Discover
The MonkCast
The MonkCast
Author: RedMonk
Subscribed: 4Played: 126Subscribe
Share
© 2025 RedMonk
Description
Join the developer-focused industry analysts at RedMonk as they discuss news and trends in the software space with leaders and practicioners in cloud, AI, IaC, security, DevOps, developer relations, observability, data, and more.
Can't get enough of the Monks? Visit the RedMonk YouTube channel or check out our research at RedMonk.com.
You can also follow RedMonk on Bluesky, Twitter (X), and LinkedIn.
Meet RedMonk's Analysts
James Governor, Principal Analyst & Co-founder
Stephen O'Grady, Principal Analyst & Co-founder
Rachel Stephens, Research Director
Kate Holterhoff, Senior Industry Analyst
219 Episodes
Reverse
In this episode, David Pollak, founder and CEO of Spice Labs, and Allan Friedman, Senior Technical Advisor at the Institute for Security and Technology, discuss the importance of software supply chain security, bills of materials, and the emerging field of post-quantum cryptography with Kate Holterhoff. Friedman, "the godfather of SBOMs," gives a state of play for 2026: where the tooling has matured, where it still falls short, and why the Cyber Resilience Act is about to make this everybody's problem. From there the conversation moves to CBOMs and post-quantum cryptography. Pollak argues PQC stopped being a 2035 problem in June, when the White House, the US military and French standards bodies all pulled their deadlines forward by five years. Also covered: whether developers should have to think about security at all, what the IPv6 transition taught us, and the 360,000 Maven packages carrying vulnerable code nobody disclosed. This RedMonk conversation is sponsored by Spice Labs.Show notes: https://redmonk.com/videos/david-pollak-allan-friedman/Chapters00:04 Introduction to the Guests and Topics06:29 The State of SBOMs in 202613:46 Understanding Cryptographic Bills of Materials22:12 The Intersection of Security and Development31:25 The CBOM Approach and Its Importance33:23 Post-Quantum Cryptography: A Future Concern?38:55 Navigating Regulations and Compliance43:57 Finding vs. Fixing Vulnerabilities in Open Source49:58 AI's Role in Security and Vulnerability Management53:31 Lessons from IPv6 and Cryptography Libraries
Kate Holterhoff talks with Victoria Melnikova, head of new business at Evil Martians, about what product market fit looks like for developer tools in 2026. Drawing on research by Evil Martians CEO Irina Nazarova, Melnikova argues PMF is a spectrum, not a switch. Product signals and revenue signals are separate things, and the gap between them tells you where to focus. Her advice to most early stage founders? Your product is probably fine, go do sales. Their conversation covers why dev tools resist the golden path metrics of generic SaaS (what's the golden path in Photoshop?), why agent experience (AX) matters now that LLMs increasingly pick tools for their users, and why engineers who use AI well are becoming the hires companies fight over. Also: a corrupted video shoot, agencies as pirate ships, and why AI should be like a good wig.Show notes: https://redmonk.com/videos/victoria-melnikova/Chapters00:04 Introduction to Dev Tools and Product Market Fit10:52 Understanding Product Market Fit in DevTools18:19 The Shifting Landscape of DevTools and AI25:33 Agent Experience and Its Impact on DevTools28:54 Navigating Agent Experience and AI Integration34:17 The Future of Hiring in Tech38:58 Designing with AI: Balancing Human Touch and Automation47:09 Security in Open Source and AI
Generated code is arriving faster than maintainers can read it. RedMonk's Steve O'Grady discusses this new reality with Jason Brooks and Brian Proffitt, both managers in Red Hat's Open Source and AI Program Office. Proffitt's teams are adding what he calls human speed bumps upstream: PR templates that ask whether AI wrote the patch, and if so, what the prompt was. The point is transparency, not blocking the flow. Brooks argues for the importance of human decision makers because writing code may cost close to nothing now, but getting another person to accept it still costs plenty, and someone always pays the token bill. The conversation also touches on maintainer burnout, why saying "no" is still a legitimate answer to a pull request, Fedora Hummingbird and its agentically assembled packages, and the thing Proffitt worries about most: trust.This RedMonk video is sponsored by Red Hat.Show notes: https://redmonk.com/videos/brian-proffitt-jason-brooks/Chapters00:04 Introduction to AI and Open Source Governance00:32 Guest Introductions: Jason Brooks and Brian Proffitt02:10 AI's Ubiquity and Industry Impact03:06 Guardrails for AI Code Quality in Projects04:22 Implementing Human Speed Bumps for AI Contributions05:17 Encouraging Transparency in AI Contributions06:46 Automated Review and Guardrails in Open Source07:50 Verifying AI-Generated Code in Fedora09:10 Human Oversight in AI Processes13:39 Developer Burnout and Managing Contribution Floods16:09 Trust and Transparency in AI-Driven Ecosystems18:30 Evolving Policies for AI in Fedora20:16 Future Challenges and Community Trust in AI21:11 Closing Remarks and Future Outlook
In this conversation recorded at Fastly Xcelerate, James Governor talks with Jefferson Frazer, Director of AI at Shutterstock, about how a two-decade-old media company reinvented itself for the age of foundation models. Frazer explains how Shutterstock's long history of human-reviewed, meticulously labeled content left it uniquely positioned when hyperscalers began seeking diverse, web-scale datasets for multimodal training. Frazer digs into the technical backbone too: a 100-plus petabyte footprint, cloud-agnostic architecture built on Fastly's private fiber and Wasm-based edge compute, and the discipline of tracking data provenance through standards like C2PA and SynthID. Looking ahead, he makes the case that unified embedding spaces and portable metadata—not any single model provider—will define the next chapter of AI-ready content.This RedMonk video is sponsored by Fastly.Show notes: https://redmonk.com/videos/jefferson-frazer/Chapters00:00 Introduction to Shutterstock and AI04:14 Data Scale and Infrastructure07:25 Fastly's Role in Data Management10:28 The Future of AI and Business Models13:28 Regulation and Provenance in AI16:35 Excitement for Unified Embedding Spaces
Why does ChatGPT recommend one DevTool over another, and what can founders do about it? In this RedMonk Conversation, Kate Holterhoff sits down with Adam DuVander, Principal Consultant at EveryDeveloper and author of Developer Marketing Does Not Exist, to explore how AI assistants are transforming software discovery. They discuss Adam’s LLM Rank research, which tracks how models like ChatGPT, Claude, and Gemini recommend developer tools, and why those recommendations often differ. The conversation covers the practical steps DevTool companies can take to improve AI discoverability, from documentation and developer experience to use-case positioning and contextual content. Along the way, Kate and Adam examine the expanding definition of “developer,” the rise of AI-assisted builders, and why developer marketing is evolving rather than disappearing. Whether you’re building a developer product or rethinking your go-to-market strategy, this episode offers a practical framework for succeeding in an LLM-first world.Show notes: https://redmonk.com/videos/adam-duvander/Chapters00:00 Defining the Modern Developer04:25 The Role of Every Developer09:38 Marketing to the New Breed of Developers12:37 Understanding LLM Rank and AI in Development19:57 The Evolution of Documentation and Developer Experience22:06 Understanding Developer Context and Use Cases25:31 Navigating AI Recommendations for Developer Tools28:55 The Importance of Language and Phrasing in Queries31:50 The Long Game of SEO and LLM Rankings36:44 Addressing Outdated Documentation and Bad Advice42:20 The Distinction Between Discoverability and Developer Success47:51 The Future of Developer Marketing in an AI World




