直近1週間の更新
9/30 (水)
How Config Safety Protects NGINX Ingress Controller from Invalid Configuration
NGINX Community Blog
NGINX Ingress Controller turns Kubernetes resources into NGINX configuration. Many of those inputs are free-form text: snippet annotations on Ingresses, snippets on VirtualServers, and in the global ConfigMap. A typo in any of them can produce configuration that NGINX refuses to load. Config safety makes sure such a mistake stays with the resource that introduced it. Configuration […]
2時間前

Under Autumn’s Spell (October 2026 Wallpapers Edition)
Articles on Smashing Magazine — For Web Designers And Developers
October is just around the corner, which means it’s time for some new desktop wallpapers! Designed by the community for the community, they’re here to brighten your screens, and maybe spark some creativity along the way.
2時間前

Cloudflare Impact reaches $100 million in donations
Cloudflare Blog
This week, Cloudflare's Impact programs will reach $100 million in donated services. This milestone means that thousands of entities including journalists, civil society, state and local governments, election management bodies, and public schools are being protected from cyberattacks.
3時間前

Cut your AI spend with AI Gateway's Auto Router
Cloudflare Blog
Cloudflare AI Gateway now features a model router that evaluates request complexity using an edge-deployed classifier to select the optimal model. By balancing expected output quality against token costs, organizations can dramatically cut AI spend while maintaining performance.
3時間前

Detect and send production issues straight to your agent
Cloudflare Blog
You can now use built-in error monitoring in Cloudflare Workers to group production failures and send stack traces, logs, traces, and application context directly to a coding agent to investigate further and open a pull request.
3時間前

Simplifying domains for people and agents
Cloudflare Blog
Cloudflare Registrar’s new search delivers fast, transparent results across 420+ extensions using Workers, Durable Objects, and WebSockets. Its expanded API and cf CLI also let agents search, register, and transfer domains.
3時間前

Monetization Gateway beta: charge AI agents for consumption with HTTP 402
Cloudflare Blog
Cloudflare’s AI Gateway, Ceramic.ai, Stocktwits, and more are using the Cloudflare Monetization Gateway today to charge agents for access to tokens, APIs, and MCP tools. U.S.-based sellers can now apply for access to the closed beta.
3時間前

Pay Per Use: when AI uses your work, you should get paid
Cloudflare Blog
Pay Per Use is now in beta. AI companies report when they use publishers’ content, and Cloudflare handles billing, payouts, and reporting, so our customers are paid according to use.
3時間前

Identify AI model overuse with User Insights
Cloudflare Blog
AI Gateway User Insights now adds task, model, turn, and user categories to help teams understand AI adoption and make better model decisions. This is available free to AI Gateway users.
3時間前

Cloudflare Containers, rebuilt to scale agent sandboxes
1
Cloudflare Blog
Cloudflare Containers now start 6x faster, let your agent choose each sandbox's image and instance type at runtime, and support filesystem snapshots in public beta, all controlled from a Durable Object.
3時間前

The Internet has a second audience
Cloudflare Blog
More than half the traffic reaching sites on Cloudflare is now automated, and AI agents are the fastest-growing part of it. We're giving site owners the tools to see who's visiting, decide who gets in, and charge for access.
3時間前

Notes from September 2026 Evan Hahn (dot com)
If you follow my monthly roundups, (1) who are you?? please say hi (2) you’ll notice a smaller post this time. September was a busy month for me.Lots of feedback on a small postI published “Anecdotally, programmers dislike ‘reduce’”. I finally wrote up a phenomenon I’ve observed for years. It’s a short post that didn’t take long to write.I got a tremendous volume of feedback—more than anything I’ve ever written. Dozens of messages, hundreds of comments, shoutouts in popular newsletters…I’m even
10時間前

プライベートクラウドにおけるサービス間通信の今、そして「サービス指向クラウド」が作る未来 LINEヤフー Tech Blog (LY Corporation Tech Blog
こんにちは。LINEヤフーで、プライベートクラウドのネットワーク関連サービスを開発している清水です。現代の大規模なWebサービスにおいては、一つのモノリシックなアプリケーションだけで構成されることは少...
14時間前

個人で育てたAIエージェント設定を、チームの資産にする(APMによるSkill・指示・MCPの配布とマルチエディタ展開) LINEヤフー Tech Blog (LY Corporation Tech Blog
こんにちは、LINEヤフー株式会社の殿山雄大です。普段は社内のGPU/AI基盤の構築・運用を担当しています。本記事では、2026年7月16日(木)に開催した社内ワークショップOrchestration...
14時間前

