terça-feira, 2 de março de 2021

SW DEV: Kanban Maturity Model

Now that kanban is more and more being used for software development...

Kanban Maturity Model
Quoting: 
"The Kanban Maturity Model codifies more than 10 years of experience implementing Kanban across diverse industries, in businesses small to extremely large. It plays an important role in creating unity, alignment, a sense of purpose and good governance. Use it to gain a better sense of achievement, provide better products and services, delight your customers, and realize superior business results."

Downloadable Key KMM Resources:
- KMM Organizational Culture
- KMM Managed Evolution
- KMM Outcomes and Benefits
- KMM Overview
- KMM Graphic
- KMM Triage Tables
- First KMM case study from BBVA, second largest Spanish bank

quarta-feira, 27 de janeiro de 2021

SW Architecture and Design (diagrams): Kroki!

A speedier way of doing analysis diagrams? Something to try.

Quoting: 

Creates diagrams from textual descriptions!

Kroki provides a unified API with support for BlockDiag (BlockDiag, SeqDiag, ActDiag, NwDiag, PacketDiag, RackDiag), BPMN, Bytefield, C4 (with PlantUML), Ditaa, Erd, Excalidraw, GraphViz, Mermaid, Nomnoml, PlantUML, SvgBob, UMLet, Vega, Vega-Lite, WaveDrom... and more to come!

Kroki!

segunda-feira, 29 de junho de 2020

REUSE: Open Telemetry project

Quoting JP newsletter: [Open Telemetry is for] the gathering of metrics produced from your applications. These metrics are either known common ones that are almost always collected (thread counts, CPU consumption, etc) or application specific but benefit from a common collection API.

After decades of every vendor/project/application building their own implementation for these, we're finally going to have a commonly available implementation and standard from the OpenTelemetry project:

https://opentelemetry.io/

From the site: "OpenTelemetry provides a single set of APIs, libraries, agents, and collector services to capture distributed traces and metrics from your application. You can analyze them using Prometheus, Jaeger, and other observability tools."

quinta-feira, 2 de abril de 2020

Unit Testing: cmocka - unit testing framework for C

A unit testing FW for Embedded? Yep.
Details here:
cmocka - unit testing framework for C



Quoting:

"

cmocka is ...

an elegant unit testing framework for C with support for mock objects. It only requires the standard C library, works on a range of computing platforms (including embedded) and with different compilers.

"




domingo, 29 de março de 2020

SW Development: MISRA Coding Standards

An article (from a tool provider, not affiliated) on MISRA C and C++ coding standards and some example rules:
https://www.perforce.com/resources/qac/misra-c-cpp

SW Development: About C++ Adoption (in Embedded)

An article on (the lack) of the latest C++ adootion, C++ 17 and the possible reasons, and the statement that 70% of embedded systems being developed in C:

https://www.perforce.com/blog/qac/should-i-adopt-cpp17

Quoting:
"

Pros and Cons of C++17 Features

The latest version of C++ includes features that improve your code, performance, and security. While these are nice features, they're not earth-shattering. 

Algorithm Optimization

One of the biggest additions is the introduction of the parallel algorithms library.

Multi-processor systems are required for computer-intensive programs and artificial intelligence. The parallel algorithms library makes it easier to execute standardized algorithms on this type of system. 

Cleaner Code

There are two features that will enable cleaner code:

  • Selection statements with initializer.
  • Structured bindings.

This also reduces keystrokes for those who understand the syntax.

So, these features provide a step up for cleaner code. 

Interested in writing cleaner code? Get coding best practices for C++ >>

Better Performance

“Guaranteed copy elision” is designed for improved compiler optimization. So, it may improve runtime performance. 

Safety and Security

The latest C++ features will improve the safety of your program and ensure secure coding, including the following:

  • Removal of trigraphs and dynamic exception specifications.
  • Stricter order of expression evaluation. 
  • Introduction of std::byte type.

The first two features prevent unspecified or undefined behavior. 

The std::byte feature improves type safety. It distinguishes byte-oriented access to memory from accessing memory as a character or integral value. It also improves readability. The intent of the code is clearer.

Learn more about the changes from C++14 to C++17"

sexta-feira, 27 de março de 2020

Security: Working remote?

