Blogs
Thought leadership from Merito practitioners covering secure software delivery, DevOps culture, and emerging tooling trends. Actionable insights you can put to work immediately.
Explore BlogsResource Hub
Explore curated expertise from our team. Blog insights, customer success stories, and practical guidance for building secure, high-performing software delivery organizations.
Thought leadership from Merito practitioners covering secure software delivery, DevOps culture, and emerging tooling trends. Actionable insights you can put to work immediately.
Explore BlogsReal-world transformations that showcase how we partner with teams to modernize pipelines, strengthen application security, and ship with confidence across regulated industries.
Explore Case StudiesTrack platform enhancements, release notes, and rollout guidance from Merito across the tools and ecosystems enterprise teams rely on.
Explore Product Release UpdatesWatch concise briefings, walkthroughs, and expert explainers covering software delivery strategy, platform operations, and modernization priorities.
Explore VideosGrab guides, checklists, and reference PDFs from the Merito team to put enterprise software delivery, security, and modernization guidance to work.
Explore PDF DownloadsCurated picks from our team—explore thought leadership and transformation stories that showcase how Merito accelerates secure software delivery.
Find the stories, guides, and insights that match your initiatives. Filter by resource type or search by topic to surface the most relevant content.
Microsoft Azure DevOps July 2026 introduces the GradleAuthenticate@0 pipeline task for authenticating Gradle builds to Azure Artifacts feeds. The update also adds guidance for pull request status checks, repository and pull request security, commit-message search, permission-performance tuning, personal access tokens, branch policies, and Azure Boards administration. Enterprise teams should use these changes to standardize release gates, reduce credential exposure, and improve auditability across delivery workflows.
Sonatype Nexus Repository 95 adds hosted and group repositories for Composer, plus Chocolatey registry and Microsoft Symbol Server support through NuGet repositories. The release also extends cleanup policies across major package formats, improves private PyPI and Hugging Face client compatibility, supports temporary AWS credentials for ECR proxies, and introduces Firewall Success Metrics reporting. Enterprise teams should assess documented upgrade changes affecting Ansible Galaxy responses, content selectors, search indexes, and Preview UI customizations before deployment.
Tricentis Tosca Cloud August 2026 introduces the Tricentis Product Expert in product documentation, providing AI summaries and answers grounded across Tricentis manuals. The release also allows contributor-role users to delete assets and folders in Organize your inventory. Enterprise teams should define deletion authority, review role assignments, and validate the staged rollout in each environment.
.png&w=2560&q=75)
Semgrep’s July 2026 update adds Agentic Workflows in public beta, combining program analysis, deterministic tools, and constrained AI reasoning to generate reviewable security findings. Supply Chain customers can block dependencies only when all associated licenses are prohibited and receive default incident-policy support with Slack notifications based on recent SBOM exposure. The update also strengthens operational governance through policy-tag warnings, clearer webhook failures, and fixes to manual triage and integration behavior.
TestRail 10.6.2 fixes an issue in TestRail 10.6.1.1001 affecting custom fields when their configuration is edited. The Cloud hotfix helps QA and release teams make controlled changes to test metadata with greater confidence. It is a targeted maintenance release rather than a broad feature expansion.

Sonatype IQ Server 205.3, released July 31, 2026, improves reliability during LDAP disruptions and sustained failed-login attempts by preventing excessive CPU consumption. The release also ensures SBOM scan artifacts, policy reports, and file descriptors are cleaned up after deletion, reducing avoidable storage consumption. It addresses CVE-2026-54291 affecting PostgreSQL connection security and CVE-2026-49844 affecting Log4j JSON output.
Checkmarx CxONE 3.62 adds detailed Audit Trail records for SAST finding triage and Analytics and Reporting activity, improving compliance evidence and forensic traceability. It introduces Risk Orchestration to consolidate results across security engines, plus generally available AI Triage & Remediation for supported SAST and SCA workflows. The release also adds AI Supply Chain scan controls, CLI and CI/CD support, AI-BOM export, and more granular SCA policy options for net-new production dependency risk.