Amazon RDS for PostgreSQLにpgAuditを導入し、監査ログで事後調査に備える
PR TIMES 開発者ブログ
こんにちは。PR TIMESでインターンをしている河野拓真です。 今回、Amazon RDS for PostgreSQLにpgAuditを導入し、監査ログを取得できるようにしました。 PostgreSQLの標準ログでも […]
15時間前

What's new in Astro - September 2026
The Astro Blog
September 2026 - Astro Germany, Evil Martians migration story, and more!
16時間前

Example.com Just Launched The Biggest Redesign In Decades
DebugBear Blog
A look at the history of visual changes to example.com.
16時間前

Quoting Anthropic Frontier Red Team Simon Willison's Weblog
<blockquote cite="https://www.anthropic.com/research/glm-5-3-and-the-spread-of-advanced-cyber-capabilities"><p>We evaluate several models on 100 tasks from the [internal Binary Exploitation benchmark] (selected at random), and find that GLM-5.3 develops full control flow hijacks in 4% of the trials; Claude Mythos Preview did so in 6%. Although GLM-5.3 performs below Claude Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and ...
17時間前

Vercel Connect now accepts service submissions
Vercel News
now lets you submit your own service to the , so you no longer need to wait for Vercel to build a connector for it.Vercel Connectconnectors directorySubmitting a service takes four steps:Vercel reviews each submission before publishing it to the directory.Get started from in the dashboard, or read what your service needs to support in the .Submit a ServicedocumentationRead moreDescribe your service.Add one or more connection methods, using OAuth or an API key.Verify each OAuth method by requesti
18時間前

Modern Web Types
Master.dev Blog RSS Feed
The web platform evolves. When it does, other tech has to catch up, and not just LLMs. Another one is TypeScript types. Philip Walton explains: For example, here’s an error I got just the other day when trying to use element-scoped view transitions: “Property ‘startViewTransition’ does not exist on type ‘HTMLElement’.” … TypeScript makes it […]
19時間前

GPT 6.1 Sol: Near-Astra intelligence for a fifth of the price Simon Willison's Weblog
<p><a href="https://news.ycombinator.com/item?id=49896586#49898129">My comment</a> on <a href="https://news.ycombinator.com/item?id=49896586">GPT 6.1 Sol: Near-Astra intelligence for a fifth of the price</a> &mdash; Hacker News.</p><p>I'm a bit late with the pelicans because I was live-blogging the keynote: <a href="https://simonwillison.net/2026/Sep/29/openai-devday-2026-live-blog/">https://simonwillison.net/2026/Sep/29/openai-devday-2026-liv...
21時間前

Photo Scrubber — local face blur & metadata removal
Simon Willison's Weblog
<p><strong>Tool:</strong> <a href="https://tools.simonwillison.net/photo-scrubber">Photo Scrubber — local face blur &amp; metadata removal</a></p> <p>I took a photograph of some protesters, then thought about how I don't like sharing photographs of strangers with identifiable faces. I <a href="https://github.com/simonw/tools/commit/aa733ecc3458d5703e3b40c84507ae362f5fb294">had GPT-6 Astra build</a> this experimental tool that would ident...
1日前

OpenAI DevDay 2026 live blog Simon Willison's Weblog
<p>I'm at <a href="https://devday.openai.com/">OpenAI DevDay</a> today, in Fort Mason, San Francisco. Same as <a href="https://simonwillison.net/2025/Oct/6/openai-devday-live-blog/">last year</a> I'll be live blogging the keynote and some other notes during the day.</p><p><em>OpenAI gave me a free ticket and a seat in the "creator" area for the keynote.</em></p> <p>Tags: <a href="https://simonwillison.net/tags/ai">ai</a&...
1日前

upm Launches as a Fast, Tiny Package Manager Written in TypeScript
1
Socket
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
1日前

Developer policy update: Transparency, state policy, and what’s ahead
The GitHub Blog
Explore GitHub’s latest transparency data and learn more about policy updates affecting developers and open source.The post Developer policy update: Transparency, state policy, and what’s ahead appeared first on The GitHub Blog.
1日前
9/29 (火)

Using AI to chart a course for our post-quantum migration
Cloudflare Blog
We’re building CryptoLabe, an internal AI-powered tool that discovers cryptography across our codebase, surfaces dependencies, and helps us progress toward a full post-quantum migration by 2029. Here’s what we’ve learned so far.
1日前