You might want to take a look on the SANS tips for working remote. Quoting:
"The SANS mission is to empower current and future cybersecurity practitioners through training, education, and skills validation to create a safer global community. …We interrupt our regularly scheduled programing to address the impact that the coronavirus outbreak is having on our daily work life. Working from home may sound like a dream come true for many people, but if this is your first experience taking your workforce virtual, the transition will likely be a bit overwhelming at first. For those given the task of setting up a home office, what should you do first? What technology will you need? How will you stay connected to your co-workers? How will you balance your family and work life? How will I stay productive with the kids home all day?

Download our infographic to help you make the most of working remote here."

Source:

https://www.sans.org/blog/18-tips-to-help-you-make-the-best-of-working-remote/

quarta-feira, 25 de março de 2020

SPARQL query language by W3C

SQL, NoSQL, SPARQL?
The summary:
https://en.m.wikipedia.org/wiki/SPARQL
The cheat sheet:
www.iro.umontreal.ca › spar...PDF
SPARQL By Example: The Cheat Sheet

sábado, 21 de março de 2020

Web tracking techniques...

... from a cookie consent form (cookie policy). Do you know them all?

Quoting:
"Definitions

Cookies

A cookie (sometimes referred to as local storage object or LSO) is a data file placed on a device. Cookies can be created through a variety of web-related protocols and technologies, such as HTTP (sometimes referred to as “browser cookies”), HTML5, or Adobe Flash. For more information on third-party cookies that we use for analytics, please review the table of cookies and tracking technologies within this Cookies and Tracking Technologies Policy.

Web Beacons

Small graphic images or other web programming code called web beacons (also known as “1×1 GIFs” or “clear GIFs”) can be included in our online service’s pages and messages. Web beacons are invisible to you, but any electronic image or other web programming code inserted into a page or email can act as a web beacon.

Clear gifs are tiny graphics with a unique identifier, similar in function to cookies. In contrast to HTTP cookies, which are stored on a user’s computer hard drive, clear gifs are embedded invisibly on web pages and are about the size of the period at the end of this sentence.

Deterministic Finger-printing Technologies

If a user can be positively identified across multiple devices, for instance, because the user has logged into a platform such as Google, Facebook, Yahoo or Twitter, it can be “determined” who the user is for purposes of improving customer service.

Probabilistic Finger-printing

Probabilistic tracking depends upon collecting non-personal data regarding device attributes like operating system, device make and model, IP addresses, ad requests and location data, and making statistical inferences to link multiple devices to a single user. Note that this is accomplished through proprietary algorithms owned by the companies performing probabilistic finger-printing. Note also that in the EU IP Addresses are personal information.

Device Graph

Device graphs can be created by combining non-personal data regarding use of smartphones and other devices with personal log-in information to track interactions with content across multiple devices.

Unique Identifier Header (UIDH)

“Unique Identifier Header (UIDH) is the address information that accompanies Internet (http) requests transmitted over an ISP’s wireless network. For example, when a customer types on his or her phone the web address of a retailer that request travels over the network and is delivered to the retailer’s website. The information included in that request includes things like the device type and screen size so that the retailer site knows how to best display the site on the phone. The UIDH is included in this information, and can be used as an anonymous way for advertisers to be able to determine that the user is part of a group that a third-party advertiser is attempting to reach.

It is important to note that the UIDH is a temporary, anonymous identifier included with unencrypted web traffic. We change the UIDH on a regular basis to protect the privacy of our customers. We do not use the UIDH to collect web browsing information and it does not broadcast individuals’ web browsing activity out to advertisers or others.”

Embedded Script

An embedded script is programming code that is designed to collect information about your interactions with the online service, such as the links you click on. The code is temporarily downloaded onto your device from our web server or a third-party service provider, is active only while you are connected to the online service, and is deactivated or deleted thereafter.

ETag, or Entity Tag

A feature of the cache in browsers, an ETag is an opaque identifier assigned by a web server to a specific version of a resource found at a URL. If the resource content at that URL ever changes, a new and different ETag is assigned. Used in this manner ETags are a form of device identifier. ETag tracking generates unique tracking values even where the consumer blocks HTTP, Flash, and/or HTML5 cookies.

Unique Device Tokens

For each user that accepts push notifications in mobile apps, the app developer is provided with a unique device token (think of it as an address) from the app platform (e.g., Apple and Google).

Unique Device ID

The unique series of numbers and letters assigned to your device."

