‘Godzilla’ event currently brewing could push 50 million people into acute hunger before the end of next year
A series of strong El Niño climatic patterns in recent decades, such as the “Godzilla” event currently brewing that is set to warp weather around the world, have been supercharged by the broader overheating of the planet caused by the burning of fossil fuels, a major new study has found.
El Niño is a naturally occurring phenomenon, taking place every two to seven years, when the waters of the eastern tropical Pacific Ocean heat up, causing a cascade of impacts around the world. The latest developing El Niño, set to peak later this year, is set to be the strongest in living memory and has been informally dubbed a “Godzilla” event.
The devastating flash flood that has ripped through the border communities of Nepal and Tibet has heightened fears that the climate crisis is destabilising the geology of mountain and polar regions, threatening millions of people.
Satellite imagery suggests a glacier collapse high in the Himalayas was the primary cause of the deadly torrent of mud, water and ice that tore along the Bhotekoshi River on Wednesday. It swept away buildings and roads and left at least 360 dead and 1,400 missing.
President Donald Trump on Thursday signed an Executive Order instructing Interior Secretary Doug Burgum to rename Lake Ontario as “Lake America.”
President Donald Trump on Thursday signed an Executive Order instructing Interior Secretary Doug Burgum to rename Lake Ontario as “Lake America.”
The change is set to take effect immediately, he said. Trump earlier in the week had floated the idea of a new moniker for the lake, which borders the Canadian province of Ontario and the U.S. state of New York.
Trump signed a similar order upon returning to the White House last year, renaming the Gulf of Mexico as the "Gulf of America."
This most recent name change is the latest in a series of tit-for-tat measures amid an all-out trade war between the U.S. and Canada.
British Columbia’s Premier David Eby on Tuesday called for residents not to travel to America unless it's absolutely essential.
“I’m asking British Columbians: If you have a choice, please don’t travel to the United States. Choose another place to do your tourism,” Eby said at a press briefing. “If you can choose a Canadian product, instead of an American one, please choose it… by being our own best customer, we can help respond and support Canadians in every corner of this amazing country.”
While Eby is leading the charge on a travel boycott from the Canadian province, other lawmakers are further clamping down on a boycott of U.S. products.
“When you’re at war, you protect your own, you protect your own backyard,” said Ontario Premier Doug Ford on Wednesday. “You don’t go down to the U.S. and buy a product. There’s nothing that we can’t make here in Ontario, or across the country.”
Finance Minister François-Philippe Champagne expressed a similar sentiment, telling reporters: “The biggest power we have, each and every one of us, is our purchasing power. We can choose when we go to the grocery store or to the hardware store to buy Canadian.”
Has Canadian travel to the U.S. declined since Trump returned to office?
Prior to Eby’s tourism plea, Canadian travel to the U.S. had shown a jump in visitors after a widely-reported decline.
In May, the number of Canadians visiting the U.S. was up by 9.9% compared to the same month a year prior, according to Statistics Canada. In June, the number of Canadian-resident return trips from the United States increased 5.0% year over year. The number of Americans visiting Canada was also higher, with a 6.1% rise year over year.
However, in the first quarter of 2026, Canadian residents took 5.5 million trips that included an outbound visit to the United States, a year over year decline of 10.6%. Spending while visiting the U.S. by Canadians during this period was also down by 13.6%.
Figures for the start of 2026 fall in line with a trend that has seen Canadian travel to the U.S. decline since Trump returned to Office last year.
Cell phone data analysis published by the University of Toronto in May found a 42% year-over-year median decline in Canadian travel to U.S. metropolitan areas.
The research also found that “when Canadians travel to the U.S., they are visiting fewer locations and staying for less time than they used to.”
Some metro areas such as Myrtle Beach, South Carolina, and Panama City, Florida, saw drops in Canadian tourism of at least 60%. In Florida, the decline in visits has persisted with an average decrease of just under 14% across the state during the first six months of 2026.
How U.S.-Canada talks collapsed into an all-out trade war
Relations between the U.S. and Canada have deteriorated further since the collapse of high-stakes trade talks last week resulted in U.S. tariffs of 50% on various Canadian products going into effect on Aug. 22, with no CUSMA exception.
In response, Canada has imposed retaliatory tariffs of up to 50% on certain U.S. goods.