Building a certificate authority for the whole Internet
14
Cloudflare Blog
Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web.
1日前

Adaptive application security for the AI era: how Cloudflare connects code, traffic, and intelligence to stop attacks
Cloudflare Blog
Cloudflare introduces an adaptive security framework connecting risk discovery, agent governance, runtime protection, and AI-powered response in a continuous learning loop.
1日前

Building a post-quantum certificate authority with Merkle Tree Certificates
Cloudflare Blog
As post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs, Merkle Tree Certificates offer a path to compact, auditable authentication. Cloudflare’s new certificate authority will support MTC issuance at scale.
1日前

We tested our own WAF with frontier AI models. Here’s what we found
Cloudflare Blog
We built a WAF tester that adapted each request based on what the WAF blocked or passed. This helped us explore variations that a fixed test might miss. We ran it across six attack categories on an authorized staging environment and discovered detection gaps worth fixing. Here’s how the loop worked, what got through, and what we did about it.
1日前

Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account
Cloudflare Blog
We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extracts structured indicators, and connects threat context directly to your WAF rules.
1日前

Is your domain using post-quantum encryption? Now you can see for yourself
Cloudflare Blog
Cloudflare has added visibility into post-quantum (PQ) encryption in TLS 1.3 directly into HTTP Analytics, Log Explorer, and Logpush. Learn how to make sure your domain is protected with PQ encryption.
1日前

Enforce positive security with Cloudflare Application Profiles
Cloudflare Blog
Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate and vary payloads.
1日前

Preventing quantum downgrade attacks against IPsec
Cloudflare Blog
A sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication extension to prevent these attacks.
1日前

Search trace spans from the Vercel CLI
Vercel News
You and your coding agents can now search a project’s trace spans from the terminal with . vercel traces searchEach span represents one step in a request, helping you investigate errors, latency, and security-related behavior without opening the dashboard.By default, returns up to 100 spans from the last hour, newest first, so you can search without first finding a request or trace ID. Filter results by environment, service, span name, status, deployment ID, request ID, trace ID, or span ID, or
1日前

PR TIMES は PHPカンファレンス愛媛2026に協賛・登壇します!#phpcon_ehime
PR TIMES 開発者ブログ
自己紹介 こんにちは、PR TIMESでエンジニアをしている中山です。 このたび、2026年10月3日(土)に愛媛大学城北キャンパスで開催される「PHPカンファレンス愛媛2026」に、PR TIMESが協賛します。 また […]
1日前

チームの記憶を検索可能にしたら、AIにタスクを丸ごと任せられるようになった
1LINEヤフー Tech Blog (LY Corporation Tech Blog
こんにちは。LINEヤフーのプラットフォーム部門でメトリクスチームに所属している千葉です。普段は、全社のサービスを支える大規模モニタリングプラットフォーム「Yamas」の開発と運用に取り組んでいます。...
2日前

Kafkaアラートの初動調査を支援するAI Alert Watcherの開発(インターンレポート)
1LINEヤフー Tech Blog (LY Corporation Tech Blog
はじめにこんにちは。法政大学情報科学部3年の霍 永豪と申します。2026年8月17日〜9月11日の4週間、社内のデータ基盤に使われているKafkaを運用するチームでインターンとして参加し、Grafan...
2日前

Look Mum, No Executors
Nx Blog
Nx v24 removes the built-in executors deprecated in Nx v23. See how inferred targets cut your configuration overhead, and convert your workspace with a single command.
2日前

Polypane 31: Canvas layout, elements panel improvements and Chromium 155
Polypane Blog
This release has a new canvas layout that lets you freely arrange panes on an infinite canvas. The elements panel now lets you filter styles…
2日前

GPT-6.1 Sol now available on AI Gateway
Vercel News
from OpenAI is now available on AI Gateway. It improves on GPT-6 Sol for coding, computer use, and professional work, including reading complex documents and carrying out multi-step workflows.GPT-6.1 SolThe model is suited to agents that need to debug code, work through business tasks, or extract answers from PDFs with tables and charts. It also improves factual accuracy on difficult questions. Its standard input and output pricing is lower than GPT-6 Astra's, while cheaper cached input makes it
2日前