Source: https://www.voxmedia.com/legal/cookie-policy#your-cookie-choices-and-how-to-opt-out

sexta-feira, 14 de fevereiro de 2020

Uphill notation: importance and uses in the medical field

The existence of a (graphical) notation improves conveying what there is to do next, diminishes the probability of error applying protocols and the use of a mobile app improves peer review and sharing of the changes in the medical protocol for a certain situation:
https://uphillhealth.com/notation

quinta-feira, 19 de setembro de 2019

SW Testing: Introduction to Stateful Property Based Testing

Introduction to Stateful Property Based Testing - Lambda Days 2019



Quoting:

"Property-based testing (PBT) relies on properties which can be written in pseudocode as:

for all (x, y, ...)  
such as precondition(x, y, ...) holds  
property(x, y, ...) is true
Introductory examples usually illustrate the technique with testing a data structure or a function, by recording its inputs and outputs and checking that specified properties are all valid.
Few commonly known examples deal with stateful PBT applied to testing actual live systems. In his talk, Kowal gives such an example. The process involves the identification of properties, building a stateful model of the system under test (SUT), using that model to generate interesting test sequences, running the test sequences on the actual system, comparing at each step of the run the system behaviour and outputs to those predicted by the model, and shrinking failing test sequences to a minimal expression."

quarta-feira, 18 de setembro de 2019

SW Testing: Print Screens?

Oh, did I ever tell you you need to take (efficiently) print screens while (manual) testing? Some ideas towards productivity:
https://www.pcmag.com/feature/370572/how-to-take-screenshots-in-windows-10

PS: Also do not forget the utility "mouse without borders" also crucial for testers (with 2 or more PCs and just one mouse).

Documentation: Tracked changes in Google Docs?

Yes. It's called suggestions. Share with Edit permissions. Uncheck the email notifications. Much like MS  Office, comments also exist in Google Docs as well as a Compare option in tools and a revision history (with human readable names that can be set by the user):
https://www.pcmag.com/article/330137/tip-how-to-use-track-changes-in-google-docs

Missing TBC: The Combine (with generated inline tracked changes) option, much useful to know what words changed between 2 revisions when someone forgot (or "forgot") to start tracking changes. If you have PDF versions attempt a conversion of PDF to docx and then combine (Office does it).

Documentation IS part of the configuration of a software so, do learn to use productivity tools. This is why it's called productivity tools.

sábado, 14 de setembro de 2019

BOOK: NASA Systems Engineering Handbook, NASA - Amazon.com

Rev1 of SEBoK from NASA (caution, there is a Rev2 and the PDF can be found at NASA sites):

NASA Systems Engineering Handbook, NASA - Amazon.com

Quoting:
"This handbook consists of six core chapters: (1) systems engineering fundamentals discussion, (2) the NASA program/project life cycles, (3) systems engineering processes to get from a concept to a design, (4) systems engineering processes to get from a design to a final product,(5) crosscutting management processes in systems engineering,and (6) special topics relative to systems engineering. These core chapters are supplemented by appendices that provide outlines, examples, and further information to illustrate topics in the core chapters. The handbook makes extensive use of boxes and figures to define, refine, illustrate, and extend concepts in the core chapters without diverting the reader from the main information. The handbook provides top-level guidelines for good systems engineering practices; it is not intended in any way to be a directive."


PDF version: https://www.nasa.gov/feature/release-of-revision-to-the-nasa-systems-engineering-handbook-sp-2016-6105-rev-2

quarta-feira, 4 de setembro de 2019

SW Construction: Java 13

One of the most popular Enterprise Application Framework is being updated, again. Details here:


"Java 13 is released in less than a month. As usual I'm listing all the new performance features in the release, just as I now do every 6 months with each new Java version. The new features, the performance benefits from each feature, and how to use the feature.