Trump has threatened to increase automobile tariffs on Canada to 50%, claiming: We don’t need Canada, they need us.”
The Trump Administration has also revived its rhetoric of referring to Canada as a “state”—a nod to Trump’s vocal ambition to annex Canada and make it the 51st state, an idea he has floated repeatedly since returning to the White House last year.
Vice President J.D. Vance during a speech in Brewer, Maine, on Monday said: “We have to remember, Canada is a state—sorry, Freudian slip.”
Canadian Prime Minister Mark Carney, meanwhile, has drawn focus to Canada’s burgeoning trade relations with other countries.
“Over the last year alone, Canada has signed more than 20 trade and security deals across five continents,” he said Wednesday. “Canada is now the best connected economy in the world,” he claimed, pointing towards trade alliances with countries in South Asia and Europe.
Carney in January met with China’s President Xi Jinping to forge what he called a “new strategic partnership” to end Canada's economic reliance on the American market. While meeting with Canada’s second-largest export market, Carney agreed to cut his country’s 100% tariff on Chinese electric cars in return for lower tariffs on Canadian farm products, including canola seeds, a major Canadian export.
After an affair with a fellow police officer ended, a Georgia cop used Flock to track her movements—and those of a man whose vehicle often showed up near hers, internal investigation records show.
‘Godzilla’ event currently brewing could push 50 million people into acute hunger before the end of next year
A series of strong El Niño climatic patterns in recent decades, such as the “Godzilla” event currently brewing that is set to warp weather around the world, have been supercharged by the broader overheating of the planet caused by the burning of fossil fuels, a major new study has found.
El Niño is a naturally occurring phenomenon, taking place every two to seven years, when the waters of the eastern tropical Pacific Ocean heat up, causing a cascade of impacts around the world. The latest developing El Niño, set to peak later this year, is set to be the strongest in living memory and has been informally dubbed a “Godzilla” event.
A jury is deliberating in the trial of Lindsay Clancy, a Massachusetts woman who killed her three children in 2023. Her defense attorney claims she was suffering from postpartum psychosis and should not be held criminally responsible. Prosecutors say she planned the killings and faked a suicide attempt that left her paralyzed from the waist down. CBS News' Shanelle Kaul has been covering the weekslong trial and shares the key moments.
Hi, this is Gergely with a bonus, free issue of the Pragmatic Engineer Newsletter. In every issue, I cover Big Tech and startups through the lens of senior engineers and engineering leaders. Today, we cover one out of four topics from last week’s The Pulse issue. Full subscribers received the article below seven days ago. If you’ve been forwarded this email, you can subscribe here.
OpenAI put an impressive-sounding case study about how they helped Asana save $5.9M with a single migration. From OpenAI (emphasis mine.)
“Asana cleared 5 years of engineering work in 2 weeks with Codex. Using OpenAI Codex, Asana replaced an outdated testing system in two weeks for about $12K.
For this project, Codex helped Asana’s engineers remove Enzyme, an outdated testing system that had made the company’s code harder to upgrade. Model and infrastructure costs came to about $12,000, compared with Asana’s roughly $6 million estimate for the previous staffing plan.
After 1.5 weeks of engineering effort spread across two calendar weeks, Enzyme was fully removed. Model and infrastructure costs totaled about $12K. For comparison: the previous plan was expected to take at least five years and estimated to cost roughly $6M. The experience changed which long-running software projects the company believes are practical to take on.”
For context, Asana migrated from Enzyme to React Testing Library, which indeed would not be a simple migration. However, their estimate of four engineers (each on circa $300K/year, according to OpenAI’s arithmetic), spending five years on the project, had me like:
But thinking about this for longer raised the question: what does a migration from Enzyme to React Testing Library even look like?
Enzyme to React Testing Library migration
Let’s take a simple test and see how it looks in various testing libraries.
For our test, we want to verify that a button increments a counter. Here’s our button in React:
Our button that increments its counter
Now, the test to verify this, in Enzyme:
The unit test in Enzyme
And let’s rewrite this test in React Testing Library:
The unit test in React Testing Library
The two tests do the same, but they have completely different syntax! Let’s see just how different they are, with a side-by-side comparison:
Two very different files: the only code in common is the imports
The main reason for this difference is that the two frameworks use a fundamentally different approach to testing. Whereas Enzyme is oriented towards component testing (notice how the test operates on a component instance), the React Testing Library operates on the rendered Document Object Model (a data structure representing the HTML shipped to the client) so the test sees the whole rendered page, not just the component its written for. That’s why the testing approach will differ radically between the two frameworks, especially when testing complex user journeys. You can learn more here on the tradeoffs between the two approaches from the React Testing Library author.