Claude Sonnet 5.5 Simon Willison's Weblog
<p><strong><a href="https://www.anthropic.com/claude-sonnet-5-5">Claude Sonnet 5.5</a></strong></p>New Sonnet model from Anthropic today. They say it "runs 30%+ faster, and costs up to 30% less for most work" - it's priced the same as Sonnet 5 but appears to beat it on every benchmark, and should be cheaper to run as well.</p><p><a href="https://tools.simonwillison.net/markdown-svg-renderer?url=https%3A%2F%2Fgist.github.com%2Fsimonw%2F1d85a9be7...
2日前

Quoting @joedaroo Simon Willison's Weblog
<blockquote cite="https://twitter.com/joedaroo/status/2104335929293127851"><p>To say that we were surprised at the jump and suddenness of the capabilities of our models when it came to “cyber” or “swarming” or “message boards” or anything else related to the incidents is an understatement. Security posture takes time to develop. It’s not just about hardening the systems at play; you have to ingrain it in the culture of the company. The literal people themselves in your organization ...
2日前

How we found 24 Android vulnerabilities using our open source AI security agent
1
The GitHub Blog
A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app.The post How we found 24 Android vulnerabilities using our open source AI security agent appeared first on The GitHub Blog.
2日前

Highlights from Git 2.56
12
The GitHub Blog
The open source Git project just released Git 2.56. Here is GitHub's look at some of the most interesting features and changes introduced since last time.The post Highlights from Git 2.56 appeared first on The GitHub Blog.
2日前

Introducing cf: the agentic CLI for the entire Cloudflare API
49
Cloudflare Blog
We are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator.
2日前

Aikido funds Node.js security
Aikido Security's Blog
Aikido is an inaugural partner in OpenJS's Security Stewardship Program, funding bug bounties and maintainer support for Node.js.Category: Product & Company Updates
2日前

Making the Most of Vercel’s AI SDK with Cloudflare Durable Objects
Master.dev Blog RSS Feed
Let's integrate Vercel's AI SDK with Cloudflare's Durable Objects to improve user experience in a fitness tracker application.
2日前
9/28 (月)

Next.js applications, powered by Vite: introducing Vinext 1.0
3
Cloudflare Blog
Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an automated testing pipeline.
2日前

Quoting Muse AI Agent Simon Willison's Weblog
<blockquote cite="https://www.threads.com/share/_oWfPufYJ/"><p>Bad news on the MX Keys Mini pickup. Usman showed up at your building around 9:15 and waited, messaged a bunch of times, and nobody came down. He left angry at 9:38 and left a negative rating.</p><p>Worse, my auto-reply told him "Yep I'm here!" at 9:27 when you clearly weren't available, which is on me. That's a bad look and it made the no-show worse.I've sent him an apology from your account owning it and of...
2日前

2026年10月の技術系イベント予定 LINEヤフー Tech Blog (LY Corporation Tech Blog
LINEヤフー株式会社では、技術に関するイベントや勉強会の主催・協賛などを行っています。最新情報は各リンク先でご確認ください。タイミングによっては、申し込み開始前や既に満席となっていることがあります。...
3日前

Decaton Per-Key-Quotaによるプッシュ通知のスパイク制御(インターンレポート) LINEヤフー Tech Blog (LY Corporation Tech Blog
はじめにこんにちは、東京電機大学大学院理工学研究科情報学専攻修士 1 年の佐藤聖璃です。インターンとして、LINE公式アカウントのプッシュ通知の配信基盤に Decaton の Per-Key-Quot...
3日前

pnpm 12.8
pnpm Blog
pnpm 12.8 warns when pnpm pack or pnpm publish would ship a .env file, installs sharedWorkspaceLockfile: false workspaces concurrently, applies every setting passed as --config.=, and no longer leaves the Windows terminal stuck after Ctrl+C in a script. This release also carries a...
3日前

Announcing Vite+ 1.0
22
VoidZero
TL;DR: Vite+ 1.0 is out, stable, MIT licensed, and about to reach two million weekly downloads. A single command, vp, manages your Node.js runtime, package manager, and frontend toolchain. Install it with curl -fsSL https://vite.plus | bash, then run vp create for a new project or vp migrate to migrate your existing one.
3日前

Search domains without authentication
Vercel News
You can now discover domain names and check availability and pricing without signing in to Vercel or providing an access token. This works through the Vercel CLI and Domains Registrar API.With the , search by keyword or domain fragment: Vercel CLIWith the , check up to 200 exact domain names in one request. The response shows whether each can be registered and, when available, its registration and renewal prices:Domains Registrar APIAuthentication is still required to buy or manage domains.Try t
3日前

