Discover
Foojay.io | Friends of OpenJDK and Java Programming
Foojay.io | Friends of OpenJDK and Java Programming
Author: Foojay.io | Java and Programming Community
Subscribed: 31Played: 799Subscribe
Share
© Foojay.io | Java and Programming Community
Description
Foojay.io is your go-to programming community podcast, connecting developers with the latest in Java, OpenJDK, JVM, and open source tools. We bring together Java professionals worldwide to share insights, tools, and news in the vibrant Java programming ecosystem.
101 Episodes
Reverse
Foojay.io quietly moved off WordPress and onto Hugo. No more CMS login, no database, no admin panel — just Markdown and AsciiDoc files, built and deployed straight from GitHub. So is a traditional CMS still the right way to run a content site in 2026, or has static tooling caught up?In this episode, Andy Damevin and Holly Cummins from the Red Hat Quarkus team join to talk through it. Andy created code.quarkus.io and Roq, Quarkus's own Java-based static site framework; Holly led the migration of quarkus.io itself from Jekyll to Roq. We go through the real security numbers behind WordPress's plugin ecosystem, and put very different static site generators head to head: Hugo and Jekyll, the veterans, versus Roq, the newcomer.Topics include:Why WordPress core is usually fine, and the plugins are where the trouble is — over 10,000 plugin vulnerabilities found since 2025What "recovery" means for a static site versus a CMS after a hack or defacementJekyll, Hugo, Roq and JBake compared, and why staying in Java matters (or doesn't)How to extend Roq as a Java developer, from a small PR to writing your own pluginWhat an actual WordPress-to-Roq migration looks like in practiceWhere a CMS still earns its keep despite all of thisGuests:Andy Damevin on LinkedIn - Principal Software Engineer at Red Hat, Quarkus core team, creator of code.quarkus.io and RoqHolly Cummins on LinkedIn - Senior Principal Software Engineer, Red Hat Quarkus team, led the quarkus.io migration from Jekyll to RoqLinks:Migrate from WordPress to RoqRoqHugoFull show notesTimestamps:00:00 Introduction of topic and guests03:29 Why WordPress is not the best choice for most sites04:36 Difference between CMS-driven websites and static websites07:02 Jekyll versus Roq and other systems11:04 How to extend Roq12:59 Moving from WordPress to Roq14:43 Pulling data with JBang or Roq from external sources into your publication process16:09 Why should I use Roq instead of Jekyll or Hugo?24:33 Static websites can be created with a small team and are much cheaper (or even free) to host26:52 How many WordPress websites have a backup to recover after getting hacked? And the advantage of having your content sources on Git.33:04 Is there still a use case for WordPress-like systems?37:09 Conclusions
Episode 101 of the Foojay Podcast.JDK 27 arrives on 15 September 2026 without finalising a single new piece of language syntax. It is still worth the upgrade: object headers shrink from 64 bits to 32, which the JEP measures at 22% less heap and 8% less CPU on SPECjbb2015, and G1 becomes the default garbage collector on every machine. Both changes live inside the JVM, so an application you compiled years ago picks them up with no code change at all.Simon Ritter, Deputy CTO at Azul and Java Champion, takes us through all nine JEPs in the release, explains why a non-LTS version is still worth testing against, and makes the point that "long-term support" describes the binary you download rather than anything in OpenJDK itself. We also cover the move from quarterly to monthly security updates that started in August 2026, and then look ahead to March 2027, when Project Valhalla reaches its first preview after roughly twelve years of work.Topics include:Compact object headers by default, and what 22% less heap actually buys you in productionPost-quantum key exchange in TLS 1.3, and the harvest-now-decrypt-later attack it defends againstJFR redaction: keeping access tokens and passwords out of flight recordings you shareStructured concurrency in its seventh preview, and why an evolving API stays in previewThe Vector API's twelfth incubation, and what it is waiting forValue Objects in Java 28: a new value keyword, 179,000 lines, 1,800 files, and why it will not be final in JDK 29Whether a Simple JSON API in the JDK will survive its previews, or go the way of string templatesGuest: Simon RitterDeputy CTO at Azul, Java ChampionSimon on LinkedInSimon on FoojayLinks:Full show notes, with every JEP linkedJDK 27What CSPUs Mean for Your Release PipelineWhat to Know About Garbage Collection as a Java Developer!Project ValhallaTimestamps:00:00 Introduction of the topic and guest01:27 How long Simon has been doing Java01:54 Why release 27 is important, even when not being a Long Term Support release04:55 Quarterly and monthly security updates between new version releases08:07 Which JVM versions are most used in companies09:23 JEP 534: Compact Object Headers by Default14:51 JEP 523: Make G1 the Default Garbage Collector in All Environments18:59 JEP 527: Post-Quantum Hybrid Key Exchange for TLS 1.322:55 JEP 538: PEM Encodings of Cryptographic Objects (Third Preview)25:35 JEP 536: JFR In-Process Data Redaction28:02 JEP 531: Lazy Constants (Third Preview)29:55 JEP 532: Primitive Types in Patterns, instanceof, and switch (Fifth Preview)33:13 JEP 533: Structured Concurrency (Seventh Preview)38:21 JEP 537: Vector API (Twelfth Incubator)40:28 Looking forward to Java 28 and Project Valhalla42:31 JEP 401: Value Objects and JEP 539: Strict Field Initialization47:36 Can we expect this to be finalized in Java 29?48:26 LTS releases every 1, 2, or 3 years?49:55 JEP 541: Deprecate macOS/x6451:53 JEP 540: Simple JSON API (Incubator)55:30 Conclusion, what to remember from this release