It took Airbnb 6 weeks to migrate 3,500 tests with AI
Last year, Airbnb revealed how they migrated their Enzyme test suite of 3,500 component test files within six weeks with LLMs. The estimate of doing this by hand was 1.5 engineering years. Airbnb did the LLM-aided migration in a multi-phase process:
Five phases of the migration, for each file. Source: Airbnb
Airbnb’s team had to build loops to keep retrying migrations; once they did, 75% of files were migrated in just four hours, and the migrations were straightforward. They then built a more sophisticated refactor pipeline for the remaining 25% of tests; after building the pipeline, the new loop migrated most of the remaining tests (97%) in total, after running over 4 days. The remaining 3% was done with LLM input, with engineers finishing it in a week.
This was in March 2025, when the frontier coding model was Claude 3.7 Sonnet. Today, models are a lot more capable, such as the likes of GPT-5.6 Sol and Claude Fable 5.
AI makes impractical migrations doable
On the basis that it took Airbnb six weeks, I find it credible that it took Asana two weeks to migrate what is probably a similarly complex test infrastructure from Enzyme to RTL, a year later.
The time and $6M cost as quoted by OpenAI feels inflated. I assume the numbers were based on an estimate that a fulltime engineer could do a maximum of X tests migrated per day, where X was between 5 and 10. Then, calculate the number of engineering years this takes (perhaps 20 engineering years), and multiply by the cost of an engineer. You estimate a project like this when it’s an undesirable project you really don’t want to do as an engineer!
So, looking at it from this point of view: does it matter if the estimate was 1.5 years (Airbnb) or half a decade (Asana, hypothetically)? Or if the estimated cost was $1M or $5M? It would still be an impractical migration and a foolish endeavor: too long and distracting, at least, in the “traditional” way!
Pre-AI, years-long migrations were rare. In 2021, Sentry took 1.5 years to convert their frontend codebase from JavaScript to TypeScript. That was a migration of 1,100 files and 95,000 lines of code! Around 10 engineers worked on the migration, so if we assume a $300K-per-engineer cost, that’s a $2–4M cost for circa 95,000 lines of code.
Indeed, Asana’s reported $12,000 migration cost could actually cost even less if there was ruthless focus on cost optimization. What about using a model that’s 10x cheaper than OpenAI, like an open model running on inference providers? After all, why use the most expensive model, especially if a company already owns GPUs, running models, making inference practically free (except for power costs, that is.) For a first run, $12,000 would be affordable for a company paying $300K for engineers. But for subsequent runs, I’d wager it’s worth spending time optimizing the cost, and saving $10K per migration (or more!)
A few more details from inside Asana
I managed to catch up with Dan Ubilla at Asana, who leads the Developer Productivity group at the company. He helpfully clarified a few things about the Enzyme migration post on the Asana site:
Asana started the Enzyme migration in 2024. The team had 4,000+ Enzyme files to migrate, and they took a first stab at the migration with LLMs, at the time. Beyond migrating existing tests, much of this phase focused on getting the codebase into a state where future tests could be written more idiomatically. This included improving mocking, data set up, and coverage instrumentation. They finished migrating about 25% of the files to RTL, choosing the tests that had the highest return on investment: meaning easiest to migrate, or most frequently updated ones.
The remainder of the migration became low priority. Asana prioritized migrations as critical (“must do soon”), important (“important to do soon”), and opportunistic (“nice to have”). The company has a good number of critical and important migrations, and the remainder of the Enzyme migration sat as one of the many opportunistic.
Five years was about when the migration was projected to finish. The effort was not about “a team working for five years, nonstop on the project” – not at all! It was about the timeframe that the opportunistic Enzyme migration would have been completed, given its priority, and done, realistically. Given this migration was going on for two years, the five-year estimate was a rational one.
