DevSecOps

Command Zero API & MCP Server: The Agentic SOC Is Here

Command Zero API & MCP Server: The Agentic SOC Is Here

Command Zero has released a public API and MCP server that turn its SOC investigation engine into a callable capability, letting security teams trigger, manage, and close investigations programmatically from within existing SOAR and AI agent workflows. The release reflects a broader market shift toward agentic security operations, where AI handles context-gathering and humans retain decision authority. ECI Research analysts assess the competitive, compliance, and operational implications.

Command Zero API & MCP Server: The Agentic SOC Is Here Read More »

IBM Bob: Agentic SDLC Platform Targets Enterprise Delivery

IBM Bob: Agentic SDLC Platform Targets Enterprise Delivery

IBM has expanded the rollout of IBM Bob, an agentic SDLC platform combining multi-model orchestration, embedded security, and lifecycle governance. Early deployments report up to 90% faster delivery and 10x ROI. ECI Research examines the competitive implications and what enterprise teams should evaluate before adopting.

IBM Bob: Agentic SDLC Platform Targets Enterprise Delivery Read More »

GitLab 18.11: Duo Agents, CI Automation, and AI Budget Controls

GitLab 18.11: Duo Agents, CI Automation, and AI Budget Controls

GitLab 18.11 introduces two purpose-built AI agents targeting CI/CD pipeline setup and delivery analytics, alongside a new credit governance framework for enterprise AI spend control. The CI Expert Agent eliminates manual YAML authoring while the Data Analyst Agent brings natural-language access to engineering metrics. Together, these additions address the operational and governance gaps that AI code generation has created but not resolved.

GitLab 18.11: Duo Agents, CI Automation, and AI Budget Controls Read More »

Codenotary Launches AI Agent Security and Autonomous Remediation Platforms

Codenotary Launches AI Agent Security and Autonomous Remediation Platforms

Codenotary has launched two new platforms targeting AI agent observability and autonomous security remediation, alongside 37 new enterprise customers in six months. ECI Research examines why the AI agent security gap is a live operational risk, what the AgentX autonomous remediation model means for enterprise security teams, and how Codenotary is positioning itself against platform-native monitoring from hyperscalers.

Codenotary Launches AI Agent Security and Autonomous Remediation Platforms Read More »

CRA Compliance and Trustable Software: What OCX 2026 Revealed

CRA Compliance and Trustable Software: What OCX 2026 Revealed

The Eclipse Foundation’s OCX 2026 made clear that CRA compliance is a product development problem, not a legal checkbox. Manufacturers face a hard deadline, open source maintainers face an inbound wave of questionnaires, and AI-generated code is adding new layers of compliance debt. Here’s what ITDMs and developers need to act on now.

CRA Compliance and Trustable Software: What OCX 2026 Revealed Read More »

Jakarta EE AI Integration: What's Coming in EE 12 and 13

Jakarta EE AI Integration: What’s Coming in EE 12 and 13

At OCX 2026, Eclipse Foundation speakers outlined Jakarta EE’s path from J2EE’s over-engineered past to a CDI-centric, AI-capable future. Jakarta EE 12 brings CDI-native services and NoSQL support, while the Jakarta AI specification targets EE 13. For enterprise architects, the case rests on a vendor-neutral integration standard for AI agents rather than a new model training framework.

Jakarta EE AI Integration: What’s Coming in EE 12 and 13 Read More »