Hansi Flick is very happy to welcome Gabriel Jesus to Barcelona – but Julián Álvarez remains the ultimate prize
If Raphinha has any misgivings about playing as a makeshift No 9 for Barcelona, he is doing a good job of hiding it. Julián Álvarez would have been proud of the Brazilian’s two neat finishes that inspired the Spanish champions to a 5-2 victory against Rayo Vallecano on Monday night, 24 hours before the transfer deadline. Lamine Yamal scored two wonderful goals of his own in a performance that reassured everyone he is back to his best. Add Anthony Gordon to the mix – impressive again in his link-up play – and you have a fluid, fearsome front three.
Yet after the departures of Ferran Torres, Robert Lewandowski and Marcus Rashford this summer, there is no doubt Barcelona not only still want a centre-forward but require one – at least one. Hansi Flick was very happy to see Gabriel Jesus, an £8.6m arrival from Arsenal, in the stands. “He’s a top striker,” the coach said. But Atlético Madrid’s Álvarez is the ultimate prize.
Все галочки закрыты, статус в шапке правильный, агент ушёл спать. Наутро я прочитал и отклонил работу целиком. Проверки не было, была формальность: писал и принимал один и тот же агент, по чек-листу, который сам же и закрыл.
В статье собираю гейт, после которого работа не идёт дальше, пока другой агент не написал вердикт в отдельный файл. В одном чате, без оркестратора, за вечер. Цена — 2,7× обращений к модели, ловит примерно каждую шестую работу.
Готового файла роли не даю: он настроен под мои сбои и у вас не сработает. Даю промпты, которыми агент заведёт вам ваши правила, и после каждого строку «что проверяете в ответе».
P.S. Первый же прогон проверяющего отклонил мою работу. Я был зол. Потом открыл его файл вердикта и понял, что он прав.
Video footage has emerged capturing a New South Wales police officer boasting about “punching” a protester in the head “when he was down”, before the protester was charged with assaulting police.
Police body-worn camera footage, which was leaked to a social media account and widely shared over the weekend, reveals a male police officer telling his colleagues during the 9 February protest at Sydney town hall against a visit by the Israeli president, Isaac Herzog: “I fucking pumped that cunt.”
Август — традиционное время затишья перед осенними презентациями, и громких релизов в этом месяце действительно было немного. Зато событий, заставляющих схватиться за голову, хватило с избытком. Модели, вдохновившись июльским инцидентом с Hugging Face, устроили массовый побег из песочниц. Anthropic напугали всех скрытыми вотермарками. А OpenAI и вовсе объявили о приостановке обучения моделей из-за того, что их грядущая модель Astra стала слишком хорошо разбираться в кибератаках.
Конечно, не оставили нас и без новых моделей. GLM-5.3-Flash под маской Ox Alpha навела шороху на OpenRouter. Google выпустили подешевевшую вдвое Gemini 3.7 Flash, а xAI догоняют конкурентов с Grok 4.6.
Собрали всё это воедино, добавили свежих инструментов и приправили выводами из новых исследований. Поехали разбираться, что принес нам конец лета!
The company known for stick vacuums and hair dryers is coming for your teeth. The $499 Dyson CameraJet uses a tiny camera to aim streams of rinsing fluid into the gaps between your teeth.
Сегодня мессенджеры стали одним из основных каналов общения. Но что, если нужно переписываться с корреспондентом, расположенным на расстоянии, измеряемом километрами, а интернет не работает?
Если речь идёт о текстовых сообщениях, помогут каналы связи, созданные с помощью технологии LoRa.
В этой статье мы разберёмся с темой обмена сообщениями через LoRa. Начнём с простого мессенджера, позволяющего обмениваться сообщениями между двумя компьютерами с разъёмами USB под управлением Windows или Linux. Затем перейдём к мессенджеру с микрокомпьютером Raspberry Pi.
В итоге мы создадим несложную mesh-сеть с ретрансляцией по принципу флуда и TTL-ограничением на микроконтроллерах ESP32-S3-N16R8 и модулях LoRa E22-900T22D. Каждый узел этой сети будет поднимать собственную точку доступа Wi-Fi с веб-интерфейсом чата. Для подключения к узлу и обмена сообщениями достаточно обычного смартфона с браузером. В качестве дополнения сделаем так, чтобы в этой сети можно было работать и с компьютера под Windows, к которому подключён LoRa USB-донгл E22-900T22U.
В 2021 году я заимел привычку вести личный бюджет, и тогда же мне пришла идея составить свою продуктовую корзину и самостоятельно отслеживать по ней инфляцию. К моменту создания этой статьи я собрал данные за 5 лет, и вот что у меня получилось.
Стоимость эксперимента с новой технологией продолжает снижаться. Проверить идею сегодня можно за вечер, а отдельную задачу передать ИИ-агенту и получить результат за минуты. Для бизнеса это меняет привычную логику внедрения. Теперь вопрос не только в том, что можно сделать с помощью ИИ, но и в том, как встроить его в рабочие процессы так, чтобы это принесло реальную пользу.
