直近1週間の更新
8/28 (金)
OpenClaw went viral. Meet the maintainers building and securing it.
The GitHub Blog
OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months.The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog.
14分前
8/27 (木)

Creating Web Widgets Using the Document Picture-in-Picture API
CSS-Tricks
The general idea is that we create a Document Picture-in-Picture window (DPIP window), and then we put HTML, CSS, and JavaScript into it.Creating Web Widgets Using the Document Picture-in-Picture API originally handwritten and published with love on CSS-Tricks. You should really get the newsletter as well.
2時間前

Personal website redesign project post: A CLI for adding new music to the collection
Piccalilli - Everything
Right, we are at the end of iteration one.The last thing to do is to make my life a little easier. Markdown files work perfectly fine for the music collection, but they're a bit of a faff. Mostly because I always forget the front matter structure, so to fix that, I created myself a Command Line Interface (CLI) which is a series of questions, resulting in a new item being added to the collection.I add a lot of music to my collection because I'm truly trying to get away from streaming platforms co
4時間前

Good riddance, TeamPCP. Now for the hard part.
Aikido Security's Blog
The AFP, FBI, and WA Police charged two men allegedly behind TeamPCP. Charlie Eriksen on why the arrest doesn't close the gap TeamPCP exposed.Category: News
5時間前

ChatGPT デスクトップの Codex から WebMCP 対応 TODO アプリを操作する
azukiazusa のテックブログ2
ChatGPT デスクトップの内蔵ブラウザが、Web サイトの機能を AI エージェント向けのツールとして公開する WebMCP に対応しました。この記事では WebMCP に対応した TODO アプリを実装し、Codex が呼び出した Site tools の引数や結果を実行履歴から確認します。
5時間前

How to customize the CKEditor UI: custom dialogs and forms
CKEditor Ecosystem Blog
Build custom dialogs in CKEditor 5 using HTML injection or the built-in Dialog plugin. Compare both approaches with a document management form example.
6時間前

Dev Machine Guard Now Inventories Where Developer Credentials Live
Step Security Blog
Dev Machine Guard now inventories where developer tools keep credentials. See which credential sources are in use across your fleet, how many devices each one affects, and how much of that material is sitting in plaintext. Credential values, fragments, hashes, and fingerprints are never stored, displayed, or sent off the device.
14時間前

Dev Machine Guard Now Inventories Browser Extensions on Developer Machines
Step Security Blog
Dev Machine Guard now inventories browser extensions across your developer fleet. See every extension installed in Chrome, Edge, and Firefox, what each one is currently permitted to do, whether it came from a marketplace or was installed some other way, and which devices are running it.
14時間前

Exploring Polyglot Monorepos with Nx, TanStack and Rust
Nx Blog
How to add Rust and the Topcoat web framework to an existing pnpm and Nx monorepo: one task graph, shared caching, and distributed CI across both stacks.
16時間前

Qwen3.8-Flash-Next Simon Willison's Weblog
<p><strong><a href="https://qwen.ai/blog?id=qwen3.8-flash-next">Qwen3.8-Flash-Next</a></strong></p>Another open weights model from Qwen. This one is "a multimodal MoE model that also serves as an early preview of the architecture used in Qwen4".</p><p>It's pretty big: 125B tokens, but only 6B active which means it gets a significant performance boost.</p><p>I've been trying it out on a DGX Spark using <a href="https://huggingface.co...
16時間前

Release Notes for Safari Technology Preview 251
WebKit
Safari Technology Preview Release 251 is now available for download for macOS Golden Gate and macOS Tahoe.
19時間前

GitHub Copilot app for Beginners: Automate Dependabot pull request triage
The GitHub Blog
Managing library updates can be tedious at times. Learn how the GitHub Copilot app can handle this type of repetitive task.The post GitHub Copilot app for Beginners: Automate Dependabot pull request triage appeared first on The GitHub Blog.
20時間前

Socket for ClickUp Is Now Available
Socket
Create ClickUp tasks from Socket alerts, automate ticketing with custom rules, and keep alert and task status synchronized.
21時間前

Top Minimus alternatives in 2026
Aikido Security's Blog
Minimus is shutting down. Compare Aikido, Chainguard, Docker Hardened Images, RapidFort, and Echo, and pick a hardened-image replacement that won't lock you in again.Category: DevSec Tools & Comparisons
1日前

animation-trigger
CSS-Tricks
The CSS animation-trigger property allows you to delay the start of a CSS animation until a specific trigger occurs.animation-trigger originally handwritten and published with love on CSS-Tricks. You should really get the newsletter as well.
1日前
8/26 (水)

Announcing Rspack 2.2
Rspack Blog
Rspack 2.2 is now available, featuring performance and HMR improvements, shorter module IDs, import.meta enhancements, and support for more platforms.
1日前

Rethinking Data Visualisation: A UX Approach To Dashboards That Actually Drives Decisions
Articles on Smashing Magazine — For Web Designers And Developers
Data visualisation sits at the intersection of two disciplines that rarely talk to each other: data and design. Meriem Benhabiles explores what changes when you bring structured UX thinking to dashboards and data presentations, from the questions you ask before opening any tool to the decisions that determine whether an insight actually lands.
1日前