Claude Sonnet 5.5 now available on AI Gateway
Vercel News
from is now available on as .Claude Sonnet 5.5AnthropicAI Gatewayanthropic/claude-sonnet-5.5Sonnet 5.5 improves on for well-scoped everyday work, from building features and fixing bugs to creating documents, slides, and spreadsheets.Claude Sonnet 5On coding tasks, Sonnet 5.5 carries changes through multiple steps and checks its work before reporting completion. It produces more polished documents, slides, and spreadsheets with fewer follow-up edits, and writes clearer explanations and reports. I
3日前

Vercel Sandbox now supports memory observability
Vercel News
now includes memory usage data.Vercel Sandbox observabilityYou can access sandbox memory usage data in the dashboard and through the CLI via the command. vercel metricsThe Memory Usage card reports average, P75, and P95 memory across your sandboxes, alongside the existing CPU usage and data transfer metrics on the sandbox overview page and the project and team-level pages.On the sandbox detail page, charts are designed to show how close a sandbox is running to its memory ceiling by: Sandbox memo
3日前

2026 in LLMs (so far)
1Simon Willison's Weblog
<p>On Friday I gave the closing keynote at the <a href="https://www.wearedevelopers.com/world-congress-north-america">WeAreDevelopers World Congress North America</a> in San Jose. I tied together the key trends from the past year into a chronological exploration of everything that happened in 2026. The video <a href="https://www.youtube.com/watch?v=GAkIytR7vcc">is on YouTube</a>; here are my annotated slides and notes to accompany the talk.</p><p><li...
3日前

S3 Is the Future, S3 Is the Past Simon Willison's Weblog
<p><a href="https://news.ycombinator.com/item?id=49851693#49871741">My comment</a> on <a href="https://news.ycombinator.com/item?id=49851693">S3 Is the Future, S3 Is the Past</a> &mdash; Hacker News.</p><p>One thing I find notable about S3 today is that, while it used to drop in price reasonably often, there hasn't been a price drop in <em>a full decade</em>:</p><pre><code>2006-03-14 $0.150/GB-month2010-11-01 $0.140/GB-...
3日前

Bluesky reply bot checker Simon Willison's Weblog
<p><strong>Tool:</strong> <a href="https://tools.simonwillison.net/bluesky-bot-check">Bluesky reply bot checker</a></p> <p>Automated reply bots on Twitter are a <em>scourge</em> - as someone with a decent number of followers I attract a swarm of these, such that anything I post there attracts dozens of mindless automated replies.</p><p>They've started manifesting on Bluesky as well.</p><p>Unlike Twitter, Bluesky still...
3日前
9/27 (日)

iframe の高さをコンテンツに合わせる CSS の frame-sizing
azukiazusa のテックブログ2
外部サービスのコメント欄やフォームを iframe で埋め込むと、内容の高さと枠の高さが合わず、スクロールや余白が生じることがあります。frame-sizing を使うと、埋め込み側の許可のもとで内容に応じた高さを使えます。
4日前

Introducing Ferry
@dlhck — David Höck
Sync your coding-agent skills, instructions, plugins, and MCP server declarations to a remote Linux box. An introduction to Ferry, with setup instructions and terminal examples.
4日前

Ember-1 from Fireworks now available on AI Gateway
1
Vercel News
from Fireworks is now available on .Ember-1AI GatewayEmber-1 is a research preview reasoning model built on for coding and agentic workflows.Kimi K3Fireworks reports approximately 40% fewer generated tokens than Kimi K3 at comparable quality across its evaluations. For coding agents that make repeated model calls, shorter reasoning traces can reduce output costs and the amount of context carried into later steps.Ember-1 supports a 1M-token context window, text and image input, tool calling, and
4日前

Kākāpō Party
1Simon Willison's Weblog
<p><strong>Tool:</strong> <a href="https://tools.simonwillison.net/kakapo-party">Kākāpō Party</a></p> <p>I presented a closing keynote for the <a href="https://www.wearedevelopers.com/world-congress-north-america">WeAreDevelopers World Congress North America</a> yesterday. As <a href="https://simonwillison.net/2019/Dec/10/better-presentations/">a STAR moment</a> I decided to weave in references to the record breaking <a href="...
4日前
9/26 (土)

CSS の scroll-axis-lock で斜め方向にスクロールできる UI を作る
azukiazusa のテックブログ2
ブラウザはスクロール操作の方向を縦か横の一方向に固定することがあります。scroll-axis-lock プロパティを使うと、この軸ロックを解除できます。この記事で scroll-axis-lock の基本的な使い方を紹介します。
4日前

Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
5日前

GitHub Copilot app for Beginners: How to build custom workflows with canvases
The GitHub Blog
Describe the interface you need in plain English, then let the agent build a live surface you can both use and update—so you spend less time adapting to tools and more time getting work done.The post GitHub Copilot app for Beginners: How to build custom workflows with canvases appeared first on The GitHub Blog.
5日前

Quoting John Gruber Simon Willison's Weblog
<blockquote cite="https://daringfireball.net/linked/2026/09/25/aten-muse"><p>Muse is getting a lot of attention — including mine — because it’s both groundbreaking technically (each user gets their own entire persistent Linux VM running in Meta’s cloud) <em>and</em> because it’s packaged in an easy-to-install easy-to-use way. It’s literally presented as <a href="https://daringfireball.net/linked/2026/09/24/song-meta-muse-cute">a cute mascot</a>. It’s the firs...
5日前

Randomly Place an Element Along Edge of Another Element
1
Master.dev Blog RSS Feed
We can animate an element along the border edge of another element to random positions... pretty easily? Might as well be a cute dog.
5日前

Improving site performance by shipping more CSS
14
The GitHub Blog
How we fully migrated github.com away from CSS-in-JS.The post Improving site performance by shipping more CSS appeared first on The GitHub Blog.
5日前
9/25 (金)

The Index: Issue #199
Piccalilli - Everything
Blurry before beautiful: image previews for the webA very good looking proposal!The root scroller and how not to lose itYet another in-depth, fantastic article by Kilian at Polypane.fonts.xyzYou know us by now: we see a good place to get fonts and we share it. This is a very nice offering with loads to choose from.“AI, make the website good”With these seismic changes, I will continue to make the argument that craft defined as caring about the quality of output (independent of the tools used to g
5日前

Push images to Vercel Container Registry from GitHub Actions
Vercel News
You can now push container images from GitHub Actions to (VCR) without storing long-lived registry credentials.Vercel Container RegistryThe new action authenticates your workflow using GitHub OIDC. It exchanges the workflow’s OIDC token for a short-lived Vercel access token, then uses that token to log in to . When the job ends, the action logs out and revokes the Vercel token.vercel/vcr-action/loginvcr.vercel.comTo start: Then add the login step before you build and push and the image:The actio
5日前

State of agent skills
Vercel News
In seven months, the registry grew to one million agent skills and recorded nearly 280 million installs.skills.shA skill gives an AI agent reusable instructions for a particular job. Agents are capable but generic; they can do many jobs, but they don't know how a specific person, team, or company does them. A skill supplies that missing context and can be as simple as a file written in ordinary language. Anthropic introduced in October 2025, and Vercel launched the registry three months later.Ag
5日前

Northern Gannet, Great Blue Heron, California Brown Pelican Simon Willison's Weblog
<p><img src="https://static.inaturalist.org/photos/740453177/large.jpg" alt="Northern Gannet"></p><p><img src="https://static.inaturalist.org/photos/740453341/large.jpg" alt="Great Blue Heron"></p><p><img src="https://static.inaturalist.org/photos/740454506/large.jpg" alt="California Brown Pelican"></p><p>Northern Gannet, Great Blue Heron, California Brown Pelican, in Monterey Bay National Marine Sanctuary, CA, US, CA</p><p>...
6日前

pnpm 12.7
pnpm Blog
pnpm 12.7 lets the global node shim follow .nvmrc and .node-version, adds pnpm install --allow-build and pnpm publish --publish-wait-timeout, and creates pnpm-workspace.yaml from the workspaces field of package.json. pnpm install --force no longer installs optional dependencies built for other...
6日前

pnpm 11.28
pnpm Blog
pnpm 11.28 adds the forceIgnoresPlatform setting and pnpm update --peer, and brings a large batch of fixes from pnpm 12 to the JavaScript CLI: pnpm deploy, --filter, nodeLinker: hoisted, and custom modulesDir setups all behave better. It also carries security fixes for shell completion, bin...
6日前

Vercel Marketplace database browser now supports Redis
Vercel News
You can now run Redis commands, browse keys, and inspect values directly in the Vercel dashboard using the .Marketplace database browserBoth the and integrations in Vercel Marketplace are supported, so you no longer need or a separate database UI.RedisUpstash for Redisredis-cliFrom your project, open and select a Redis database. The database page now includes two new tabs:Infrastructure > StorageThese tabs are currently available only to team members with the Owner role. Learn more in the .Ma...
6日前