The team wanted to prove that LLMs drastically speed up migrations, and demonstrated it with an opportunistic , low-priority one. The Enzyme migration was not all that important to do quickly, and would have sat around for years. So it was the perfect candidate to prove that with LLMs, long migrations can be sped up!
And finally, one addition from my end:
The $6M cost was a back-of-the envelope estimation. I asked Dan how this estimate of the migration costing $6M came together. Dan confirmed that the estimation was done the same way as most of us do these estimations:
Estimate how long it takes an engineer to manually migrate a single Enzyme file (including rewrite + validation). Be generous with this estimation
Multiply it by the outstanding files to migrate (the 3,000+ ones)
Add in the time to remove any traces of the framework, monitoring, static analysis tools
Multiply by the hourly rate of a typical engineer
… and the number came out to $6M
This estimation does not take into account that migrating even ten files by hand takes less than ten times more than it takes to migrate one file (you become more efficient), nor does it assume LLM usage. It’s a baseline to get a sense of how the work would have been done, pre-AI, if distributed across all Asan engineers to pick up, and migrate few files, whenever they have time. My take is that this number is probably an overestimation, but the point is less about the number, and more to convey that this is a lot of work!
Internally, Asana’s team and leadership are now convinced about the usefulness of LLMs for migrations, and they’ll be using them for other, long-running, otherwise soul-sucking migrations.
Expect long-avoided migrations to finally happen
A few months ago, Uber shared that they executed a massive JUnit migration in four months with two engineers and AI: moving 600,000 unit tests spanning 15 million lines of code (!!) by moving from the unsupported JUnit 4 to JUnit 5. During the migration, 1.25M lines of code were modified. This type of migration used to be impractical; with AI tools, it took eight engineering months of effort, plus AI costs.
And there’s the Bun migration (530,000 lines of code from Zig to Rust in two weeks for a $165K API cost) as another example of drastically faster migrations with AI.
The best part about rapid, AI-assisted migrations is not needing to worry about supporting “old” libraries. One of the main reasons library migrations have been such a pain was the need to keep supporting the old library or technology during the migration. Shortening this window could well be worth the additional cost, at least until we figure out how to drastically reduce the time and cost of these migrations, as well.
The shared characteristic of all of the above migrations is that engineers needed to plan for it, design verification loops, and be involved throughout. I always dreaded migrations, so I see it as good news that we have a new tool to use for “grunt work” like this.
Did Meta really decide to reduce team sizes by 60% because of AI? An in-depth report by Reuters details how Meta’s leadership decided to slash team sizes by 60%, hatching plans in January to execute the social media giant’s largest-ever layoffs. But Mark Zuckerberg changed his mind at the last second, and now the company is stuck with all-time low morale, a wave of resignations, and its prized culture turning mercenary. Analysis.
More thoughts on Ramp’s in-house AI infra. Building AI tools in-house is akin to an “internal bootcamp” for AI engineering, which probably justifies the exercise at most tech companies.
Industry Pulse. GitHub’s load increase is speeding up, Stripe acquires OpenRouter, Ramp launches Ramp Router in public, a career “double boomerang”, App Store revenue drops for the first time ever at Apple – and what is a bug?
Donald Trump signed an executive order on Thursday directing the federal government to rename Lake Ontario, making it Lake America, amid his escalating trade war with Canada.
The order directs federal agencies to adopt the name-change on US maps, documents and databases. But Trump has no authority to rename Canada’s portion of the lake, nor to compel Canada, international legal bodies, international mapmakers or the rest of the world to adopt a new name.
European champions Paris St-Germain will face Premier League duo Manchester City and Aston Villa in the league phase of this season's Champions League.
The deadly flash flood in Nepal was likely caused by a huge chunk of a glacier that broke off and temporarily dammed a river, according to preliminary investigations by scientists.
Attorneys for Andrew and Tristan Tate, the “manosphere” influencers accused of sex crimes in the United Kingdom, fought for their freedom on Thursday, telling a federal judge that the defendants are not a flight risk.
Jamie Smith and Jordan Cox battle difficult conditions and an improved Pakistan performance to take England to a competitive total on the opening day of the second Test.
В первой части мы успешно вскрыли чёрный ящик LINQ: написали Where вручную, разобрались, как компилятор превращает yield return в конечные автоматы, и посмотрели на методы с частичной буферизацией. Но LINQ был бы не собой, если бы на этом всё закончилось.