Hover Proximity Using Modern CSS
1Master.dev Blog RSS Feed
You can always easily style :hover, but what if you want the NEXT item to have styling too? Or, just a smidge harder, the PREVIOUS item. How about multiple in any direction?
1日前

Software supply chain security requires decisions rather than defaults
Aikido Security's Blog
Most software runs on decisions nobody made. We talk about why gating, pinning, backporting, and SBOM upkeep only work if someone actually owns them.Category: News
1日前

Aikido Security achieves ISO 42001:2023 certification for AI governance
Aikido Security's Blog
Aikido Security has achieved ISO 42001 certification, the global standard for AI governance, covering AI pentesting, Code Security Audit, and Deep PR Review.Category: Compliance
1日前

Aikido launches agentic pentesting for Android apps
Aikido Security's Blog
Aikido's agents pentest your Android app and its backend in a single whitebox assessment. You get reproducible findings, AutoFix, and retests for every issue.Category: Product & Company Updates
1日前

Quoting Paul Dix Simon Willison's Weblog
<blockquote cite="https://pauldix.com/the-end-of-programming"><p>The fact that AI wrote 1M LOC and then refined it over the course of the next couple of months to produce a reliable piece of software that is currently running on millions of developer machines is absolutely mind blowing. And you can say, “well it’s not that impressive because they had an oracle to compare against, so it was simple to go from one language to another”, but I think that’s selling this entire thing short...
1日前

AI活用率100%のQA組織をつくるまで
1LINEヤフー Tech Blog (LY Corporation Tech Blog
本記事は、LINEヤフーの技術カンファレンス「Tech-Verse 2026」のセッション「10x Speed With QA Agent Platform — How we scaled adopt...
2日前

LINEヤフーのAgent iを支えるAIエージェント基盤:「誰でも作れる」と「安全に動かせる」をどう両立したか
2LINEヤフー Tech Blog (LY Corporation Tech Blog
LINEヤフーでは、ユーザーの目的に応じてさまざまなサービスや機能をつなぐAIエージェントサービス「Agent i」の開発を進めています。Agent iで多様なニーズに応えるには、現場のアイデアを素早...
2日前

DASH by Datadog 2026に登壇してきた
CyberAgent Developers Blog | サイバーエージェント デベロッパーズブログ
こんにちは。株式会社タップルでエンジニアリングマネージャーをしている山岸です。 この度、2026年6 ...
2日前

Why engineers should come to the SF Ruby Startup Conference in 2026
Evil Martians
The SF Ruby Startup Conference is an engineers' conference: meet the people building Ruby open source, scaling Rails in production, and shaping what agentic Rails looks like next.
2日前

Muse Image now available on AI Gateway
Vercel News
from Meta Superintelligence Labs is now available on AI Gateway. It is their first image model and a separate family from Muse Spark, returning images rather than text. Send a prompt and get an image back, or send an image with an instruction and get it changed. One model does both, so you don't switch models to move from generating to editing.Muse ImageTo use Muse Image, set to and call from the :modelmeta/muse-image-1.0generateImageAI SDKTo steer the result toward art you already have, pass re
2日前

Gemini 3.5 Transcribe now available on AI Gateway
Vercel News
from Google is now available on AI Gateway. It takes audio and returns text, in two variants:Gemini 3.5 TranscribeThe model detects the language on its own, covers 85+, and follows a speaker who switches language partway through. You can also supply custom vocabulary so it recognizes names, jargon, and spellings.Streaming transcription is new in AI SDK V7: opens the socket and takes a of raw audio chunks, so you can pass a microphone straight through. Tell it the format you are sending with :str
2日前

Qwen 3.8 Flash now available on AI Gateway
Vercel News
from Alibaba is now available on AI Gateway. It takes text and images as input, serves a context window of 1 million tokens, and can return up to 65k tokens in a response. Alibaba recommends it for coding, tool use, and multi-step agent workflows.Qwen 3.8 FlashTo use Qwen3.8-Flash, set to in the :modelalibaba/qwen3.8-flashAI SDKTo use it in a coding agent, see the , then run to connect agents like Claude Code, Codex, OpenCode, Cursor, Pi, and more and select inside the agent.coding agents guidev
2日前

GLM 5.3 Flash now available on AI Gateway
Vercel News
is now available on AI Gateway.GLM 5.3 Flash from Z.aiGLM-5.3 Flash is a multimodal model that supports text and vision input, with a 1M token context window. It supports function calling, structured output, and streaming. To use GLM-5.3 Flash, set to :modelzai/glm-5.3-flashYou can also pass images alongside text in a message. URLs and Base64 data URLs both work, and a request can include multiple images:To use it in a , run to connect agents like Claude Code, Codex, OpenCode, Cursor, Pi, and mo
2日前