Episode 100 of the Foojay Podcast. No grand plan. It just happened.To mark the milestone, Frank turned the microphone around and invited other podcasters: Adam Bien (airhacks.fm), Jennifer Reif (Breaktime Tech Talks), Kadi McKean and Steve Pool (10xInsights), and Oumaima Zerouali (JCast). Same questions for each: why did you start, what broke, and what did you learn?Along the way: why a no-prep podcast works when you have 20 years of experience, the difference between writing a blog and recording a podcast, burnout from editing, AI tools that changed someone's voice into Batman, and why a Dutch Java podcast about the human side of development got its first episode from a calendar invite that became a recording.Guests:Adam Bien — airhacks.fmJennifer Reif — Breaktime Tech TalksKadi McKean and Steve Pool — 10xInsightsOumaima Zerouali — JCastLinks:airhacks.fm on SpotifyBreaktime Tech Talks on Spotify10xInsights | 10xInsights on SpotifyJCastFoojay Podcast #67: Writing a book. Does it make you rich and famous?Foojay Podcast #71: 30 Years of Java with James GoslingFoojay Podcast #99: Testing the Untestable: LLM Security for Java Developers with TiberiusFrank on JCastOther podcasts mentioned:Spring DocumentaryContent:00:00 Introduction01:00 Adam Bien (airhacks.fm)12:52 Jennifer Reif (Breaktime Tech Talks)26:25 Kadi McKean and Steve Pool (10xInsights)38:43 Quote by James Gosling39:46 Oumaima Zerouali (JCast)48:01 ConclusionHosted by Frank Delporte | foojay.io
Your Java AI application is live in production. But have you tested whether it can be jailbroken, manipulated into revealing its system prompt, or tricked into printing content it should never output?In this episode, Iryna Dohndorf, Software Engineer at Karakun Group and creator of Tiberius, explains how to bring security testing to LLM-powered Java applications. We cover why traditional unit tests break down with non-deterministic systems, how the Scan-Fixture-Validate workflow works, what buff mutation testing is, and why even well-trained models can be cracked with something as simple as the grandmother attack.Topics include:Why LLM non-determinism breaks the classic input/output test modelThe Scan-Fixture-Validate principle and sharing test artifacts across teamsPrompt injection, jailbreaks, and emotional manipulation attacksBuff mutation: testing linguistic surface coverageProbabilistic security contracts and multi-trial scansFingerprinting and why your model choice should not be detectableLLM as a judge: using a second model as a guardrailGetting started with Tiberius in Spring Boot and LangChain4jGuestIryna Dohndorf - Software Engineer at Karakun GroupLinkedInLinksArticle on FoojayTiberius on GitHubSecurity Testing GuideTimestamps00:00 Introduction of topic and guest01:05 The problem Tiberius wants to solve06:39 How "traditional" unit tests don't work for LLM integrations10:23 Scan-Fixture-Validate principle and sharing artifacts15:15 Using different skills, for example, the grandmother skill17:33 Testing for required versus forbidden bias19:35 The probes across nine attack categories used by Tiberius20:44 Buff mutation testing26:55 Using Tiberius in your pipelines and when to fail29:35 Using multi-trial scans31:14 Fingerprinting: which model you use, should not be detectable32:55 Combining multiple models, model as a judge34:41 Sharing JSON models to improve tests36:05 How to get started with Tiberius in Spring and with LangChain4j36:41 Quarkus not supported yet, plans for the future39:07 Conclusions and a call out to everyone to become a Foojay author
WebAssembly is already running inside Java applications, but most developers just don't know it yet.In this episode, Andrea Peruffo walks us through how WebAssembly is becoming the modern, safe alternative to JNI. Run Rust, C, and other native libraries directly on the JVM, without the crash risks, per-platform packaging headaches, or the observability blackhole that JNI creates.From JRuby's Prism parser to SQLite and full Postgres running as pure Java bytecode, the use cases are real. And the project making it possible, Endive, under the Bytecode Alliance, is open and ready to explore.GuestAndrea PeruffoGitHub: https://github.com/andreaTP/LinkedIn: https://www.linkedin.com/in/andrea-peruffo-32269178/Bluesky: https://bsky.app/profile/andreatp.bsky.socialLinksA New Generation of Java Libraries: Wasm Becomes the Implementation DetailChicory on GitHubEndive on GitHubEndive documentationBytecode AllianceOpenJDK Project DetroitTimestamps00:00 Introduction of topic and guests00:56 What is WebAssembly?03:35 Comparing the performance with JavaScript05:45 JRuby already uses WebAssembly09:04 JNI versus FFM API versus WebAssembly13:58 Other Java-related tools that use WebAssembly17:56 History of the Chicory and Endive projects to bring WebAssembly to Java21:03 Projects of the Bytecode Alliance22:02 The Endive project as the glue to bring WebAssembly tools to Java23:30 Integration of the Redline compiler28:59 Why this is the perfect solution to modernize existing Java applications31:18 Is this approach performant?32:24 What future changes in Java and the JVM will make this even better35:04 How Endive can be used in AI development37:28 What to expect in Endive41:29 Conclusions








