Agents write most of my code these days. That leaves me with this question: what do I do with all this free time? I considered learning a new framework, but that sounds suspiciously like work. Luckily, the VS Code team has a better idea. They gave me something to take care of. What is the VS Code pet? The pet is an interactive character that sits above the chat input box. It reacts to chat activity and to whatever you do to it. So while the agent works, the pet watches. Before, I was the only one staring at the progress indicator while pretending to supervise. Now I have company. Remark: The pet is marked as experimental, so it might change or be removed. Don't get too attached. (I got attached within five minutes.) Adopting your pet Type /vscode-pet in the chat input to show or hide it. In the new-session view of the Agents window, you can also right-click outside the input box and select Pet (/vscode-pet) . Show or hide. That's the entire commitment. As fa...
Dependency Track is an open source component analysis platform from OWASP. You upload the SBOM of your application, and Dependency Track keeps track of the components inside it. It checks those components against vulnerability sources like the National Vulnerability Database, GitHub Advisories and OSV. It also lets you define policies and send notifications when something new shows up. In short: it tells you which of your applications are affected when the next vulnerable library hits the news. Recently Dependency Track got an upgrade and version 5 was released. So, time to upgrade! However, that turned out not to be as easy as expected. It took us 2 attempts. Our first attempt failed completely, so we took a different route. Here is what we tried and the two things that cost us the most time. Big shout out to Jef, who looked over my shoulder during the upgrade and helped tackling the issues when we got stuck. Two approaches in the documentation The Dependency Track documenta...