Эту тему подробно разобрали на девятом митапе MWS для ИТ-руководителей. Эксперты обсудили, как компаниям работать с неопределенностью, когда стоит внедрять ИИ-агентов, как сохранить управляемость и перестроить процессы так, чтобы технологическое ускорение действительно приносило бизнес-результат.
Привет! Меня зовут Саша Журавлев. Я венчурный инвестор и основатель фонда. Мы инвестируем в технологические компании на стадиях Seed / Series A в США, а в своем телеграм-канале рассказываю, как вижу рынок и принимаю инвестиционные решения.
Продолжение этой статьи. Досмотрел выступления портфельных компаний Sequoia о том, как они строят внутри себя AI-модели. Понравилось выступление основателя Harvey (AI-компании для юристов) и нарратив из Moneyball, который он продвигал:
Alex Eala has become the Philippines’ biggest sporting star since Manny Pacquiao. Now the 21-year-old’s traveling army of fans have descended on Flushing Meadows
Thecrowd began to swellin Louis Armstrong Stadium a half hour before 2pm. A fair number of fans were probably there to see Taylor Fritz and Terence Atmane practice, but it was the session after theirs that was the headline attraction on the Friday of the US Open’s fan week. The blue, red and white throughout the stands, spotted on bucket hats and posters and basketball jerseys and flags, signaled who these people were here to see.
This has been the year of Alex Eala, the 21-year-old sensation who has taken the tennis world by storm. At No 18, she is the Philippines’ highest-ranked player ever, its biggest sports celebrity since Manny Pacquiao. The country’s president hosted a reception to celebrate her success, and called for a national celebration after she won her first tour-level title last month at the DC Open. Forbes estimates Eala’s off-court earnings for the past year to exceed $5m, plus $1.7m in prize money, and her agent predicts she will be the world’s second-highest-paid female athlete by 2027.
Ten years after taking a knee to stand against racism and police brutality at great cost to his career and finances, Colin Kaepernick is back in the spotlight.
The deluge capped a summer of extreme climate events, from deadly heatwaves to wildfires. We must take action now
For millennia, the high peaks of the Himalayas were held together by an invisible, frozen cement – permafrost and glacial ice that bound ancient rock into seemingly unshakable fortresses. But as the planet continues to warm, this alpine glue is liquefying.
The glacial collapse and deluge in Nepal and Tibet was not a freak weather event; it was the structural failure of a mountain itself, nature’s latest commentary on the deadly consequences of human-caused planetary warming. And it was the exclamation point on a summer of extremes, illustrating with a sole unnatural disaster the apocalyptic future that lies in store if we fail to take dramatic climate action.
It’s a great detection tool, but if your plant is infested with thrips or spider mites it may not be enough …
The problem
The worst pests are the ones you can’t see; thrips and spider mites are tiny and very good at hiding on the undersides of leaves, in leaf joints and along stems. By the time you notice the damage – silvery streaks, speckling or fine webbing – the infestation is usually well under way. Early detection is the difference between a quick fix and a full-blown outbreak.
The hack
Use a sticky lint roller to pick up pests that are hard to see. The idea is it works as both a detection tool, and a light physical intervention, lifting adults and eggs before they multiply.
Last month, Microsoft’s gaming division told its workforce it was cutting 3,200 jobs, which some say will have big ramifications for game development – as well as taking a huge personal toll
On the morning of 6 July, an email went out from Asha Sharma, the chief executive of Xbox, to all of the division’s employees around the world. Under the headline “Resetting Xbox”, it announced the most significant restructuring in the history of Microsoft’s console business: 3,200 staff would be laid off throughout the financial year to 2027, and 1,600 of those roles would be eliminated immediately.
An hour later, at studios throughout company, the Teams meeting invites started arriving. “It was a virtual call with our studio manager,” says Anne Barrett, who was laid off from Bethesda Game Studios Austin. “All of our cameras and microphones were turned off so we weren’t able to say anything or react to anything. We were just brought in, told the news and it was like: ‘You guys are going to lose access to your Slack channel.’ So you saw a flurry of goodbye messages before everything was just shut off.”
It was a bumper season for Hollywood, almost back to pre-pandemic levels, with Tom Holland blockbusters winning out, but there was still a string of disappointments
As the world continued to burn and temperatures reached worrying highs, most of us decided to take refuge in the cinema this summer. It provided some relief for audiences, but even more so for the industry at large, with the season pushing past the magic $4bn mark to become the biggest since 2019, up 20% from last year. There were the expected hits (Spider-Man never misses), but there were also unprecedented breakouts (we were obsessed with Obsession) and surprise underperformers (are kids Minions-ed out?)
So at the end of a season with epic highs and cavernous lows, what lessons can Hollywood learn?
Stephania Messina kept birthing boys. In the Quiverfull conservative Christian church she belonged to outside Detroit, Michigan, that made her a community celebrity. Your quiver, as the church taught it, is your womb, meant to be filled with as many arrows – a metaphor for children – as you can shoot unto the Lord. She shot five. “They treated me like I was Mother Mary, like I was this gift to the church,” she said.