Vercel Security Dashboard is now generally available
Vercel News
The Vercel Security Dashboard is now generally available on all plans, giving you one place to see your security posture across every account and project.You can access the Security Dashboard in or run in the Vercel CLI. the UIvercel security checkAs teams grow and coding agents make it faster to spin up projects, small misconfigurations add up quietly. The Security Dashboard automatically flags issues like:Misconfigurations are ordered by risk with the most severe first, and each finding links
2日前

Python projects now support routing rules
Vercel News
Python projects can now use to set response headers or rewrite requests to internal paths, including apps built with FastAPI, Django, and Flask.routing rulesThe evaluates rules before requests reach your application, so changes apply without a new deployment.Vercel CDNFor example, this FastAPI app serves a route:/newTo send requests for to that route, create a rewrite from the CDN tab in your project dashboard or with the :/oldVercel CLIPublished rules take effect immediately across all regions,
2日前

EVE Online: The Move to Python 3 Begins! Simon Willison's Weblog
<p><strong><a href="https://www.eveonline.com/news/view/the-move-to-python-3-begins">EVE Online: The Move to Python 3 Begins!</a></strong></p>EVE Online has been one of the most interesting case studies in Python at scale for over twenty years now.</p><p>They've been running on <a href="https://github.com/stackless-dev/stackless/wiki/">Stackless Python</a> since their launch in 2003, and their last major upgrade was 16 years ago, to St...
2日前

How to evaluate LLMs before production
The GitHub Blog
These are the lessons we learned evaluating LLMs for real-world secret scanning.The post How to evaluate LLMs before production appeared first on The GitHub Blog.
2日前

Socket for Asana Is Now Available
Socket
Create and manage Asana tasks directly from Socket alerts, with manual task creation, automated ticketing rules, and two-way sync.
2日前

Vercel applications are protected from Next.js August 2026 security vulnerabilities
Vercel News
SummaryImpact on Vercel deploymentsResolution for self-hosted applicationsCreditReferencesTwo vulnerabilities affecting Next.js were disclosed in the August 2026 Security Release. Next.js applications hosted on Vercel are protected and require no customer action. Next.js disclosed the following critical vulnerabilities: After the AVIF vulnerability was identified, Vercel applied protections to its managed Image Optimization service.Applications hosted on Vercel are protected. No upgrades, config
2日前

Speed Insights now has a free tier
Vercel News
now has a free tier that gives you a high-level performance overview from your real users. The new free tier: Speed InsightsInstall Speed Insights: Previously, free Speed Insights was limited to a single project on Hobby, and upgrading to Pro meant losing access unless you paid for the add-on. Now your free tier carries over, and you only pay if you upgrade.The paid product, now called Speed Insights Plus, includes deeper diagnostics and historical data. If you were already paying for Speed Insi
2日前
8/25 (火)

MicroLighter Master.dev Blog RSS Feed
A brand new 2 KB client-side syntax highlighter from Dave. Includes a web component for very easy usage. Maybe these web components have legs, eh? The most interesting part about it is that it doesn’t touch the DOM. It uses the Highlight API to colorize text and TextMate grammars (the same as in VS Code) […]
2日前

MicroLighter: Syntax Highlighter
CSS-Tricks
Syntax highlighting for code blocks without the complicated markup, spans, classes, and bloated JavaScript, courtesy of Uncle Dave.MicroLighter: Syntax Highlighter originally handwritten and published with love on CSS-Tricks. You should really get the newsletter as well.
2日前

Could OpenClaw have actually hacked that Australian gym? We decided to test it.
Aikido Security's Blog
We recreated the viral AI gym hack in a controlled environment. Running Opus 4.6 on OpenClaw, the model exploited the booking flaw in nine of ten runs.Category: Research
2日前

Why Your Website Should Never Stop Changing
Articles on Smashing Magazine — For Web Designers And Developers
Every website peaks on launch day and slowly drifts from there, not because it breaks, but because nobody has time to keep it current. Autonomous websites, continuously optimized by agents after launch, aim to change that. Pierre Burgy shares what they learned building for full website autonomy and the deeper design problem they uncovered along the way.
2日前

IndexedDB と React・Dexie.js でタスク管理アプリを作ってみる
azukiazusa のテックブログ2
IndexedDB は、構造化されたデータをブラウザへ保存できる非同期・トランザクション型のデータベースです。この記事では素の IndexedDB API で基本的な仕組みを確認した後、React と Dexie.js でタスク管理アプリを実装します。
2日前

Introducing Run SDK: secure eval for your agents
Vercel News
Agents increasingly write TypeScript programs to coordinate tools and process their results. Once those programs touch real applications, some steps require authentication, while others need human approval.Executing that code with gives it the same access as the application around it, including its secrets and internal services, and leaves no durable way to pause at those boundaries.evalToday, we're releasing the , a package for executing untrusted JavaScript and TypeScript without giving it dir
3日前