Pixel Canary is now available in stealth for free on AI Gateway
Vercel News
is now available on as . It's free for a limited time while in stealth.Pixel CanaryAI Gatewaystealth/pixel-canaryPixel Canary is strong at coding, including building applications and refactoring existing code. It is well suited to frontend development and mobile app design, from responsive layouts and app screens to navigation and interactive components.On , Pixel Canary ties at a 90.3% baseline success rate, passing 28 of 31 tasks. With Next.js documentation supplied through , it passes 30 of 3
6日前

Crafting WCAG 3 for more accessible user experiences
Web Accessibility Initiative (WAI)
In the W3C blog post Crafting WCAG 3 for more accessible user experiences, W3C WAI Director Shawn Lawton Henry covers some of the stakes and challenges in developing W3C Accessibility Guidelines (WCAG) 3.
6日前

Note on 24th September 2026 Simon Willison's Weblog
<p>The more time I spend working with coding agents, the more convinced I am that they make software engineering even harder.</p><p>We can do amazing things with them, but unlocking their full potential requires extraordinary discipline and knowledge.</p> <p>Tags: <a href="https://simonwillison.net/tags/coding-agents">coding-agents</a>, <a href="https://simonwillison.net/tags/ai">ai</a>, <a href="https://simonwillison.net/tags/llms">ll...
6日前

Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Socket
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
6日前

commit-rewriter 0.2 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/commit-rewriter/releases/tag/0.2">commit-rewriter 0.2</a></p> <blockquote><p>Support for branches other than the default branch. Use <code>uvx commit-rewriter --branch other</code> to run against another branch. <a href="https://github.com/simonw/commit-rewriter/issues/3">#3</a></p></blockquote> <p>Tags: <a href="https://simonwillison.net/t...
6日前

When chat is the wrong UI
1
The GitHub Blog
What is a developer to do when they need something more tangible than a chat box? Enter canvases.The post When chat is the wrong UI appeared first on The GitHub Blog.
6日前

datasette 1.0a41 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/datasette/releases/tag/1.0a41">datasette 1.0a41</a></p> <p>Alec Garcia added <a href="https://docs.datasette.io/en/latest/internals.html#internals-telemetry">support for OpenTelemetry</a> to Datasette in this release.</p><p>I've also refactored all of Datasette's modal dialogs to a single Web Component, which is now <a href="https://docs.datasette.io/en/latest/jav...
6日前

Top CodeQL alternatives in 2026
Aikido Security's Blog
Top CodeQL alternatives compared on noise, fixes, cost, and more: Aikido Security, Semgrep, Snyk Code, SonarQube, Checkmarx, and VeracodeCategory: DevSec Tools & Comparisons
6日前

AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
The GitHub Blog
In this blog post, I explain how to use the new fuzzing taskflow based on the GitHub Security Lab Taskflow Agent AI framework. The post AI-powered fuzzing with the GitHub Security Lab Taskflow Agent appeared first on The GitHub Blog.
6日前
9/24 (木)

100 Devs
Master.dev Blog RSS Feed
Kevin Powell is doing game-show-style (specifically Family Feud) shorts where, using data from a survey of 100 devs, he asks another dev what the most popular answers were. Here’s:
6日前

Public Packages
vlt /vōlt/ | blog
Explore the JavaScript ecosystem without an account, and publish packages from your own registry for anyone to install.
6日前

The Vercel Bug Bounty Program is now publicly available
Vercel News
In 2022, we launched a private bug bounty program through HackerOne. Over the last several years, we've worked with HackerOne's VIP program to refine our process, targets, and scope, onboarding thousands of their best researchers and hardening security across our platform. We've translated those learnings into several public bounty programs: Today, we are combining our private and OSS bounty programs into a single, public . Vercel bug bounty programAI has fundamentally changed the nature of bug
6日前

