CODING JAG - Issue 309

Welcome to the 309th edition of Coding Jag brought to you by TestMu AI!๐Ÿ‘

GitHub Advanced Security scanned the workflow file. It read the exact lines that allowed anyone to run commands on Snowflake's build machine simply by opening an issue with a crafted title. It passed them clean. Five days later, an autonomous agent from Wiz found the hole and walked into Snowflake's internal Jira.

Then the argument started over who wrote the bug. GitHub says a human did. Wiz's CTO agrees the specific lines were not Copilot's, though Copilot is listed as a co-author on the pull request. The part nobody disputes is the part that matters: the review said clean, and it wasn't.

That thread runs through the whole week. Cypress shipped a command that hands your AI agent direct access to a live test session. Zed launched Delta so a reviewer can see the conversation behind every edit. Go made its goroutine leak profile generally available. And 1,221 people re-ran 2,226 papers from ICML and found that almost a quarter had a claim falsified or contested.

TestMu Conf 2026 is on air right now, and Day 3 runs tomorrow, 21 August. Replit CTO Luis Hector Chavez and Microsoft's Dona Sarkar both keynote, and the whole thing is free and virtual. Day 2 opened with Thomas Dohmke asking whether the developer lifecycle is dead.

๐Ÿ“ฌ Come across something useful or interesting? Just reply and let's exchange ideas.

News

Wiz CTO Speaks Out Amid Confusion Over Snowflake-GitHub Copilot Flaw

08 minChrome-Extensionitpro.com

๐Ÿ”“ Nicole Kobie unpicks the flaw everyone is still arguing about. Wiz's autonomous agent found a script injection in Snowflake's public repo, triggered it with a crafted issue title, and reached internal Jira. GitHub Advanced Security had scanned that same file and passed it as clean.

Microsoft Confirms GitHub Is Down Worldwide

09 minChrome-Extensionbleepingcomputer.com

โš ๏ธ Mayank Parmar covered the 17 August outage as it unfolded. Actions, Webhooks, Issues, Pull Requests, and SAML and OIDC sign-in were degraded, with error rates hitting 20% across the web and API, and roughly 50% for repository downloads. The copilot went down too. Check your build fallbacks.

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

10 minChrome-Extensionthehackernews.com

๐Ÿšจ Swati Khandelwal reports GitLab breaking its own patch schedule for this one. A flaw rated 9.4 allowed an unauthenticated user to modify or delete public projects and user data via a single GraphQL request. Fixed in 19.2.4, 19.1.6, 19.0.8, and 18.11.11. Only self-managed installs need to act.

SpaceX Has Closed Its $60bn Cursor Deal, and Cursor Was Buying a Company the Day Before

07 minChrome-Extensionthenextweb.com

๐Ÿ’ฐ Cristian Dina, CRO at The Next Web, reports the largest venture-backed acquisition on record. SpaceX completed its $60 billion purchase of Cursor on 14 August, two months after the binding agreement. The day before, Firetiger joined Cursor. If your team standardized on Cursor, the roadmap has a new owner.

Introducing Agent Assurance for Autonomous AI Agents

08 minChrome-Extensiontestmuai.com

๐Ÿค– Anubhav Singhmaar, AI Product Manager at TestMu AI, introduces Agent Assurance. It reads your autonomous agent's codebase, writes the test suite, runs it for real, and grades every criterion against observed evidence rather than the agent's own account. Eighteen scenario categories, nine of them adversarial by default.

AI

Recovering Encrypted LLM Reasoning Traces

09 minChrome-Extensionembracethered.com

๐Ÿ”‘ Johann shows that the encrypted reasoning blobs your agent leaves behind are not the opaque data everyone assumes them to be. Researchers decoded 315,320 reasoning blocks scraped from public repositories and pulled out 367 pieces of personal data and 182 credentials, including API keys and passwords. Check what your harness commits.

What We Learned by Reproducing 2,200 Papers from ICML

10 minChrome-Extensionhuggingface.co

๐Ÿ“Š Abubakar Abid and 86 contributors ran the largest replication effort a machine learning conference has seen. In 19 days, participants published 6,816 logbooks covering 2,226 papers, about a third of ICML. Almost a quarter of the examined papers had at least one claim falsified or contested. Read benchmark tables accordingly.