Во второй части переходим к «тяжёлой артиллерии» — OrderBy, GroupBy и Join. Эти методы вынуждены нарушить главный завет ленивых вычислений: они материализуют данные в памяти, прежде чем отдать хоть один элемент. Но как именно?
После этой статьи LINQ перестанет быть чёрным ящиком: вы будете точно понимать, сколько памяти съест каждая цепочка методов и в каком порядке следует вызывать эту цепочку.
Arsenal face mouthwatering assignments against Real Madrid and Bayern Munich as they bid to go one better than last season’s agonising near miss and win a first Champions League title.
Medicine, food and other supplies are the urgent priority. But the rising risks from shrinking glaciers must be faced too
Thousands of people in Nepal and Tibet are in desperate need of emergency assistance following Wednesday’s disaster. With 360 people confirmed dead, more than 1,300 others are still missing as search and rescue operations continue. The precise sequence of events linking glacier collapse to flash floods is yet to be confirmed. But there is no doubting the enormous destructive power of the brown torrent that can be seen on video clips surging down the steeply sided Himalayan valleys, sweeping away everyone and everything in its path.
Testimony from survivors about terrifying near-escapes and losses is reminiscent of previous disasters, including the 2004 tsunami. With some of the worst-affected areas still cut off and accessible only by helicopter, there is a high level of uncertainty about the total number of people who have died or homes that have been destroyed. Existing medical, food, shelter and sanitation supplies will need to be replenished. Pledges of help for locally led relief efforts from foreign governments and agencies, following reports that hundreds of those missing were tourists or pilgrims, must lead to swift action. People need basics including electricity and clean water before they can start to rebuild and recover.
Do you have an opinion on the issues raised in this article? If you would like to submit a response of up to 300 words by email to be considered for publication in our letters section, please click here.
President Trump on Thursday signed an executive order to rename Lake Ontario to "Lake America." The move comes as the trade war between Canada and the U.S. escalates.
The jury has begun deliberations in Lindsay Clancy's trial for the killings of her three children. Clancy has admitted to killing the kids, but has pleaded not guilty to murder charges, arguing she was overmedicated and suffering from postpartum psychosis. CBS News' Shanelle Kaul, Katrina Kaufman and Rebecca Roiphe have the latest.
The executive order directs the Interior Department to update the Geographic Names Information System, changing the name of Lake Ontario to Lake America.
Compliance is the part of software delivery that everyone agrees is important, yet nobody enjoys. It
often lives in spreadsheets, screenshots, and the quiet dread of an upcoming audit. GitLab's custom
compliance frameworks work differently. Instead of documenting what should be true about your
projects, you define the controls once and let the platform continuously verify what is true.
In this article, you'll learn why compliance adherence matters, how to stand up a SOC 2 framework in
minutes using a template, how to monitor adherence on an ongoing basis, how to enforce compliance
with policies, and which standards already ship as ready-to-use templates. You'll also get a look at
where AI-specific compliance templates are heading. You can watch the video below to see it in
action:
Tier note: Compliance frameworks are available in Premium and Ultimate. Framework
requirements and controls, the checks that power adherence reporting and the compliance status
report, require Ultimate. Everything here applies to GitLab.com, GitLab Self-Managed, and GitLab Dedicated.
Why compliance adherence matters and how custom frameworks help
Regulatory and contractual obligations like SOC 2, ISO 27001, PCI DSS, and
FedRAMP exist because customers,
partners, and regulators need assurance that your software is built and shipped responsibly. Falling
short isn't just a paperwork problem. It can block deals, trigger fines, delay product launches, and
erode trust. Compliance also isn't a one-time event. A project that was compliant at audit time can
drift the moment someone disables a scanner, removes branch protection, or merges without the
required approvals.
Custom compliance frameworks are designed to close that gap. A compliance framework in GitLab is a
label you create on a top-level group to identify projects that carry specific compliance obligations or need extra oversight. On its own that label provides organization and visibility. In
Ultimate, a framework can also carry requirements made up of controls, which are automated
checks against the configuration and behavior of every project the framework is applied to.