But while she was quickly pushed into leading worship and Bible study groups for women and children, she wasn’t permitted to talk about politics.
Utah District Judge Tony Graf Jr. will hear arguments over evidence introduced in July, to decide if there's enough probable cause for a trial in the shooting of the conservative activist last year.
Spiking prices and rental bidding wars are raising fears of more displacement in a city where previous tech booms and a housing shortage have already driven out many.
A new model in Vermont emphasizes hands-on learning while stripping away frills like gyms and meal plans that increase costs. Other newly created institutions are also reimagining college.
(Image credit: Oliver Parini for The Hechinger Report)
The true cost of "vertical integration": Patients directed to a higher-priced location for procedures. Or forced to buy from their insurer's wholly owned pharmacy, which may not stock the drug prescribed or provide it at the lowest price.
Статья рассчитана на людей, которые планируют ремонт самостоятельно, и дизайнеров, которым приходится размещать сетевые розетки вместе с мебелью и бытовой техникой. Глубокие знания компьютерных сетей не понадобятся. Все основные термины и подключения постараюсь объяснить по ходу статьи.
Всем привет! Меня зовут Кирилл, я сетевой инженер и автор технических статей. Остальные мои материалы можно найти в профиле @ProstoKirReal.
Недавно я почти закончил ремонт в новой квартире. Ремонт я делал не своими руками, но проще от этого не стало. Приходилось следить за каждым этапом, разбираться в строительных материалах и принимать решения в областях, с которыми раньше почти не сталкивался.
Да вообще не сталкивался.
Проект локальной сети я взял на себя. Здесь хотя бы был опыт проектирования и знакомая территория.
Часто компании начинают с одного направления, например, с нормализации данных или внедрения MDM, но впоследствии вынуждены возвращаться к уже выполненным этапам. Причина в отсутствии комплексного плана развития НСИ и понимания оптимальной последовательности работ.
На вебинаре 23 сентября в 11:00 эксперт SOFROS Яна Журавлёва покажет, как определить оптимальную последовательность внедрения решений в зависимости от текущего состояния данных, ИТ‑ландшафта и задач бизнеса.
Мировой рынок нефти сталкивается со всё новыми вызовами. С одной стороны, постоянная эскалация конфликта на Ближнем Востоке приводит к нарушению поставок сырья через Ормузский пролив. Впервые за месяц США и Иран обменялись ударами. С другой стороны, относительная стабильность ОПЕК после недавнего выхода ОАЭ из картеля оказалась под угрозой, и теперь назревает гораздо более масштабный кризис. Власти Венесуэлы прорабатывают сценарий выхода из организации стран-экспортёров нефти ради заключения беспрецедентного стратегического соглашения с США.
Этот разворот стал возможен после радикальной смены политического курса в Каракасе: захват и передача Вашингтону бывшего президента Николаса Мадуро открыли путь к прямому диалогу двух государств. По данным источников, близких к переговорам, ключевым элементом сделки станет долгосрочная аренда США венесуэльских месторождений сроком на 100 лет. Если этот план будет реализован, Венесуэла фактически перейдёт под экономический контроль США. Для самой ОПЕК это грозит потерей одного из исторических столпов-учредителей и перераспределением квот внутри картеля, ставя под сомнение его способность контролировать мировые цены в условиях новой геополитической реальности.
Все самое лучшее от топовых ИИ-разработчиков: нейросети, промты, гайды. Подойдет предпринимателям, разработчикам, создателям контента, и всем кто интересуется нейросетями. Внутри ссылки и описание всех ресурсов, удобная структура. Просто открываете и берете что надо для ваших задач.
Renewed fighting revived concerns the conflict could become more prolonged and further disrupt oil flows through the Persian Gulf, just as supply risks are being compounded elsewhere.
Australia’s two biggest cities had their hottest and equal hottest winters on record, with three eastern states also breaking temperature records.
The Bureau of Meteorology’s (BoM) spring outlook shows above average daytime and night-time temperatures are expected to continue for much of the country, with an increased chance of unusually high maximums.
A decade after Kaepernick’s quiet protest shook the NFL, his exile looks less like an aberration than a blueprint for the culture war that followed
America likes nice round numbers, perfect for anniversaries and reflections, and it has, suddenly, been 10 years since Colin Kaepernick first protested police killings – more accurately, police killings of Black people that went unpunished either internally or by the courts – by taking a knee during the national anthem for the entirety of the 2016 NFL regular season. He never played in the league again.
Ten years covers a lot of ground, especially in these years of American darkness, and many of the important details surrounding Kaepernick, his banishment and significance have disappeared, time replaced by more time and more darkness – time moving faster than ever, at internet speed, where nothing matters, where nothing sticks. We consume by clip, by click, by meme, and knowledge by meme is not knowledge at all.
Donald Trump speaks to the media alongside posters of his proposed White House ballroom amid construction at the White House on May 19, 2026. —Chip Somodevilla—Getty Images
President Donald Trump’s $400 million, 90,000 sq ft White House ballroom is a step closer to becoming reality.