The end of credential sprawl for agents
1
Vercel News
Every useful agent reaches beyond your codebase. It posts to Slack, opens pull requests, queries Snowflake, or calls an internal API. That reach is what makes it valuable, and it's also where the risk lives, because for years, granting it meant provisioning a long-lived token and hoping it never leaked. replaces long-lived tokens with ones your code requests at runtime, scoped to the task and expiring on their own.Vercel ConnectDuring the , we've grown the ecosystem past 100 connectors, unified
3日前

Access control for AI agents on Rails: gating SQL with Action Policy
Evil Martians
Our Rails AI assistant had read-only SQL access and could still return peer review scores. Learn how we kept open-ended analytics in an in-app AI assistant while making database access honor application permissions.
3日前

MiniMax M3 and M2.7 are free on AI Gateway
Vercel News
and are free on AI Gateway via GMI Cloud through Sunday, September 6.MiniMax M3M2.7Use or to route requests to GMI Cloud. These model IDs will return an error after the free period ends.minimax/minimax-m3-freeminimax/minimax-m2.7-freeTo keep requests working after the free period, use the standard model ID without the suffix and place GMI Cloud first in the provider order:-freeAI Gateway tries GMI Cloud first and can fall back to another provider if GMI Cloud can't serve the request. This lets t
3日前

Wan 3.0 now available on AI Gateway
Vercel News
is now available on AI Gateway as .Wan 3.0 from Alibabaalibaba/wan-v3.0-videoWan 3.0 combines text-to-video, image-to-video, first- and last-frame conditioning, and reference-based generation in one model. References can include images, video, and audio. It generates clips up to 30 seconds at 30 fps in 480p, 720p, or 1080p, with synchronized audio. Previously, Wan 2.7 required separate and model IDs and was limited to 15-second clips at 24 fps.-t2v-r2vWan 3.0 supports , so no HTTP request needs
3日前

AI Gateway now supports asynchronous video generation
Vercel News
on AI Gateway can now run asynchronously. Video generationBy default, keeps one HTTP request to AI Gateway open until the result is ready. Because video generation can take seconds or minutes, that request can exceed request timeouts.generateVideoWith asynchronous generation, your application can receive a webhook, poll for completion, or start a generation and retrieve the result in a later request.Choose an option based on whether your process can keep running and whether your application can
3日前

Vercel Connect is now generally available
Vercel News
is now generally available on all plans and in . Instead of storing long-lived provider secrets, your code requests short-lived, scoped tokens at runtime. Deployments authenticate with their existing Vercel OIDC identity. Each token is scoped to the task, refreshed automatically, and expires on its own.Vercel Connectv0Register a connector . Pass the service name and the CLI pre-populates the brand name, icon, auth type, and MCP or discovery URL, then prompts for any credentials the service requi
3日前

Chat SDK now supports Slack Enterprise Grid
Vercel News
Chat SDK's Slack adapter now supports .Slack Enterprise GridBots installed org-wide work across every workspace, with correct token resolution, tenant-scoped caches, and event retry deduplication.The adapter now stores org-wide installations by enterprise ID. This matches how tokens are resolved for incoming events, slash commands, and interactive payloads. records the new identity fields:SlackInstallationToken resolution behaves the same over HTTP webhooks and Socket Mode. Events route by the i
3日前

Vercel Connect now supports Linq
Vercel News
now includes a managed connector for , so your apps and agents can send and receive messages over iMessage, RCS, and SMS.Vercel ConnectLinqAs a , Vercel can create a Linq account and phone number for you, or link an existing account. You never manage credentials yourself.Vercel Managed ConnectorCreate a connector from the or :dashboardVercel CLIThe connector powers the new in .Linq channeleveRun , choose Vercel Connect, and eve wires up the connector, phone numbers, and webhook for you:eve add c
3日前

Bring your agent to Notion with Chat SDK
Vercel News
Your team already works in Notion. Now your agent can too.With the new for Chat SDK, the same agent you run on Slack, Discord, GitHub, Teams, or WhatsApp can join comment discussions on your Notion pages, no separate codebase required.Notion adapterEach Notion page maps to a channel and each comment thread to a thread, so replies stay threaded automatically.The adapter supports mentions, message editing, conversation history, and up to three file attachments. By default, your bot replies when @-
3日前

Chat SDK now supports XChat
Vercel News
You can now build bots that hold end-to-end encrypted 1:1 and group conversations on XChat with the new for Chat SDK.XChat adapterThe adapter handles all encryption, key management, and signature verification automatically. Bots can also message users first, as long as the user has encrypted chat set up and follows the bot.XChat has no markdown rendering, so the adapter falls back automatically: URLs and @mentions render as tappable links, tables as ASCII code blocks, and cards as text with a li
3日前

How Bucketeer A/B Test Choose Which Version of Your Feature to Ship
CyberAgent Developers Blog | サイバーエージェント デベロッパーズブログ
Hi, I’m a backend engineer working on Bucket ...
3日前

