Coffee With Developers Jul 20, 2026

Evals vs. Evil - AI and Package Security - Laurie Voss

Laurie Voss

Laurie Voss warns that unchecked AI agents are poisoning open-source supply chains. Learn why entry-level coding is dead, and how strict spec writing will save your architecture.

Pause
Mute Enter Fullscreen
#1 about 3 min

Defining and implementing LLM evaluation strategies

Because traditional unit tests fail on variable LLM outputs, utilizing a separate model for evaluation serves as an effective testing substitute.

#2 about 2 min

Managing AI costs with open-source models

To mitigate volatile per-token subscription expenses, engineering teams can adopt open-source models that provide comparable performance at a lower cost.

#3 about 3 min

Assessing the real value of the agentic movement

While the agentic tech bubble persists, foundational models offer practical value by reliably converting unstructured data into structured pipelines.

#4 about 3 min

Combating AI slop in open-source projects

The careless misuse of AI generation tools is actively overwhelming open-source maintainers with a flood of low-quality, automated pull requests.

#5 about 3 min

Addressing supply chain attacks in package managers

To combat rising supply chain attacks fueled by AI-generated code, ecosystems must update default client configurations to prioritize repository security.

#6 about 3 min

Balancing developer velocity with vital security guardrails

As code generation tools drastically lower implementation costs, organizations must introduce robust automated guardrails to sustainably enable higher deployment velocities.

#7 about 3 min

Redefining developer roles and software architecture requirements

Since AI agents can now handle basic coding tasks, early-career engineers must pivot toward mastering software architecture and complex spec writing.

#8 about 2 min

The enduring value of in-person developer events

Despite the rise of remote tools, physical proximity and spontaneous human connections remain critical for cross-domain networking and career growth.

Matching moments

1:55 min

Shifting developer workloads and realistic AI productivity gains

Chris Heilmann +2 · LIVE

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

5:16 min

Motivations for adopting AI to enhance developer productivity

2:05 min

The impact and risks of AI generated code

Chris Heilmann · LIVE

3:45 min

Balancing AI tool mandates with developer trust and productivity

Chris Heilmann +2 · LIVE

3:33 min

Navigating developer bottlenecks and human accountability

Werner Vogels Werner Vogels +1 · World Congress 2026 Europe

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Stage 4

Evals Are Infra: Building AI Systems Developers Can Actually Trust

Phoebe Wang

Member of Technical Staff at OpenAI

Phoebe Wang
Open session

World Congress 2026 North America

September 24, 2026 · 16:10–16:40

Stage 2

The Death of the Code Review

Laurie Voss

Head of Developer Relations

Laurie Voss
Open session

World Congress 2026 North America

September 25, 2026 · 11:40–12:10

Stage 2

Reinventing Testing Practices in the AI Era

Eric Deandrea

Java Champion & Senior Principal Software Engineer at IBM

Eric Deandrea
Open session

World Congress 2026 North America

September 24, 2026 · 16:50–17:20

Stage 1

When Humans Stop Writing Code: Rethinking Languages, Compilers, and Responsibility

Simon Auer

Organizer of flutter vienna meetup and CEO of marqably

Simon Auer
Open session

World Congress 2026 North America

September 24, 2026 · 15:30–16:00

Mainstage

Our Brains in the AI Era

Cassidy Williams

Senior Director of Developer Advocacy, GitHub

Cassidy Williams
Open session

World Congress 2026 North America

September 23, 2026 · 13:40–14:10

Stage 2

Building an AI-Native Development Workflow

Vanessa Minik

Senior Service Delivery Engineer, GitHub

Vanessa Minik