Back to home

Research and releases

Sources that change how we work.

We follow published software-engineering research and upstream changes that may affect how software is built, tested and operated. Each note states the source type and limits the delivery implication to what the source supports.

Reviewed 21 August 2026

Research in use

Each finding leads to a bounded choice.

These sources inform a method. Engagement results and delivery team composition remain separate operating decisions.

Software development

Research-program update · not peer reviewed
24 February 2026

We are Changing our Developer Productivity Experiment Design

METR reports that selection effects and unreliable time measurement prevent its late-2025 experiment from producing a dependable estimate of AI-assisted developer productivity.

How it affects the work

We measure AI assistance on the work and team using it, including review and rework. Fixed AI productivity multipliers stay out of engagement plans.

Read the source: METR

Quality engineering

Software-engineering preprint · not peer reviewed
6 July 2026

On the risk of coding before testing

In the studied tasks, tests generated after faulty model-written code detected faults less often than tests generated independently: 14% compared with 25%.

How it affects the work

For AI-written code, we retain a validation path derived independently from the implementation, such as acceptance checks based on the requirement or contract.

Read the source: Konstantinou, Tambon and Papadakis

Testing and review

ICSE-SEIP conference paper
2024

Productive Coverage: Improving the Actionability of Code Coverage

Google reports that prioritising uncovered code by similarity to tested or frequently executed production code improved coverage and produced modest review-efficiency gains in its environment.

How it affects the work

We use coverage with change risk and production context to decide where another test may help. Release readiness requires evidence beyond a raw coverage percentage.

Read the source: Google Research

Post-quantum security

Federal Information Processing Standards
August 2024

NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)

NIST finalised primary post-quantum cryptographic standards (ML-KEM for key establishment and ML-DSA for digital signatures) to secure communications against future quantum computer cryptanalysis.

How it affects the work

We design crypto-agility layers and audit long-retention data pipelines against post-quantum standards, enabling systems to rotate cryptographic primitives without architectural disruption.

Read the source: NIST CSRC

Distributed systems

Systems verification research
2025

Formal Verification of Distributed Consensus and State Machine Protocols

Formal specification and automated model checking uncover subtle liveness and partition-recovery defects in distributed ledgers and consensus state machines before production deployment.

How it affects the work

We apply state-machine invariant modeling and adversarial partition testing when building decentralized ledgers, cryptographic audit pipelines, and high-concurrency protocols.

Read the source: ACM SIGOPS

Autonomous agent containment

Technical whitepaper & incident deconstruction
September 2026

Why WAFs Failed: Deconstructing the 1,200-Agent Hugging Face Proxy Breakout

Perimeter WAFs and L7 proxies failed because the attack was executed entirely by legitimate, authorized agent tokens capability-chaining permissions across internal service meshes and mounted Docker sockets.

How it affects the work

We mandate the Three Invariants of Defensive Agent Runtimes: semantic air-gapping in ephemeral microVMs, deterministic pre-execution tool interceptors, and zero-trust capability tokens with cryptographic human-in-the-loop approval gates.

Read the whitepaper: Anystack Engineering Autonomous Systems Group

Verification systems

Technical whitepaper & verification architecture
September 2026

The Carrier Illusion: Deterministic Verification of AI-Generated Software

When models author implementation code and test suites simultaneously, completion incentives cause tests to pass by construction. Tests verify carrier existence (.toBeDefined) while omitting payloads, error branches, and domain invariants.

How it affects the work

We mandate the Three Pillars of Deterministic Verification: static AST assertion inspection, sandboxed schema mutation testing (including homomorphic object substitution), and physical dual exit-code transition proofs.

Read the whitepaper: Anystack Engineering Systems Verification Group

Release watch

Current upstream changes.

This dated sample shows the type of watchlist we maintain. Each engagement follows the client's actual stack and support policy.

Application framework

Official security notice
20 August 2026

Upcoming Next.js August Security Release

Vercel announced an August 26 security release covering one critical vulnerability and identified 16.3.3 and 15.5.24 as the planned updates. Technical details remain withheld until release.

What we would check

Identify affected applications and prepare an upgrade test window. Confirm the planned versions against the published release before applying them.

Read the official source: Next.js

Browser testing

Official patch release
30 July 2026

Playwright 1.62.1

The patch fixes TypeScript-configuration regressions and accessibility-snapshot problems around the 1.62 release line.

What we would check

Pin the selected version and rerun monorepo configuration, browser and accessibility-snapshot checks before adopting the 1.62 component-testing changes.

Read the official source: Microsoft Playwright

JavaScript runtime

Official LTS release
3 August 2026

Node.js 24.19.0 “Krypton”

The LTS release includes configurable HTTP-header validation, TLS negotiation information and per-event-loop delay sampling.

What we would check

Trial the LTS update under the application's integration, dependency and operational checks. Use new diagnostics only where they answer a recorded reliability question.

Read the official source: Node.js

The engagement decides what applies.

The pod shape is an Anystack operating choice. Research, releases and advisories inform technical decisions alongside the constraints and evidence in the client system.