Building an Agentic SDLC With a QA Engineering Mindset

07 minChrome-Extensionstackoverflow.blog

๐Ÿง  Suneet Malhotra, Senior Manager of Test Engineering at Motorola Solutions, walks through the five-agent pipeline he built using MCPs. He uses Cohen's kappa to evaluate multiple LLMs-as-judges and shifts QA left with a specification enrichment stage right after design. The companion code is on his GitHub.

Automation

Lessons Learned From Fixing Flaky Tests With Claude

08 minChrome-Extensionhenrikwarne.com

๐Ÿงช Henrik Warne sped up the 1360 integration tests tenfold, from around 40 minutes to around 4 minutes, then paid for it in flakes. Tests that passed alone started failing in parallel. He is now under one flaky run in ten. Claude helped most by correlating timestamps across log files, not by writing code.

Cypress 15.21.0 Adds a Command That Hands Your Agent the Test Session

09 minChrome-Extensiondocs.cypress.io

โš’๏ธ The new Cypress tap command gives your AI agent direct access to an open Cypress session. It lists running sessions, starts and reruns a spec, reports results, prints a failing test's error and Command Log, and inspects the DOM and accessibility tree. cy.exec() is now deprecated for cy.task().

Deeply Buried 16-Year-Old SQLite Bug Caused Last Year's Tailscale Outages

10 minChrome-Extensiontheregister.com

๐Ÿ› Brandon Vigliarolo of The Register tells a story every tester should keep handy. A data race in SQLite went undetected from July 2010 until Tailscale's backups began detecting corruption in August 2025. Six months of investigation and a purpose-built logging tool later, they found it. Coverage is not correct.

Tools

Go 1.27 Is Released

07 minChrome-Extensiongo.dev

๐Ÿน Nicholas Husin, writing for the Go team, ships two things testers should grab first. The goroutine leak profile in runtime/pprof is now generally available, so permanently blocked goroutines are automatically detected. And httptest gains NewTestServer, an in-memory fake network. Generic methods and encoding/json/v2 land in the same release.

Introducing Delta

08 minChrome-Extensionzed.dev

๐Ÿ”บ Nathan Sobo introduces Delta, which Zed describes as a multiplayer environment for coding with agents and reviewing what they build. DeltaDB replicates the conversation and the worktree together, in real time, capturing every edit between your commits. Teammates who never open Delta still see a normal git repo.

Visual Studio Code 1.134

09 minChrome-Extensioncode.visualstudio.com

๐Ÿงฐ Almost this entire release exists because agent transcripts became unreadable. A prompt timeline puts a dot in the gutter for each prompt and flags which ones changed files. Find in chat searches the whole conversation, including what is not on screen. Side-by-side chat groups let you compare subagent runs.

Video & Podcast

Why IoT Testing Proves Manual Testing Never Died With Oleksii Cherkashyn

10 minChrome-Extensiontestguild.com

๐ŸŽค Joe Colantonio talks with Oleksii Cherkashyn, Quality Assurance Team Lead at Blynk Technologies Inc. He built a custom Node.js library that simulates up to 50,000 device connections, so performance testing never needed the hardware. He also explains why he chose WebdriverIO over Playwright and which IoT cases can never be automated.

How to Stop AI From Ruining Your Codebase

07 minChrome-Extensionyoutube.com

๐ŸŽฅ Emily Bache, on the Modern Software Engineering channel, tackles the technical debt that coding agents quietly pile up. She walks through Habit Hooks, an open-source tool by Ivett ร–rdรถg. It runs your linters in CI, then swaps each rule violation for a coaching note the agent can act on.

Events

TestMu Conf 2026 | Agentic Engineering & QA Summit

08 minChrome-Extensiontestmuai.com

๐ŸŽค Live right now, and Day 3 runs tomorrow. TestMu Conf is free, virtual, and global, with 80 sessions, 100+ speakers, and 75K registrations from 120+ countries. Tomorrow brings keynotes from Replit CTO Luis Hector Chavez and Microsoft's Dona Sarkar, plus live challenges with prizes worth up to $15,000.

STARWEST 2026 | Software Testing Conference

09 minChrome-Extensionstarwest.techwell.com

๐ŸŽค STARWEST runs from 20 to 25 September in Anaheim and online. Early Bird offers up to $200 off, depending on the package, but you must register and remit payment by 21 August. That is tomorrow. Groups save 10% for 3+, 20% for 6+. Keynotes include Filip Hric of Qodo.