Instead of asking an engineer to confirm that static application security testing (SAST) is running, that the default branch is protected, and that merge requests need two approvals, GitLab evaluates those conditions for you on a schedule
and whenever relevant project settings change. Compliance stops being a snapshot you assemble before
an audit and becomes something you can watch year-round. Frameworks are created on the top-level
group and inherited by all subgroups and projects beneath it. You can apply up to 20 frameworks to a
single project when it needs to satisfy several standards at once.
This changes the day-to-day effort in a few ways. Compliance moves left into the development
workflow, audit preparation becomes a matter of exporting a report rather than reconstructing
evidence, and consistency is enforced by the platform rather than by good intentions.
Applying a template to adhere to SOC 2
Building a framework by hand means defining every requirement and every control one at a time. For a
standard like SOC 2 that maps to many controls, that's repetitive and error-prone. Templates solve
this by giving you a complete, predefined framework, with the name, description, color,
requirements, and controls all configured, and that you can adopt in a single step.
In the sidetab, select Secure > Compliance center.
Click the New framework button.
Choose Create from template.
Scroll down to the SOC 2 template, and select View details to see the controls the
template implements.
Press the Use template button to implement the SOC 2 template. customize the name,
description, and color if you'd like. Select Next when complete.
Preview the included requirements and controls.
Apply the framework to the groups/projects that require it.
Press the Create framework button.
Your framework is created and will be applied to the groups/projects you selected.
Option B: Import the SOC 2 JSON template
If you're on a GitLab version without the in-product template picker, or you want to keep the
template under version control and tweak it first, import the JSON directly:
On the Frameworks tab, select New framework, then Import framework.
Choose the soc2.json file from your local system.
When the import succeeds, the SOC 2 framework appears in your frameworks list.
A framework only does something once it's attached to projects. Make sure you apply this
framework to the groups/projects where it will be used.
Note: Imports fail with an Unable to determine the correct upload URL error if a framework with the same name already exists. Rename or remove the existing one first.
Edit and apply the framework to your projects
You can also edit the newly created framework as well as apply it to
additional groups/projects:
In Secure > Compliance center, open the Frameworks tab.
Hover over the SOC 2 framework and select Edit Framework.
In the Requirements & Controls section, under Action, select the ... > Edit.
Perform any necessary changes to the requirements or controls.
In the Scoping section, select the groups/projects that fall under SOC 2.
Select Update Framework.
If you want every new project in the group to inherit SOC 2 automatically, set the framework as the
group default in the Basic information section. The framework will then be applied to all
newly created and imported projects going forward.
What the SOC 2 template actually checks
Once applied, the SOC 2 framework maps GitLab controls to the relevant Trust Services Criteria. A
few highlights:
SOC 2 criterion
What it covers
GitLab controls applied
CC3.2
Identifying vulnerabilities in system components
Dependency scanning, container scanning, DAST, API security running
CC5.1
Segregation of duties
At least two approvals; author and committer approvals forbidden; approval rules locked from editing
CC6.6
Protecting authentication credentials in transit
Secret detection running
CC6.8
Detecting unauthorized or malicious software changes
Default branch protected
CC7.1
Detecting new vulnerabilities through scanning
Dependency, container, SAST, DAST, and API security scanning running
CC8.1
Authorizing, testing, and approving changes
SAST, DAST, secret detection running; default branch protected; at least two approvals
After the framework is applied to a project, GitLab runs a compliance scan and begins reporting on
whether each control passes. No manual evidence gathering required.
Continuously viewing compliance status
Applying a framework is only half the value. The other half is knowing, at any moment, where you
stand. That's the job of the compliance status report (Ultimate), found in your top-level group
under Secure > Compliance center > Status.
The report surfaces the most recent instances where projects do and do not adhere to a
framework's controls, so you can spot and close gaps fast. Each row tells you:
Status: whether a requirement is in or out of compliance
Requirement: the specific controls in a requirement that failed (for example, "At least two
approvals")
Framework: which framework the control belongs to (for example, SOC 2)
Project: where the non-adherence was found
Last Scanned: when the gap was first recorded
Fix Suggestions: information on how to resolve the issue
You can filter by project, framework, or requirement, jump straight into a project's compliance
detail view, and export the whole report (delivered to your inbox as an attachment) when an auditor
asks for evidence.