The Supreme Court on Monday allowed Trump to move forward with construction of the ballroom, which had been partially blocked by lower courts. Divided 5-4, the Supreme Court granted an emergency request filed by the Trump Administration earlier in August, staying the lower court rulings.
The legal challenge to the construction, brought by the National Trust for Historic Preservation, argued that Trump did not have the authority to build the ballroom without congressional approval.
The Supreme Court ruled on procedural grounds that the trust likely does not have legal standing to sue. The court did not rule on the legality of the construction.
“Today, we do not pass upon the legality of the government’s East Wing project. We conclude only that, based on the submissions before us, the government is likely to prevail in showing that the Trust lacks ... standing to challenge the project in federal court,” the court said in its ruling.
The decision comes after Chief Justice John Roberts issued a temporary stay on the lower court injunction on Aug. 21, allowing above-ground construction to proceed while the full court deliberated.
Roberts ultimately was the only conservative justice to dissent, arguing that the project was “likely unlawful.”
“The ballroom is a building or structure being erected on federal park grounds—President’s Park—in the District of Columbia. Yet Congress has not passed any law resembling ‘express authority’ for the Executive’s construction of it,” Roberts wrote.
Trump celebrated the legal victory in a Monday post on Truth Social.
“I am pleased to report that the United States Supreme Court has just ruled in favor of the Ballroom/Military Complex being built without any further contingency, doubt, or threat,” Trump wrote. “We are living in the Golden Age of America, and this Building will be one of the Greatest ever constructed in Washington, D.C.”
The President said the ballroom will be completed in the summer of 2028.
The legal battle over Trump’s White House ballroom
The trust filed the lawsuit in December on behalf of one of its members, Alison Hoagland, an architectural historian and preservationist who lives in Washington. Hoagland said in a declaration that she would “suffer both professional and personal injuries, including to my aesthetic, cultural and historical interests, if a ballroom of the proposed form and scale were constructed.” She argued that “an adjacent structure overshadowing the White House, exceeding it in height and massing, would diminish the primacy of the White House.”
The Supreme Court’s majority said the trust likely lacked standing as the court had not previously recognized legal standing “in circumstances like these.”
“To the contrary, we have repeatedly held that mere offense, disagreement, or distaste does not qualify as a concrete and particularized injury,” the court said.
Roberts, in his dissent, wrote that a “historic preservationist such as Hoagland can be aesthetically injured in a concrete, particularized way by the transformation of a historic building that she frequently enjoys.”
The trust also argued that the government needed the “express authority of Congress” to build on federal land in Washington, D.C.
The Justice Department argued that the White House had authority for the construction under other federal statutes. It also argued that the project was necessary for national security reasons, citing an alleged assassination attempt on Trump during the White House Correspondents’ Association dinner in April, as well as other alleged attacks and threats against the President.
“This case involves an extraordinary and unlawful injunction that will halt the ongoing construction of the integrated military complex, including a totally secure ballroom space, at the East Wing of the White House, which is vitally required by national security,” DOJ lawyers argued. The Administration said in its emergency request that construction was 65% complete.
The Supreme Court majority concluded that halting construction at this stage would likely cause “irreparable harm” to the government.
In late March, U.S. District Judge Richard Leon in Washington, D.C., issued a preliminary injunction in favor of the trust, blocking above-ground construction of the ballroom while litigation proceeded. The underground portion of the project, which involved construction of military and medical infrastructure, was allowed to continue, along with above-ground work deemed “strictly necessary” to ensure security.
On Aug. 7, the U.S. Court of Appeals for the District of Columbia Circuit upheld the preliminary injunction, concluding that the Administration could not construct the ballroom during litigation without obtaining congressional approval.
“Each President is a temporary tenant, not the owner, of the White House,” the D.C. Circuit majority said in its ruling.
The trust’s president and CEO Brent Leggs said in a statement on Monday that the organization was “deeply disappointed in the Supreme Court’s ruling.” He noted that “the majority did not weigh in on whether the ballroom project was in fact legal.”
“This is not the final decision on the merits of our case and does not resolve our fundamental argument—that each President is a temporary steward of the People’s House and does not have the unilateral authority to demolish and redesign it without the approval of Congress,” Leggs said.
Construction began last October with the demolition of the East Wing of the White House. Built in 1902 during Theodore Roosevelt’s presidency and expanded in 1942, the East Wing had housed the offices of the first lady and the White House movie theater.
The new ballroom, substantially bigger than the demolished 12,000 sq ft East Wing, is expected to accommodate as many as 999 guests and include missile-resistant columns, drone-resistant ceilings, and ballistic- and blast-proof glass. It also includes an underground complex containing bomb shelters, medical facilities, and other security features.
The Washington Post reported in June that an internal contractor estimate projected a total cost of $600 million, with just over half coming from taxpayer-funded accounts. Democratic lawmakers have also pointed to Office of Management and Budget documents that showed more than $350 million in Secret Service funding reserved for “White House Security Measures,” which the lawmakers alleged were connected to the ballroom project.