Perforce BlazeMeter 3.2 strengthens test governance by adding version history, side-by-side comparison, and restore capability for virtual service transactions. It extends AI Log Analysis to multi-tests, increases performance-test file uploads to 100 MB, and lets ShiftLeft Converter users select output format and destination project. These changes help enterprise teams investigate test issues faster while keeping configuration changes attributable and recoverable.

A walkthrough of how to build your own software ROI model instead of relying on vendor numbers, applied to SAP Change Impact Analysis. Covers five figures, where each one physically lives in your organization, who to ask for it, and how long it should take to pull, so the business case survives scrutiny in a steering committee.
This video explains why SAP regression cycles take weeks. Because nobody can produce a list of what a transport changed, its dependencies, and what production actually uses, testing everything becomes the only defensible option. Chris Carpenter of Merito walks through checks any team can run this week, covers SAP data showing 40 to 60% of custom ABAP never executes in production, and explains how change impact analysis (LiveCompare, SAP CIA, or bundled with Tricentis Tosca) shrinks regression scope based on risk.
Perforce Perfecto 26.8 improves governance for AI-assisted testing by attaching the global knowledge used in AI test flows to execution reports. The release adds explicit API rate-limit responses, updates DevTunnel certificates for affected clouds, and supports Quantum 3.2.5/3.2.6, Playwright 1.60.0, current iOS and iPadOS versions, and new Chrome, Firefox, and Edge versions. Teams using iOS 27 simulators must explicitly set Appium 3.3, while virtual-device apps built only for Intel require ARM64 builds on iOS 26.4 or later.

A live demo showing how Merito's marketing team uses Claude Code to publish an approved blog post directly to a production CMS. A custom Claude skill populates the title, summary, body, FAQs, tags, and metadata, then an SEO audit skill validates the draft automatically. The video also covers Merito's five AI engagement frameworks for enterprise Claude adoption.

This enterprise-focused video demonstrates how Claude Code can support the full software delivery lifecycle, from Jira user story planning through code generation, testing, security review, CI/CD, and production deployment. Chris Carpenter, COO at Merito, explains five practical enterprise adoption frameworks for Claude and shows real integrations with Jira, MCP, Git, test automation, and governance workflows. The session is aimed at engineering leaders, DevSecOps teams, architects, QA leaders, and organizations evaluating enterprise AI for SDLC modernization.

SAP Change Impact Analysis (CIA), sold by Tricentis as LiveCompare, reads a transport, support pack, or upgrade delta and resolves every dependent object down the call structure, standard SAP code included. It weights that dependency graph with production usage so objects nobody calls drop out of scope, then matches the result against test repositories such as Tosca, qTest, or Solution Manager to return covered objects and coverage gaps. Run on every transport cycle it makes a SAP Cloud ALM release gate enforceable instead of a signature field.

A business case for SAP change impact analysis should rest on five numbers the team produces itself: the fully loaded cost of one regression cycle, the number of cycles run per year, the share of test cases that exercise an object a transport actually changed, a scope reduction the team would defend to a CFO, and the price of one escaped defect. Vendor-published ROI percentages collapse under finance scrutiny because they trace back to a product page rather than the buyer's own program, and the escaped-defect line is usually the largest item in the model.

Workflow misconfigurations drove the largest software supply chain attacks of 2025 and 2026. This free PDF gives you a single prompt that turns Claude Code into a ranked GitHub Actions security audit of your repository.
This tutorial explains how to connect Tricentis Tosca to GitHub and enable version control for Tosca test automation projects. It covers GitHub prerequisites, creating a Personal Access Token, configuring Tosca Multi-User Repository settings, connecting to GitHub, selecting branches, and completing the initial commit. The video is designed for QA Engineers, Test Automation Engineers, QA Leads, and DevOps teams looking to improve collaboration, traceability, and change management in enterprise test automation environments.