Behind the scenes, scans that refresh the report are triggered automatically when a framework is
added to a project, when an associated framework's requirements change, and on a recurring 12-hour
schedule. Results typically appear five to ten minutes after a scan runs. This means compliance
drift becomes visible within hours rather than at the next annual audit. To view the report, you'll
need to be an administrator, or have the Security Manager or Owner role for the group.
Adhering to compliance via policies
Reporting tells you when something is wrong. Policies stop the wrong thing from happening in the
first place. This is where compliance frameworks move from observation to enforcement, and it's an
Ultimate capability tied to the framework label.
A compliance framework can act as the scope for Security
policies. Scan execution policies,
Pipeline execution policies, and merge request approval policies can be scoped to a compliance
framework, so every project carrying that label automatically inherits them. For example, you can
require that SAST, secret detection, and dependency scanning run on the default branch, and require
approval from a designated security team before a merge request that introduces new critical
vulnerabilities can be merged. Because the policy is bound to the framework rather than to
individual projects, adding a new project to the framework instantly brings it under the same
guardrails.
The pieces work together. The framework defines the obligation, controls and the status
report measure adherence, and policies and compliance pipelines enforce the behavior. You're
not just documenting that SOC 2 requires two approvals and running scanners. You're making it
difficult to ship anything that violates those requirements. When a control fails, the status report
flags it. When a policy is in place, the non-compliant change is blocked before it merges.
Available templates
GitLab ships a growing library of predefined framework templates in the Compliance Adherence
Templates
project,
each mapping a recognized standard to GitLab controls. As of publication, these include:
Each template's exact requirement-to-control mapping is documented in the compliance
standards
reference. You can import any of them as-is, or use them as a starting point. Export a framework as
JSON, adjust the requirements and controls to match your organization's interpretation of a
standard, and re-import. The JSON schema is straightforward. A framework has a name,
description, color, and an array of requirements, each with its own controls and evaluation
expression. That makes templates easy to keep in version control and share across groups.
A look ahead: AI-specific compliance templates
The compliance standards covered today were largely written for traditional software. As
organizations embed AI into their products and their own development workflows, a new class of
obligations is emerging around governing how AI systems are built, approved, and monitored. Examples
include the EU AI Act, ISO/IEC 42001, and the NIST AI Risk Management Framework.
GitLab is exploring AI governance compliance templates (Epic
#16808, with planning tracked in Work item
#22336) to extend the same template-driven
model into this space. The intent is to let teams adopt an AI-governance framework as easily as they
adopt SOC 2 today, with predefined requirements and controls that map to AI-specific obligations,
applied to the projects that build or deploy AI capabilities, and surfaced through the same
compliance status report.
It's worth keeping one distinction in mind. Compliance is the state of meeting a defined set of
requirements, while governance is the ongoing capability to keep AI systems compliant as both
the systems and the rules evolve. GitLab's broader direction pairs AI-assisted detection with
human-in-the-loop approval and auditable, policy-based enforcement, so AI findings inform decisions
but accountable humans and measurable controls still gate what ships. AI-specific templates would be
the onramp, giving you a fast way to encode emerging AI requirements into the same framework,
control, status report, and policy machinery you're already using for everything else.
Summary
Custom compliance frameworks let you define your obligations once and have GitLab continuously
verify them. Templates take the manual setup out of getting started, so a SOC 2 framework is a few
clicks or a single JSON import away. The compliance status report keeps adherence visible on a
12-hour cadence, and security policies plus compliance pipelines turn that visibility into
enforcement. With a library of standards already available and AI-specific templates on the horizon,
the path from "we should be compliant" to "we can prove we are, continuously" is shorter than it's
ever been.
This blog post contains "forward‑looking statements" within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934. Although we believe that the expectations reflected in these statements are reasonable, they are subject to known and unknown risks, uncertainties, assumptions and other factors that may cause actual results or outcomes to differ materially. Further information on these risks and other factors is included under the caption "Risk Factors" in our filings with the SEC. We do not undertake any obligation to update or revise these statements after the date of this blog post, except as required by law.
Some of the world's largest tech companies and AI startups have come together to decry the current state of cybersecurity and to advertise a new solution that they say can ward off a new generation of cyber threats.
