships with a synthetic load generator to prove your whole monitoring pipeline end-to-end.
Open source: https://t.co/Ur3bYnMMBW
#AI #NVIDIA #GPU #OpenSource #MLOps #DGXSpark #DeepLearning
🦞 Published "Remote Claws" on ClawHub — 39 MCP tools that let your cloud OpenClaw agent control your desktop securely.
Screenshots, mouse, keyboard, browser, shell, files. Three security layers before anything runs.
Your agent gets claws. Your machine gets guardrails.
https://t.co/v8OHGZ3bxV
#AgenticAI #MCP #OpenClaw #AISafety #OpenSource