Learn how to implement Claude with governance, workflow integration, security controls, and measurable business outcomes across engineering, QA, DevSecOps, and enterprise applications.
Most Tricentis rollouts, whether Tosca, qTest, or NeoLoad, stall after the purchase order is signed, and the licensed seats quietly turn into shelfware. The license is the cheap part. The real cost is the faster regression, fewer defect escapes, and lower rework you paid for but never operationalized. Buying Tricentis through a partner like Merito closes the gap between purchase and payoff, and often lands a lower price than going direct.

See how UFT customers stand up OpenText DAST inside existing QA workflows, with authenticated scans anchored to real user journeys.
Healthcare organizations use Epic test automation to validate critical workflows, reduce upgrade risks, protect revenue cycles, and ensure patient safety. Merito helps enterprises build and manage scalable Epic QA automation frameworks.
Learn how enterprise organizations scale AI-powered test automation with framework governance, Playwright architecture, traceability, CI/CD integration, and quality engineering best practices.
Learn how enterprise teams can use AI unit testing to improve software quality while maintaining governance, traceability, compliance, and release confidence across the SDLC.
Learn how enterprise teams can implement AI-first test automation with governance, traceability, CI/CD integration, and quality controls that reduce risk and improve release confidence.

Learn how SAP quality engineering reduces release risk, improves delivery speed, and supports SAP S/4HANA transformation success.

Navigating the End of Life for Jira Data Center with Atlassian phasing out Jira Data Center, many organizations are facing a critical crossroads. In this video, Adam Sandman (CEO of Inflectra) and Louis Tadman (CTO of Merito) discuss the official roadmap, the challenges of forced cloud migrations, and why SpiraPlan is the premier on-premise and self-hosted alternative.

Perforce Continuous Testing delivers AI-powered web, mobile, API, and performance testing at scale, cutting test maintenance by 90% and regression cycles by 70%.

OCS previously relied on Selenium for their test automation needs but it was an open-source solution that required significant coding knowledge and was primarily limited to web-based testing. While powerful, it created a bottleneck by limiting automation to developers or team members with coding experience.

Stellantis is one of the world's leading automakers and mobility providers, known for its portfolio of iconic brands. With a strong focus on innovation, the company continuously works to improve vehicle quality, safety, and efficiency. To support these efforts, Stellantis relies on rigorous software testing and development processes to ensure its technology meets high industry standards.

When it comes to ensuring reliability and performance of critical systems, particularly with Electronic Health Records (EHR) platforms like Epic and integrations with their downstream applications, Healthcare IT teams face several unique challenges compared to other industries. One major healthcare provider was struggling with inefficient testing processes, zero automation, and a lack of structured reporting. Merito implemented a comprehensive test automation strategy to enhance testing efficiency and enable a Ready-Set-Go testing approach. This provided key stakeholders with an easy to use, collaborative environment, empowering doctors and nurses with limited IT knowledge, to participate in user acceptance testing (UAT). The initiative established clear communication channels, validation/reporting structures, and ultimately ensured higher quality releases which improved systems for patient care and safety.

Used by 60% of Fortune 500 companies, the Workday platform is a leader in enterprise cloud applications for managing finance, HR, and operations. As the backbone of critical enterprise workflows, organizations leveraging Workday require a comprehensive solution to streamline testing processes, which are often heavily manual and time-intensive. To address these challenges, Merito developed a powerful Automation Accelerator for the Workday Platform—a modular solution designed to automate and optimize the testing of Workday's platform and Workday Extend applications using Tricentis Tosca.

Merito partnered with Cencora to successfully migrate their enterprise testing operations from Zephyr Enterprise to Tricentis qTest. This strategic transition streamlined test management processes, improved traceability across the SDLC, and enabled greater collaboration and efficiency for Cencora’s QA teams at scale providing realization of return on investment rapidly.

Faced with significant challenges in regression testing, including inefficient automation efforts, manual workflows, and a lack of a reusable testing framework, Pratt & Whitney sought a transformative solution. Merito partnered with Pratt & Whitney to address these obstacles. We implemented a scalable automation framework, optimized their Software Development Life Cycle (SDLC), and automated their approval processes. These solutions enhanced testing efficiency and fostered collaboration across teams.