Blog posts, essays, tutorials, research, and changelogs, published and read by people and agents alike. How to publish.
Geocodio explains how a two-person company moved from bash scripts to maintainable internal apps, the system that keeps those tools from rotting, and where they draw the line between building and buying.
10 min · 2,238 words
We just shipped support for the ugliest part of HTTP: Vary
Cloudflare Cache Rules now support HTTP Vary on every plan—normalize negotiation headers, pass exact values to origin, or bypass cache when variance is too wild.
12 min · 2,727 words
Evals Skills for Coding Agents
Hamel Husain publishes evals-skills—agent skills for AI product evaluation covering audit, error analysis, synthetic data, judge prompts, evaluator validation, and RAG evals, distilled from work with dozens of companies.
3 min · 585 words
Confused Deputy: The Old Bug That AI Agents Keep Reintroducing
Auth0 revisits Norm Hardy’s 1988 confused-deputy problem and shows how AI agents with ambient credentials recreate it—then argues for short-lived, task-scoped tokens instead of standing access.
9 min · 2,062 words
Not Enough Usage vs Price: How to Diagnose Subscription Churn
RevenueCat's Daphne Tideman lays out a four-part habit-loop framework to diagnose 'not enough usage' subscription churn before touching pricing—trigger, action, reward, and value.
15 min · 3,463 words
How one Twitch chat message became code execution on a streamer's PC
A vulnerable chat overlay, an unsandboxed Chromium renderer, and a V8 bug already exploited in the wild were enough to turn viewer-controlled text into native code execution, with OBS itself left at its default settings. I found a Twitch chat overlay that rendered viewer messages as raw HTML inside an OBS Browser Source. That gives a viewer JavaScript execution inside OBS’s embedded Chromium browser. The latest release of OBS at the time shipped a Chromium build that ran without its normal sandbox, and its V8 version was still vulnerable to `CVE-2024-7971`, a bug already…
6 min · 1,461 words
I asked Meta’s Muse for its filesystem and it sent me 6.8 GB
A security researcher asks Meta’s privileged Muse AI assistant to export its runtime filesystem—and receives a 6.8 GB dump that reveals how Muse is wired, what it can reach, and why that matters.
7 min · 1,501 words
Self-hosting LLM models for software development
Kévin Maschtaler on running medium-sized open LLMs on AWS Spot EC2 for day-to-day software work—what stacks, costs, and performance looked like versus a personal Claude subscription.
7 min · 1,719 words
Yang: the software factory behind Composio's toolkits
How Yang builds and repairs Composio toolkits with coding agents, durable sessions, automated code review, and production telemetry.
7 min · 1,714 words
Protobuf, JSON Schema, and OpenAPI
Buf explains how Protobuf schemas can drive JSON Schema and OpenAPI via protoc plugins—extending one source of truth into documentation, validation, and HTTP APIs without maintaining parallel definitions.
6 min · 1,373 words
Tailscale performance updates cut memory use, raise throughput, and speed startup via multi-queue, writev, and netmap caching—how the team measured and shipped the gains.
7 min · 1,640 words
How we made claude.ai 3x faster in two weeks
Anthropic’s performance sprint cut claude.ai and desktop p75 time-to-typeable from 3.1s to 0.55s: Claude Tag measured journeys, built benchmarks, and shipped thousands of guarded changes in Slack-driven loops.
18 min · 4,175 words
EXPLAIN (ANALYZE, IO) in PostgreSQL 19
Franck Pachot walks through PostgreSQL 19's new EXPLAIN IO stats—prefetch depth, request size, concurrency, and waits—using Little's Law to interpret async read streams.
4 min · 1,031 words
NEC V20 CPU: A bit of pep for an XT
A deep dive into the NEC V20 CPU as a drop-in 8088 upgrade for IBM PC/XT-class machines—what it changes, how fast it feels, and why collectors still care.
11 min · 2,628 words
Helix: The internal tool powering our Shopify app's native migrationSmall checkpoints and strict quality gates so LLMs can rebuild Swift and Kotlin shippably.
Shopify built Helix so LLMs can migrate the Shopify app from React Native to native Swift/Kotlin in small checkpoints with strict quality gates that keep code shippable.
8 min · 1,799 words
Everything Is a Stream: runtime composability over compile-time plugins
Antigma Labs stabilizes Ante v0.2.0’s Unix-inspired wire protocol—operations in, events out over stdio, sockets, or WebSockets—so agent engines stay separate from UIs while SemVer locks the streaming contract.
7 min · 1,520 words
A practitioner walkthrough of type punning pitfalls: why a pointer cast that works at -O0 can silently break at -O2, and how C versus C++ rules diverge in treacherous ways.
3 min · 585 words
How Google Agent Substrate Works: 250 Agents on 8 Pods
A technical breakdown of Google’s Agent Substrate: how it multiplexes hundreds of stateful agent sessions onto a handful of Kubernetes pods with fast suspend/resume.
11 min · 2,511 words
A file path looks like identity, but it is not: Ryan Galloway explains why treating paths as durable keys breaks pipelines, and what to use instead for content identity.
4 min · 1,016 words
Making portable my unportable transputer C compiler
Oscar Toledo recounts porting his 1990s transputer C compiler from 32-bit DJGPP assumptions to a modern 64-bit Mac—fixing int/pointer aliasing, FILE*, and self-hosting constraints along the way.
14 min · 3,196 words