How Klaviyo shipped 356 internal apps in two weeks on Vercel
Vercel News
Klaviyo on VercelImplementing safeguards across the stackBuilt a platform for shipping internal apps512 builders and 356 live apps in two weeksEvery app ships SSO-gated and private by defaultBuilders go from idea to live app in 3 minutes Apps are private and SSO-gated through OktaSensitive environment variables are set at the team level, out of builders' handsKlaviyo's hardened GitHub security is inherited by every projectWiz scans every project, and findings feed Klaviyo's SIEMPublic deployment
6日前

itch.io で Posting Puzzle を公開しました
2
まめめも
itch.io で Posting Puzzle というゲームを公開しました。封筒と切手を対応付けるだけの小さなブラウザパズルです。全 12 ステージ。 mametter.itch.io ルールは口頭で説明するより、実際に触ってみてもらったほうがわかりやすいと思うので、遊んでみてください。 以下ネタバレ 元ネタ これはポストの対応問題(Post correspondence problem 、以下 PCP)という決定不能問題をほぼそのままゲームにしたものです *1 。「ポスト」は郵便ポストではなく、問題の考案者の名前(Emil Post)です。 決定不能なので、この問題の汎用ソルバーを書くこと…
7日前

How Legora Cut CI Maintenance in Half
Nx Blog
How a three-person platform team at Legora halved their CI config, drove sandbox violations to zero, and stopped hand-tuning shards across 600+ projects.
7日前

Vercel Connect now supports TanStack AI
Vercel News
Agents built with TanStack AI can now call OAuth-protected MCP servers through Vercel Connect, with no credentials for you to store or rotate.The new subpath exports , which takes a TanStack transport config and attaches a Connect-backed auth provider. The provider is called before every MCP request, so the token is always fresh.@vercel/connect/tanstack-aiconnectMCPTransportIf the user has not granted access, fails with a consent challenge before the model runs. Catch it with and redirect to Con
7日前

We just shipped support for the ugliest part of HTTP: Vary Simon Willison's Weblog
<p><a href="https://news.ycombinator.com/item?id=49823195#49823961">My comment</a> on <a href="https://news.ycombinator.com/item?id=49823195">We just shipped support for the ugliest part of HTTP: Vary</a> &mdash; Hacker News.</p><p>I've been wanting this from Cloudflare <em>for years</em>.</p><p>The classic problem here is if you do that thing where user agents that send "accept: text/html" get HTML, while user agents that do...
7日前

Release Notes for Safari Technology Preview 253
WebKit
Safari Technology Preview Release 253 is now available for download for macOS Golden Gate and macOS Tahoe.
7日前

Malicious Firefox Extension Poses as PDF Identity Verifier to Hijack Google Accounts
Socket
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.
7日前

Rendering huge pull requests in the GitHub Copilot app
1
The GitHub Blog
How we rebuilt the diff surface in the GitHub Copilot app to open a million-line pull request with hundreds of inline review comments.The post Rendering huge pull requests in the GitHub Copilot app appeared first on The GitHub Blog.
7日前

Unlimited Vercel Blob stores on every plan
Vercel News
You can now create as many stores as you need. The previous limits of 100 stores on Hobby, 500 on Pro, and 1,000 on Enterprise no longer apply.Vercel BlobBlob store creation is now billed alongside other , including , , and calls. On Pro that's $5.00 per million. On Hobby it counts toward the 2,000 free operations you get each month. Deleting a store is free.Blob Advanced Operationsput()copy()list()Create a new store whenever you want a hard boundary instead of a pathname convention:Storage, ope
7日前

Gemini 3.8 TTS Playground Simon Willison's Weblog
<p><strong>Tool:</strong> <a href="https://tools.simonwillison.net/gemini-tts-playground">Gemini 3.8 TTS Playground</a></p> <p>Google <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-8-text-to-speech/">released two new Gemini text-to-speech models</a> today - <code>gemini-3.8-flash-tts</code> and <code>gemini-3.8-flash-lite-tts</code>.</p><p>They come with a library...
7日前

Shadow roots, explained with live examples Simon Willison's Weblog
<p><strong>Tool:</strong> <a href="https://tools.simonwillison.net/shadow-roots">Shadow roots, explained with live examples</a></p> <p>Prompt to Fable 5.1 Medium:</p><blockquote><p><code>Build an artifact to explain shadow roots in CSS with interactive examples</code></p></blockquote> <p>Tags: <a href="https://simonwillison.net/tags/css">css</a></p>
7日前

Introducing Solo
Master.dev Blog RSS Feed
A versatile tool for managing coding projects, integrating multiple terminals and AI agents within a single control panel.
7日前

Top Greptile alternatives in 2026
Aikido Security's Blog
We compare the top Greptile alternatives in 2026 on coverage, noise, review depth and more: Aikido Security, CodeRabbit, Qodo, Graphite, SonarQube and CodeAnt AICategory: DevSec Tools & Comparisons
7日前