There was initially little congressional appetite to authorize the project. But after the April shooting, some congressional Republicans rallied behind the project. Three Republican Senators introduced legislation to authorize $400 million in federal funding for the overall project. Senate Republicans later proposed a separate $1 billion appropriation for broader Secret Service needs, which included security features associated with the project, although the provision was ultimately removed from the legislation before it passed Congress.
Even so, some lawmakers have continued to oppose the construction project. Seven Republicans joined Democrats in June in an unsuccessful bid to bar federal or private funding for the ballroom without congressional authorization.
The Administration said in court filings that a 250-person crew has been working 20 hours a day, seven days a week.
“The Project, despite the baseless lawsuit brought by the so-called National Trust for Historic Preservation of the United States, which is not in any way affiliated with the United States Government, is under budget and ahead of schedule,” Trump wrote on Monday.
Большой каталог сам по себе еще не делает интеграцию сложной. В нашем проекте интеграции сайта с 1С сейчас 211 761 позиция номенклатуры. Передать такой объем можно, вопрос скорее в том, сколько ресурсов и времени на это потребуется. Проблемы начинаются позже: когда данные нужно не просто выгрузить, а отобрать, обработать, регулярно обновлять и доставить в другую систему.
Проект работает на связке 1С:Управление торговлей + интернет-магазин на Bitrix. Источником основных данных остается 1С: там находятся номенклатура, склады, цены и остатки, а сайт в основном работает как витрина. В обратную сторону с сайта в 1С приходят заказы.
Изначально для этой связки использовали типовой обмен. Но проект развивался: появились дополнительные отборы и обработка данных, разные сущности стали требовать разной скорости обновления. В какой-то момент часть данных начала приходить на сайт с задержкой.
Мы не стали переписывать интеграцию целиком. Архитектура менялась постепенно, по мере того как в production проявлялось очередное ограничение. Сначала оказалось, что тяжелая полная выгрузка конкурирует с оперативными изменениями.
Когда их развели по времени, уперлись в скорость обработки на стороне сайта. Когда начали разделять большой обмен на отдельные потоки, нашли bottleneck уже внутри 1С. Позже появились новые потребители данных, 1С:Шина и новый вопрос — как контролировать доставку при асинхронной передаче.
Ниже — этот путь в том порядке, в котором мы его проходили с командой ASAP.
Запрос на дашборд часто начинается со списка показателей и заканчивается красивым отчётом, по которому непонятно, что делать дальше. На примере BI-дашборда для сравнения подразделений разбираю, как перейти от пожеланий к конкретному решению, проверить сопоставимость данных и построить структуру отчёта от отклонения к деталям.
Ниже не попытка восстановить всю работу над проектом по дням, а структура подхода, к которой я пришёл на практике.
UK house prices increased for the first time in four months in August, according to a leading index, as buyers and sellers remained in a “holding pattern” before an expected increase in interest rates later this year.
The average price of a British home rose 0.2% month on month in August to £275,465, the first increase since April, according to Nationwide. Analysts had forecast a 0.1% rise.
Security stepped up in Pattaya before arrival of thousands of sailors and marines whose deployment was extended due to US war in Iran
Authorities in the Thai resort city of Pattaya have stepped up security as they prepare to welcome thousands of sailors and marines from the USS Abraham Lincoln who have spent more than 270 consecutive days at sea.
“About 600 officials will provide security and other necessary assistance,” the provincial governor, Narit Niramaiwong, told AFP.
Разговор о том, кто на самом деле контролирует облако, часто начинается с регионов: где выполняется рабочая нагрузка и где хранятся её данные. Но выбор региона — только часть картины, архитектура платформы значит ровно столько же. Особенно важно, как она разделяет между кластерами ответственность за управление, исполнение, сборку и наблюдаемость.
Недавняя публикация сообщества CNCF, «От резидентности данных к цифровому суверенитету: архитектурные паттерны для cloud native-платформ», хорошо это обосновала. Под такими режимами, как EU Data Act, NIS-2, DORA и UK Data (Use and Access) Act, платформенным командам теперь приходится показывать не только то, где выполняются рабочие нагрузки. Нужно показать и то, как платформу эксплуатируют, защищают и по каким правилам ею распоряжаются, вплоть до плоскости управления.
Та статья изложила требования и представила паттерн «кластер на тенант» как один из способов провести границы изоляции. Команда VK Cloud перевела статью, в которой на те же требования смотрят под другим, но дополняющим углом: что происходит, если считать контроль над платформой свойством топологии её плоскостей. В качестве примера, который можно изучить самому, авторы берут OpenChoreo, внутреннюю open source-платформу разработки и проект CNCF Sandbox. Впрочем, сами архитектурные идеи применимы широко.
Static credentials in CI/CD environments are a significant source of security risks and operational overhead. They can be accidentally leaked through logs and build artifacts. And you can never be sure who’s copying, saving, or sharing them with others during the CI/CD setup process. In addition, they require regular rotation to meet security requirements.
That’s why many services, including major cloud providers, now support authentication with short-lived OIDC identity tokens, allowing CI/CD pipelines to authenticate without storing static credentials.