SaaSの技術的難しさはホリゾンタルとバーティカルで異なる
57
カミナシ エンジニアブログ
はじめに カミナシでSWEをしている osuzu です。 筆者はSaaSと呼ばれる業務ソフトウェア開発を前職含め6年ちょっと経験し、最近ようやく言語化できたことがあります。 それは「SaaSの技術的な難しさは、ホリゾンタルかバーティカルかで種類が異なる」ということ。そしてより重要なのは、この2つの戦いを混ぜてしまうと、どちらの戦い方も難しくなるということです。 前提: ホリゾンタルSaaSとバーティカルSaaS 念のため用語を揃えておきます。 ホリゾンタルSaaS: 業界を問わず横断的に使われるSaaS。チャット、タスク管理、通知、ドキュメントなど。SlackやNotion、Google Do…
3日前

Your alt text passes automated checks. That doesn’t mean it’s any good.
1
The GitHub Blog
We built a plugin for the GitHub Accessibility Scanner to make sure your alt text is actually accessible. Here's how it works.The post Your alt text passes automated checks. That doesn’t mean it’s any good. appeared first on The GitHub Blog.
3日前
The Cloudflare Blog – Brought to you by EmDash
1
Cloudflare Blog
We migrated the Cloudflare Blog to EmDash to prove our stack at massive scale. Here is how we stress-tested performance, safely routed production traffic, and redesigned the frontend experience.
3日前

llm-anthropic 0.27 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/llm-anthropic/releases/tag/0.27">llm-anthropic 0.27</a></p> <p>This release of the Anthropic plugin for <a href="https://llm.datasette.io/">LLM</a> mainly provides compatibility with the recently released <a href="https://github.com/anthropics/anthropic-sdk-python/releases/tag/v1.0.0">anthropic v1.0.0</a> Python library, which switches from <code>httpx</code...
3日前

Elastic build machines now use Turborepo cache hits to prevent downgrades
Vercel News
now consider cache hits when deciding whether to use a smaller build machine. A warm-cache build no longer triggers a downgrade. Elastic build machinesTurborepoA warm-cache build can use less CPU and memory than the same build with a cold cache. Downgrading based on that lower usage could leave a later cold-cache build without enough resources to complete successfully.This change applies automatically to all builds using Elastic build machines. No action is required. Learn more in the .build doc
3日前

Intent to Ship: JPEG XL
1Mozilla Hacks – the Web developer blog
It isn’t often that new image formats land in browsers. In the early 2000s we had JPEG, GIF, and PNG. The 2010s gave us WebP, which was a modest step up from JPEG. But the 2020s have given us two new image formats that are a big step up from previous formats: AVIF and JPEG […]The post Intent to Ship: JPEG XL appeared first on Mozilla Hacks - the Web developer blog.
3日前
8/24 (月)

CKEditor 5 v48.4.0 Release Highlights: AI Context Library and Image Understanding
CKEditor Ecosystem Blog
CKEditor AI now works from your own prompts and files, fits what your editor is set up to do, and understands the images in your document. Table editing and formatting around widgets are also improved.
3日前

WordPress PHP-Only Block Registration
CSS-Tricks
Seven and half years after blocks arrived in Core, WordPress introduces a way to build blocks without React annd build pipelines. All you need is PHP.WordPress PHP-Only Block Registration originally handwritten and published with love on CSS-Tricks. You should really get the newsletter as well.
3日前

Design Systems + Horizontal @layer Master.dev Blog RSS Feed
My post Thinking Horizontally in CSS @layer got Stuart Robson thinking about how to pull it off at a bigger scale. Stu is right that our components are essentially hand-written, whereas with a more enterprise-scale design system, design tokens are more likely to come from a build pipeline. That got Dave Rupert thinking about how […]
3日前

Introducing Sandcastle Master.dev Blog RSS Feed
"Let's say you have 4 issues that can be implemented simultaneously..."
3日前

Your executable is a SQLite database Simon Willison's Weblog
<p><strong><a href="https://fzakaria.com/2026/08/23/your-executable-is-a-sqlite-database">Your executable is a SQLite database</a></strong></p>Farid Zakaria describes a neat Linux pattern for creating a SQLite database file that can be directly used as an executable binary.</p><p>The trick sets the SQLite file format's 4-byte application ID (68 bytes into the file) to SELF, standing for Structured Executable &amp; Linkable Format. The various ...
3日前

How Aikido finds more vulnerabilities than Mythos at half the cost
Aikido Security's Blog
Aikido AI Code Audit found 8 more vulnerabilities than Claude Security with Mythos at less than half the cost. How harness design drives coverage per dollar.Category: Research
3日前

ドメイン移行を通して、インフラからアプリまで値の流れを追った1か月
2
CyberAgent Developers Blog | サイバーエージェント デベロッパーズブログ
はじめに こんにちは!2026年7月の1か月間、「CA Tech JOB」に参加した池畑です! 株式 ...
3日前

Shai-Hulud was the best thing to happen to supply chain security
Aikido Security's Blog
npm Trusted Publishing sat near-idle after it was released. Then Shai-Hulud and 14 more supply chain attacks pushed adoption 3.4x. Charlie looks at the data behind it.Category: News
3日前