Java 13 is pretty light on performance features, but one specifically is worth knowing about ... read on at ""

terça-feira, 3 de setembro de 2019

Metrics: Software Development Performance Index (SDPI)

Software Development Performance Index (SDPI) for measuring Agile Teams performance.
The concept and principle is described in this whitepaper of "The impact of Agile Quantified" (from the Software Engineering Institute, the organization managing the CMMI model:

quinta-feira, 8 de agosto de 2019

BOOK: Software Testing Foundations, 4th Edition: A Study Guide for the Certified Tester Exam (Rocky Nook Computing): Andreas Spillner, Tilo Linz, Hans Schaefer: 9781937538422: Amazon.com: Books

A book about SW testing according to the International Software Testing Qualifications Board (ISTQB):

Software Testing Foundations, 4th Edition: A Study Guide for the Certified Tester Exam (Rocky Nook Computing): Andreas Spillner, Tilo Linz, Hans Schaefer: 9781937538422: Amazon.com: Books

Quoting:
"Professional testing of software is an essential task that requires a profound knowledge of testing techniques. The International Software Testing Qualifications Board (ISTQB) has developed a universally accepted, international qualification scheme aimed at software and system testing professionals, and has created the Syllabi and Tests for the Certified Tester. Today about 300,000 people have taken the ISTQB certification exams. The authors of Software Testing Foundations, 4th Edition, are among the creators of the Certified Tester Syllabus and are currently active in the ISTQB. This thoroughly revised and updated fourth edition covers the "Foundations Level" (entry level) and teaches the most important methods of software testing. It is designed for self-study and provides the information necessary to pass the Certified Tester-Foundations Level exam, version 2011, as defined by the ISTQB. Also in this new edition, technical terms have been precisely stated according to the recently revised and updated ISTQB glossary."


quarta-feira, 7 de agosto de 2019

Agile: Crystal Methods

Crystal is one Agile methodology born in the mid-90s and still used today in some railway projects:

Crystal Methods - Wikiversity


Quoting:

"Crystal methods are a family of methodologies (the Crystal family) that were developed by Alistair Cockburn in the mid-1990s. The methods come from years of study and interviews of teams by Cockburn. Cockburn’s research showed that the teams he interviewed did not follow the formal methodologies yet they still delivered successful projects. The Crystal family is Cockburn’s way of cataloguing what they did that made the projects successful.

Crystal methods are considered and described as “lightweight methodologies”. The use of the word Crystal comes from the gemstone where, in software terms, the faces are a different view on the “underlying core” of principles and values. The faces are a representation of techniques, tools, standards, and roles.

Methodology, techniques, and policies are differentiated between by Cockburn:
  • Methodology - set of elements (e.g. practices, tools)
  • Techniques - skill areas (e.g. developing use cases)
  • Policies - dictate organizational musts

Crystal methods are focused on:
  1. People
  2. Interaction
  3. Community
  4. Skills
  5. Talents
  6. Communications
Cockburn says that Process, while important, should be considered after the above as a secondary focus. The idea behind the Crystal Methods is that the teams involved in developing software would typically have varied skill and talent sets and so the Process element isn’t a major factor.
Since teams can go about similar tasks in different ways, the Crystal family of methodologies are very tolerant to this which makes the Crystal family one of the easiest agile methodologies to apply.
In his research, Cockburn [1999], he defines behaviour of people in teams:
  • “People are communicating beings, doing best face-to-face, in person, with real-time question and answer.”
  • “People have trouble acting consistently over time.”
  • “People are highly variable, varying from day to day and place to place.”
  • “People generally want to be good citizens, are good at looking around, taking initiative, and doing ‘whatever is needed’ to get the project to work.”

The points above are why Crystal methods are so flexible and why they avoid strict and rigid processes typically found in older methodologies."

There are several variants of the method and the set of methodologies is sometimes called "Crystal xx". For more details follow the lin k above.  

segunda-feira, 5 de agosto de 2019

SW Development: Error budgets?

Just sharing this article with thoughts about conflicts with Devs, Ops /DevOps and about error budgets:

DevOps = Dev + ErrorBudget + Ops - Expedia Group Technology - Medium

Quoting:
"It wasn't until I learned about Error Budgets that I
realized exactly how dev and ops could merge into an effective
"devops", and I've written about that in my latest article https://medium.com/expedia-group-tech/devops-dev-errorbudget-ops-9441e94ff698 "
(...)
"There’s a lovely description in chapter 3, Embracing Risk of Google’s Site Reliability Engineering book which I will quote here:
For example, if product development wants to skimp on testing or increase push velocity and SRE is resistant, the error budget guides the decision. When the budget is large, the product developers can take more risks. When the budget is nearly drained, the product developers themselves will push for more testing or slower push velocity, as they don’t want to risk using up the budget and stall their launch. In effect, the product development team becomes self-policing. They know the budget and can manage their own risk. (Of course, this outcome relies on an SRE team having the authority to actually stop launches if the SLO is broken.)"