In this article, we will explain how OIDC authentication works and show how the new TeamCity OIDC JWT plugin enables your build configurations to authenticate securely to AWS, Google Cloud, and other services that support OIDC.
What is OIDC?
OpenID Connect (OIDC) is an authentication standard originally designed to verify user identities. However, many popular cloud providers and services, such as AWS and Google Cloud, use parts of the OIDC specification to authenticate workloads. This article focuses only on those parts.
The authentication flow starts when an identity provider (IdP) issues a cryptographically signed JSON Web Token (JWT) containing information about a workload. Each piece of information in the token is called a claim. Each token contains a validity period, an intended audience (the service or services the token was issued for), and an issuer URL. The issued token can then be presented to a third-party service (such as a cloud provider), which we will refer to as a token consumer.
When a token consumer receives a token, it uses the issuer URL to retrieve the metadata document ({issuer_url}/.well-known/openid-configuration). Among other information, this document includes a link to the issuer’s JSON Web Key Set (JWKS), which contains public keys used to verify token signatures. OIDC issuer URLs must use the https scheme, so the metadata document can only be served over HTTPS. Some consumers also support validation against a preconfigured set of keys instead, in which case the issuer does not need to serve the metadata document over the internet.
After retrieving the public keys, the consumer verifies the token signature against them. If the signature is valid, the consumer checks whether the token was issued for an expected audience and is currently valid (not expired). The validated token’s claims are then used by the consumer to authenticate the workload.
Some consumers accept IdP tokens directly. Others perform atoken exchange and return service-specific temporary credentials for workloads to use.
To enable this authentication method for TeamCity builds, the server needs to act as an identity provider and issue tokens for them.
Introducing the TeamCity OIDC JWT Plugin
The new OIDC JWT plugin adds IdP capabilities required to issue tokens for third-party services that support OIDC, such as AWS and Google Cloud.
The tokens are signed using algorithms based on RSA or ECDSA. Signing keys can be rotated either from the web UI or with an authorized request to an HTTP endpoint. By default, key rotation does not affect running builds or invalidate previously issued tokens.
For publicly accessible TeamCity instances, the plugin provides the .well-known/openid-configuration document and a JWKS with the issuer’s public keys. It also features a configurable issuer URL for instances that are not accessible from the internet,allowing you to host these documents on a public HTTPS host without exposing the TeamCity instance itself.
Finally, the plugin provides an API that allows other plugins to add new ways to sign tokens. By implementing a simple interface, plugin authors can add support for external hardware security modules (HSMs) or other key management services, such as Google Cloud KMS.
The installed and enabled plugin can be configured via Admin | Integrations | OIDC Tokens. You can set the issuer URL (for instances inaccessible from the internet), configure signing settings, and manage signing keys.
Configuration changes may disrupt existing integrations. We recommend configuring the plugin before you set up OIDC for your builds. Once the plugin is configured, you can add build features that provide OIDC tokens.
The OIDC Token (in build parameters) build feature is the easiest way to issue a token. It generates a token at the start of the build and stores it in the specified build parameter. The lifetime of the token is configurable. By default, it equals the build timeout or 10 minutes if no timeout is specified.
The feature allows you to issue a token for one or more audiences. When different services require separate single-audience tokens, add a separate build feature for each token.
With long-running builds, tokens issued at the start of a build may remain valid for longer than necessary. For such builds, there is the OIDC Token (on demand via HTTP request) build feature. It allows build scripts to obtain short-lived tokens during the build with an HTTP request. The lifetime of issued tokens is always 5 minutes and cannot be changed.
The build can then present the issued token directly to the target service or use it as part of that service’s authentication flow.
The correct audience and token lifetime depend on the service you are integrating with. Consult the service’s official documentation for instructions on setting up OIDC authentication. You can also follow the setup guides we have for AWS and Google Cloud.
Learn more
Visit the plugin’s JetBrains Marketplace page for more information:
The public sector handles sensitive citizen data, which is why software projects built with secure coding are imperative to deliver high trust levels. Code compliance with data protection laws, financial governance standards, and various regulations and policies is an obligation that must be consistently met to maintain trust and accountability.
According to IBM’s Cost of a Data Breach Report 2026, the global average cost of a data breach is $4.99 million. That’s a lot of money for any organization in the public sector. Similarly, the Ponemon Institute and Globalscape’s report, The True Cost of Compliance with Data Protection Regulations, determined that the cost of non-compliance is 2.71 times higher than being compliant. Hardcoded credentials or insufficient input/output validation are common, costly issues, often caused by working at speed and incomplete validation checks.
Many issues create compliance problems, and poor code security is one of the biggest risks, which code maintainability can mitigate. Ensuring compliance also helps avoid the costs associated with productivity loss, financial penalties, legal fees, and settlements that can quickly add up after a breach.
Understanding the risks of non-compliance in the public sector when building and updating software and taking steps to ensure code compliance helps avoid financial and reputational damage.
Strict standards apply across public sector software for data protection, security controls, accessibility, and supply chain transparency. Compliance with specific regulations, frameworks, and standards is mandatory, but may vary depending on your location and the applicable policies.