В последние 5 лет, мы разрабатываем устройства с уровнем функциональной безпосности SIL3 (в части встроенного ПО). Это накаладывает кучу ограничений, например, абсолютно запрет на использование не сертифицированных по функциональной безопасности средст, типа Cube, или компилятров GNU и Clang, только сертифицированные средства типа IAR Workbench Function Safety.
Соотвественно для того, чтобы получить как можно больше баллов по функциональной безопасности необходимо иметь как можно больше диагностик, в том числе и диагности CPU. Сами писать диагностику CPU дело довольно трудемкое, поэтому мы используем сертифицированные библиотеки от производителя.
С развалом началом перестройки, для предпринимателей всех мастей открылся настоящий Клондайк. Перед ними были огромные пустые рынки с миллионами "голодных покупателей". В том числе и рынки настольных игр. Что официально выходило в СССР? В основном всякие "ходилки", да книги с головоломками. Придумать свою игру сложно, а придумать и "отладить" ее еще сложнее. Так появился целый пласт ворованных и адаптированных игр. Вся огромная армия разношерстных "бизнес", "коммерсант" и прочих клонов Монополии как раз туда. Но были и более редкие экземпаляры, клоны других игр. Клоны настольного Риск, например. Или клон немецкой игры 1986-го года - "Сумасшедший лабиринт". Про него в этой статье и пойдет речь.
Про игру Цена риска в интернете катастрофически мало информации. Сколько я не искал, нет ни сканов правил, ни внятных фотографий самой игры. Всё, что мне удалось найти можно спокойно пересчитать по пальцам одной руки:
Sally-Anne Bowen, now 65, convicted of assaulting boys at Christ’s College, Finchley, where she was chemistry teacher
A chemistry teacher has been found guilty of indecently assaulting two teenage pupils at an all-boys school in the late 1980s.
Sally-Anne Bowen, who taught at Christ’s College in Finchley, north London, assaulted the teenage boys when they were aged around 14 to 15 and she was in her mid-20s.
Jes Staley made comments to US lawmakers investigating his links to the convicted sex offender
The former Barclays boss Jes Staley has denied having sex with a woman dressed as Snow White, after being questioned about an infamous email exchange about Disney princesses with Jeffrey Epstein.
The comments were detailed in newly released transcripts from a closed-door interview last month with US lawmakers as part of their investigation into Epstein, who died in prison in August 2019 while awaiting trial on child sex-trafficking charges.
Vidosic’s decision is surprise on eve of WSL season
39-year-old led Brighton to May’s FA Cup final
The Brighton manager, Dario Vidosic, is to leave the Women’s Super League club a little over a week before the start of the new season, multiple sources have told the Guardian.
The Guardian understands Vidosic is the leading candidate for the Angel City head coach role with a view to starting work before the 2027 NWSL season.
There still is no off-ramp in sight despite President Donald Trump's repeated assertions that the war has been won or a deal to resolve it was nearly complete.
European champions Paris St-Germain will face Premier League duo Manchester City and Aston Villa in the league phase of this season's Champions League.
Jes Staley made comments to US lawmakers investigating his links to the convicted sex offender
The former Barclays boss Jes Staley has denied having sex with a woman dressed as Snow White, after being questioned about an infamous email exchange about Disney princesses with Jeffrey Epstein.
The comments were detailed in newly released transcripts from a closed-door interview last month with US lawmakers as part of their investigation into Epstein, who died in prison in August 2019 while awaiting trial on child sex-trafficking charges.
Sally-Anne Bowen, now 65, convicted of assaulting boys at Christ’s College, Finchley, where she was chemistry teacher
A chemistry teacher has been found guilty of indecently assaulting two teenage pupils at an all-boys school in the late 1980s.
Sally-Anne Bowen, who taught at Christ’s College in Finchley, north London, assaulted the teenage boys when they were aged around 14 to 15 and she was in her mid-20s.
One claim alleges that a developmentally disabled man was pressured into spending more than $40,000 during a single visit and giving employees more than $10,000 in tips.
A charity tied to Gov. Ron DeSantis’s wife received the money from a state Medicaid settlement and diverted it to political committees supporting a cause favored by the governor.
St. Paul police will lose access to their two Flock Safety license plate reader cameras after residents pushed back on the surveillance technology at a city meeting.
Netflix has walked back plans to put AAA games on its streaming platform. Instead, it's pivoting to marketing highly anticipated titles like Grand Theft Auto VI.