Open VSX Unblocks Extension IDs Used in Malware Campaign
Socket
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
3日前

Vercel Sandbox is now globally available
Vercel News
now runs globally, starting with four regions: (Washington, D.C.), (San Francisco), (Cleveland), and (Paris). Vercel Sandboxiad1sfo1cle1cdg1 remains the default. Support for all Vercel regions is coming soon.iad1Choose a region close to the databases, object storage, and other services your sandboxes access to reduce latency. Region selection is available on all plans. Pro and Enterprise teams can also configure failover regions. If the primary region is unavailable, new sandboxes start in the c
4日前

PR TIMESの認証認可を再設計するときに考えたこと
2PR TIMES 開発者ブログ
PR TIMESでCTOをやっている金子 (@catatsuy) です。 2023年に、PR TIMESのログインシステムへJWTを導入したことを開発者ブログで紹介しました。 この記事では、JWTの仕様や移行の進め方など […]
4日前

ESLint v10.9.1 released
ESLint Blog
HighlightsThis patch release fixes false positives in the no-loss-of-precision rule that were introduced in v10.9.0.Bug Fixes1e641c9 fix: no-loss-of-precision false positive with trailing decimal point (#21251) (Aleksandr Shoronov)Documentationad74a8d docs: add deprecation steps for EOL package versions (#21248) (Francesco Trotta)Chores3c3ae53 chore: update ecosystem plugins (#21249) (ESLint Bot)
4日前

pnpm 11.24
pnpm Blog
pnpm 11.24 brings back pnpm approve-builds --global, which isolated global installs took away in v11.0, and makes recursive batch publishing group its packages by registry so a credential mismatch is caught before anything is published. It also stops --frozen-lockfile from failing over the pnpm version the lockfile pins.
4日前

Environment variables now use Config and Secret types
Vercel News
When you add or edit an environment variable in Vercel, you now choose Config or Secret instead of using the Sensitive toggle. Existing variables marked Sensitive are automatically treated as Secrets and continue to work without migration.You can select an environment or Preview branch for each value. The in the dashboard shows each variable’s type and where it applies.environment variable listThe team policy is deprecated with this update. When enabled, it required every environment variable cr
4日前

Bun runtime now supports large functions and extended max duration
Vercel News
The on Vercel Functions now supports larger package sizes up to 5GB uncompressed and extended max duration for up to 30 minutes, two betas that previously ran on Node.js and Python only.Bun runtimeLarge functions raise the standard 250MB package size limit to 5GB, and extended max duration raises the generally available 800-second ceiling to 1800 seconds for Pro and Enterprise teams. Both features require to be enabled. New projects are enrolled in the large functions beta automatically, while e
4日前

Connect v0 apps to Slack, Google, and 100+ other services
Vercel News
Apps and agents built in v0 can now securely connect to , including Slack, Google, Notion, GitHub, and Salesforce, through .more than 100 servicesVercel ConnectAsk v0 to connect your app to a service. It opens the connector setup and guides you through it.You set up each connector once for your team, then reuse it across apps.For managed connectors like Slack and GitHub, Vercel handles app registration, so you don’t need to create or configure an app with the provider. For other services, you ca
4日前

AIエージェントにGoogle Cloudの操作を任せるためのガードレール ─ Google Cloud PAMの導入
CyberAgent Developers Blog | サイバーエージェント デベロッパーズブログ
はじめに 株式会社AJA でバックエンドエンジニアをしている片山です。 AJA DSP では、Goo ...
4日前

AWS re:Invent 2026 に行こうか悩んでいるあなたへ(あるいは2年前の自分へ)
11
カミナシ エンジニアブログ
今年も AWS re:Invent がラスベガスで開催されますね。私は去年初めて現地参加し、今年も参加する予定です。この記事では、今まで現地参加に消極的だった私が、去年悩んだ末に初参加して感じた「現地参加すべき理由」を紹介します。もし、この記事をきっかけに現地参加を決めた人がいたら X(saramune) で連絡をください。現地でお会いできたら、ぜひ一緒にご飯でも食べながら AWS 談義をしましょう!(私が美味しいお店を探しておきます!) なお、本記事は AWS さんの連載「「ラスベガス5日間で得たもの」── re:Invent に賭けたスタートアップのリアル」にて、弊社 CTO がインタビュ…
4日前

The State of Open Source Supply Chain Attacks
Step Security Blog
StepSecurity threat intelligence tracked 56 open source supply chain attacks from August 2025 to August 2026, roughly one every three days since March. See the data and the defenses.
4日前

Anthropic’s best AI model struggles to attract users as cheaper tools thrive Simon Willison's Weblog
<p><strong><a href="https://www.ft.com/content/5ee49718-c258-4f01-aa32-7e5b76ae5245">Anthropic’s best AI model struggles to attract users as cheaper tools thrive</a></strong></p>A few interesting numbers in this FT story gathered from "people with knowledge of the matter":</p><ul><li>Anthropic's "annualized revenue" for July is up to $65bn - it was $47bn in May, and I collected <a href="https://simonwillison.net/2026/May/29/anthropic/">...
4日前