Our cheat sheet helps developers working on public sector software understand potential compliance risks, the considerations to make, and how using a code quality tool can help ensure compliance. It outlines common issues for public sector software, so your development team can review its code quality against each factor before deployment to minimize any risks.
Save time, stay safe, and ensure you’re not breaking any rules.
Compliance Risk
Dev Consideration
Code Quality Tool Use
Non-uniform delivery quality breaches contract standards, resulting in disputes over “whose code failed”
Inconsistent coding standards across contractors and subcontractors
Automatic enforcement of centrally configured quality profiles across all teams
Institutional knowledge loss leading to undetected regressions in critical systems
Dev teams change over long lifecycles, causing quality drift
Baking continuous inspection into the CI/CD pipeline, regardless of who writes the code
Rising maintenance costs and risks breaching long-term supportability commitments in contracts
Unchecked code smells, duplication, and complexity accumulate
Track technical debt metrics on an ongoing basis
Breach of secure development lifecycle mandates with potential data breaches exposing citizen data
Injection flaws, insecure deserialization, and unsafe input handling
Static application security testing (SAST) detects known vulnerability patterns
Violation of identity and access management standards causes a credential leak risk
Hardcoded credentials or secrets in source code
Secret detection built into code scans
Non-compliance with data protection laws (e.g. GDPR), which require appropriate security measures
Weak or outdated cryptography
Flags insecure crypto implementations
Supply chain security failure, which breaches vulnerability management requirements
Vulnerable open-source dependencies
Dependency vulnerability scanning
Breach of procurement restrictions on acceptable licenses that cause IP/legal exposure
License conflicts in dependencies
Automated license compliance checks
Unsupported components in production mean incident response and patching obligations aren’t met
Outdated libraries are no longer supported
Dependency freshness tracking
Failing to produce evidence during compliance audits or contract milestone sign-off
A lack of objective audit evidence for code quality/security
Automated and time-stamped historical reports
Audit findings cite inadequate or inconsistent quality assurance process
Deliverable acceptance criteria breach and contractual SLA non-conformance
Non-compliant code progressing through the pipeline unchecked
Quality gates block merges/releases below the threshold
Business continuity risks during vendor/contractor handover
Inherited/legacy code with unknown risk areas
Complexity and risk for unfamiliar codebases surfacing
A breach of government IT policy restricts external SaaS/cloud dependencies
A need for on-prem/air-gapped tooling
Self-hosted deployment option
Code compliance risk 1: Security and data protection compliance
Failing to comply with security and data protection standards and regulations puts sensitive and personal information at risk of exposure. Public sector software processes large amounts of personal data. Aligning it with applicable security and data protection standards, such as the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, is vital.
Requirements vary by country, too. For example, public sector bodies in EU countries must abide by General Data Protection Regulation (GDPR), a strict data privacy and security law, while UK central government departments and agencies are subject to the National Audit Office (NAO) standards.
US agencies work within Federal Acquisition Regulation (FAR), Defense Federal Acquisition Regulation Supplement (DFARS), and Federal Risk and Authorization Management Program (FedRAMP).
The real-world impact for developers
Developers must build privacy and defense procedures into the software development lifecycle (SDLC) from the start to protect sensitive data. Leaving it too late or considering security too close to testing and deployment can jeopardize privacy protection.
Using weak and outdated cryptography is another compliance risk, as it leaves public sector software vulnerable to attacks. Weak cryptography can also breach controls required under frameworks like ISO/IEC 27001 (Information Security Management), risking loss of certification and reputational damage.
Considering supply chain vulnerabilities and the accountability for personal data handled by third-party vendors is important, too. Third-party dependencies must be treated as active risks. Integrating a code compliance tool like Qodana into the IDE and CI/CD pipeline brings automated SAST checks, secret detection, and cryptography scanning directly into developers’ existing workflow, catching issues before they reach production.
Secure credential storage, explicit user-consent handling, penetration testing before deployment, and ongoing automated testing help with security and data protection compliance. This can ensure public sector software retains NCSC Cyber Essentials certification.
Code compliance risk 2: Contractual and procurement compliance
Public sector software can automate government purchasing and supplier agreements. This improves efficiency but may introduce compliance risks, such as service level agreement (SLA) non-conformance. Failure to comply with an SLA can result in contract termination and financial penalties.
Various regulatory guidelines cover contractual and procurement compliance. These include the FAR in the US and the UK Public Contracts Regulations 2015 (procurement law). Government departments can add specific rules and regulations, like the DFARS and the Cabinet Office Technology Code of Practice.
Potential risks include non-compliant code progressing through the pipeline unchecked, like committing an active API secret key to a feature branch and not running SAST, which can lead to a breach of deliverable acceptance criteria. Vague requirements and missing edge cases may cause this. It may also result in disputes over delivery quality across contractors due to siloed teams.
Open-source dependencies, risks and actions
Open-source dependencies often carry licensing terms too, such as copyleft clauses and commercial-use restrictions. These may conflict with procurement rules on acceptable software. An undetected license conflict can expose the public sector body to IP disputes or breach of contract. Automated license compliance scanning flags these conflicts at the dependency level, before they become a legal problem.