Quoting Drew Breunig Simon Willison's Weblog
<blockquote cite="https://www.dbreunig.com/2026/08/23/fable-the-end-of-moore-s-law.html"><p>Prior to Fable, it felt silly to waste <em>too</em> much time improving your coding harness or context strategies. A new model would arrive at the same price (or cheaper!) and paper over most of your problems.</p><p>But then Fable landed. It was (and still is!) <em>incredible</em>. But the cost was so high and Opus was <em>good enough</em> (as w...
4日前
8/23 (日)

Vitest のモックを using で自動的に復元する
azukiazusa のテックブログ2
Vitest で作成したスパイを復元し忘れると、別のテストへモックの状態が漏れるおそれがあります。Vitest 3.2.0 以降では `vi.spyOn()` の戻り値を `using` で宣言すると、スコープを抜けるときに元の実装を自動的に復元できます。この記事では `using` による自動復元の仕組みを紹介します。
4日前

pnpm 11.23
pnpm Blog
pnpm 11.23 gives the registries setting a shape that describes each registry once — its tarball layout, the scopes routed to it, the prefix it answers to — so an Artifactory or GitLab registry can finally keep its tarball URLs out of pnpm-lock.yaml. It adds virtualStoreType, makes undeclared imports resolve under ESM with the global virtual store without a plugin, teaches pnpm config get to report the settings pnpm actually acts on, and warns about settings no pnpm version recognizes.
5日前

Quoting Linus Torvalds Simon Willison's Weblog
<blockquote cite="https://github.com/torvalds/linux/commit/818bebeb63dd6bf5f4e07e145f6cdbace520a34c"><p>And this was a debug session from hell, enormously helped by an AI doing much of the grunt-work.</p><p>I'd like to call it my tireless helper, but the AI several times stated flat out that this was impossible and unsolvable and that we should just write a report about it.</p><p>I suspect those things have been trained by people who may not be quite as stubb...
5日前

llm 0.33 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/llm/releases/tag/0.33">llm 0.33</a></p> <p>My highlights from this release:</p><blockquote><ul><li>Upgraded to the OpenAI Python library 3.x and switched the HTTP client dependency from <code>httpx</code> to <code>httpx2</code>. <a href="https://github.com/simonw/llm/issues/1608">#1608</a>, <a href="https://github.com/simonw/llm...
5日前

More than just code review Simon Willison's Weblog
<p>The key skill required to make productive use of coding agents is being able to confidently instruct them on how to make changes and then confidently verify that those changes have been applied in the correct way.</p><p>Sometimes this involves reviewing every line of code they have written, but there are other ways to achieve that goal. Eyeballing every line of code has never been the most effective way to validate a change to a piece of software.</p> <p>Tags: &...
5日前
8/22 (土)

Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper
1
Step Security Blog
Three Rust crates are compromised: arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 each added a typosquatted build-time dependency (proc-macro1, proc-macro-en) whose build script downloads and runs a remote binary during cargo build. Full technical analysis: timeline, dropper dissection, runtime detection, IOCs, and remediation.
5日前

AI に技術ブログを書かせてみてわかったこと
azukiazusa のテックブログ2
AI が書いた記事は一般論に寄りすぎ、冗長になりやすいと考えていたため、これまでは誤字脱字の確認にだけ AI を使っていました。AI に任せる執筆フローを試したところ、生成稿を批判的に読み、自分の体験を加えて推敲すれば、学習効果は大きく失われないと感じました。この記事では、実際に試した方法について紹介します。
5日前

Slack 上でオープンな開発を行う Slack Code を試してみた
42
azukiazusa のテックブログ2
Slack Code は Slack 上でオープンな開発を行う手段を提供する機能です。コードチャンネルと呼ばれる特別なチャンネルを作成し、チーム全体でコーディングエージェントとやり取りを行うことができます。この記事では Slack Code を実際に試してみた感想を紹介します。
6日前

Vim's UserGettingBored autocmd Evan Hahn (dot com)
In short: Vim has a joke autocmd called UserGettingBored that doesn’t do anything.Vim’s automatic commands feature, usually shortened to “autocmd”, lets you run code when various events occur. For example, you could implement an auto-save feature by binding the TextChanged event to the :w command.Vim has over 100 events, from “buffer was created” to “file was saved”. But one of them sticks out to me: UserGettingBored. Here’s the documentation:UserGettingBored: When the user presses the same key
6日前

proto v0.61 - Swift support, GPG verification, and immutable lockfiles
moonrepo Blog
A new language joins the toolchain, downloads can now be verified with GPG signatures, and
6日前

Say it once: introducing Bot Preference Sync
Cloudflare Blog
Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.
6日前

How Ora benchmarks every major AI agent on Vercel
Vercel News
Ora on VercelEvery harness expects its own infrastructureOne platform under every harnessTesting eve like any other harnessThe framework behind Ora's own agentsFront end, back end, and agent runtime on one platformEvery major agent tested side by side on live sitesHundreds of commits a day from a 16-person engineering team7% fewer steps to reach the goal2x native success: twice as many tasks finished on the customer's own site instead of falling back to web search9% more valid endpoints: more of
6日前