Developers should embed automated quality gates into the CI/CD pipeline, so non-compliant code can’t progress toward a contractual deliverable. This replaces manual sign-off with an objective and repeatable check that provides useful evidence if a dispute over delivery quality arises.
Code compliance risk 3: Audits and accountability
Failing to produce evidence during compliance audits results in unverified controls being treated as non-existent. For public sector software, this can lead to failed certifications and financial penalties. A digital paper trail is essential for objective audit evidence of code quality and security, ensuring accountability.
A reliance on subjective, manual sign-off alongside inconsistent findings from the quality assurance process risks audit failure. Lacking objective audit evidence for code quality and security also exposes public sector software to compliance failure and technical debt. Automated tools can replace subjectivity to help ensure compliance with relevant regulatory guidelines and audits.
The National Institute of Standards and Technology (NIST) provides guidelines for federal information systems and organizations, which apply to some public sector software in the US. There are also audit requirements of ISO/IEC 27001 and the National Audit Office (NAO) standards for public spending accountability in the UK.
Developers must automate audit reports, embedding automated controls within the SDLC to ensure compliance with audits. This also mitigates any risk from manual sign-off. Integrating testing and traceability into CI/CD pipelines creates a digital audit trail to help produce evidence during any compliance audit.
Code compliance risk 4: Long-term supportability and continuity
Public sector software failures can lead to critical citizen service outages. Long-term supportability enables the continuity of such software and the effective application of updates over time to maintain performance and security levels. It also helps compliance with relevant regulations and global standards, such as ISO 22301 (Business Continuity Management System).
Any public sector software that relies on open-source code is also at risk of being built on libraries that become outdated. Incident response and patching obligations won’t be met due to unsupported components. There are also business continuity risks during vendor or contractor handovers, as teams may inherit code with unknown risk areas, where the complexity of an unfamiliar codebase can hide problems until it’s too late.
Prioritizing quick fixes can create technical debt and breach long-term maintenance commitments. A short-term patch that isn’t built for long-term support often needs revisiting later. That future fix is usually costlier and more time-consuming than doing it properly the first time.
Developers should implement dependency freshness tracking to identify and use the latest stable version or patch release. This minimizes potential security risks due to using outdated libraries and ensures public sector software is up-to-date.
Keeping the number of external dependencies to a minimum also makes long-term supportability easier. Automated unit and integration tests help catch bugs before deployment, while static code analysis catches code errors early, making it easier to address them and ensure long-term supportability.
Code compliance risk 5: IT governance and infrastructure policy
Public sector software must meet security baselines and comply with various regulatory guidelines for IT governance. For example, the UK’s Government Cloud First policy ensures public sector organizations use public cloud services as the default when procuring new or existing IT and software solutions.
Government IT policy often restricts the use of external SaaS or cloud dependencies. Using non-compliant tooling puts sensitive public sector data at risk. This can violate FedRAMP (Federal Risk and Authorization Management Program), a standardized approach based on NIST guidelines that ensures cloud providers meet strict federal data protection rules.
IT infrastructure is also at risk of erosion due to institutional knowledge loss linked to the governance of long-running systems. When developers and staff leave without documenting context, workarounds, and the rationale for decisions, it can make understanding and maintaining the infrastructure difficult.
Digital audit trails
A digital audit trail helps with ongoing infrastructure maintenance. Development teams can also consider on-premises and air-gapped tooling as a self-hosted deployment option for better code compliance.
These secure systems require no external cloud dependencies. Embedding automated guardrails into the SDLC helps achieve compliance through continuous scanning and policy-as-code.
Discover more about using Qodana for DevOps to help ensure code compliance in public sector software projects or try Qodana for 30 days.
As part of the deal, the U.S. is creating a private company as a joint venture with North American Blue Energy Partners, owned by Venezuelan businessman Alejandro Betancourt.
Однажды вечером я, как обычно, листал ленту одного синего маркетплейса и случайно наткнулся на электронный замок со сканером отпечатка пальца. По описанию — почти идеальное устройство за небольшие деньги: биометрия, защита от воды, какая-то «уникальная» микросхема. Звучит убедительно, но исследователь на то и исследователь, чтобы не принимать рекламные обещания на веру, а потому уже на следующий день замок лежал у меня на столе. Ну, а дальше сработал знакомый принцип: где один интересный девайс, там быстро появляется пара других…
Меня зовут Астафиев Денис, я ведущий специалист по аппаратным исследованиям в Бастионе. По работе я регулярно разбираю самые разные устройства, чтобы проверить, насколько можно доверять тому, что производитель обещает на коробке. Сегодня будем смотреть сразу на три замка с биометрией и искать слабые места в их защите.
Сразу оговорюсь: цель этой статьи — не любой ценой «дожать» дешевый китайский замок до уровня лабораторного исследования. Наоборот, мне хочется на простом и доступном примере показать, как обычно строится базовый аудит аппаратной безопасности и почему начинать его стоит совсем не с самых сложных атак.