Top image hardening tools in 2026
1
Aikido Security's Blog
Image hardening tools compared for 2026: Aikido, Chainguard, Docker, RapidFort, Echo, Minimus, and WizCategory: DevSec Tools & Comparisons
6日前

Best enterprise AI pentesting tools for application security in 2026
Aikido Security's Blog
Compare the top enterprise AI pentesting tools of 2026: Aikido, XBOW, NodeZero, Pentera, Hadrian, and Cobalt.Category: DevSec Tools & Comparisons
6日前

PHP and Composer Support Is Now in Beta
Socket
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.
6日前

llm 0.32.1 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/llm/releases/tag/0.32.1">llm 0.32.1</a></p> <p>Fresh installs of LLM stopped working the other day because the OpenAI Python library dropped its usage of <code>httpx</code>, and it turned out LLM depended on that library but only installed it via a transitive <code>openai</code> dependency.</p><p>This dot-release fixes that for the moment by pinning to &l...
6日前

llm-openrouter 0.7 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/llm-openrouter/releases/tag/0.7">llm-openrouter 0.7</a></p> <p>Now that this plugin is compatible with <a href="https://simonwillison.net/2026/Aug/4/new-release-of-llm/">LLM 0.32</a> it can display the reasoning traces for LLMs available through OpenRouter.</p><blockquote><ul><li>Updated for compatibility with <a href="https://llm.datasette.io/en/stabl...
6日前

Stop Making TUIs Simon Willison's Weblog
<p><strong><a href="https://sockpuppet.org/blog/2026/08/20/stop-making-tuis/">Stop Making TUIs</a></strong></p>Thomas Ptacek advocates for building real native user interfaces for even the smallest of personal tools, because coding agents have reduced the cost of getting a usable-enough GUI up and running to almost nothing.</p><p>I wrote about my vibe-coded bandwidth and GPU monitoring macOS task bar apps <a href="https://simonwillison.net/2026...
6日前

Resolved: CSS Class Prefix Selector
CSS-Tricks
A newly resolved proposal would allow us to select classes that are a prefix for variations with a wildcard, like .prefix-*.Resolved: CSS Class Prefix Selector originally handwritten and published with love on CSS-Tricks. You should really get the newsletter as well.
6日前

Quoting Matt Webb Simon Willison's Weblog
<blockquote cite="https://interconnected.org/home/2026/08/21/galactic"><p>After I released version 1.0, I figured I would have to do the rotations myself. So I sat down with ChatGPT and I didn’t get it to write the code, but I got it to educate me. With a patient, interactive tutor, I was able to finally do what I hadn’t by reading books and asking mathematician friends – I learnt how to use quaternions just enough to make the app work.</p><p>So learning doesn’t stop jus...
6日前
8/21 (金)

What is CVE remediation in 2026?
Aikido Security's Blog
CVE remediation is fixing known flaws in the software you run. Why upgrading often fails, what remediation actually involves, and how backporting fixes it.Category: DevSec Tools & Comparisons
6日前

Keyboard Shortcuts That Display The Correct Modifier Key per OS Master.dev Blog RSS Feed
Websites often hardcode keyboard shortcuts for Mac (⌘) while neglecting Windows users, leading to confusion.
6日前

The Bun CVE Gap, Closed: Surgical Updates Land in Bun 1.4
Nicolas Charpentier's Blog
Three months ago, I wrote that Bun was the only mainstream package manager that couldn't do surgical CVE remediation. Bun 1.4 ships in-place transitive updates, bun audit fix, and nested overrides. Time to re-run the original reproductions.
6日前

The Index: Issue #195
Piccalilli - Everything
BulletedThis is the stuff that's exciting about the AT protocol. Not the "new twitter" bullshit, but the endless possibilities that this technology opens up. It's using the fancy new private data stuff too.The future of CSS: target multiple classes with the class prefix selectorAs Bramus says in the article, we can sort of do this already, but those substring selectors don't perform well. This new method is a very good improvement!Ruminations on notificationsA good write-up on how annoying and h
6日前

We burned 11.7bn tokens to find the best cyber AI model
Aikido Security's Blog
We tested 10 AI models on 32 fresh CVEs. DeepSeek V4 Pro found 28, and three cheap runs beat one pass of Opus 5 or Grok on total coverage.Category: Research
6日前

Deployment Storage keeps your deployments rollback-ready
Vercel News
Every deployment produces a set of files, including the pages, functions, and assets Vercel serves. Deployment Storage keeps those files available so you can inspect previous deployments and roll back when needed.Instantly roll back to previous deployments in secondsIf a production deploy ships a bug or a change you want to reverse, rolling back restores the previous version in seconds. Open your project, click on the Production Deployment tile, then choose an earlier production deployment. Verc
6日前

Cottontail, Electrobun 2.0, and Why I Decided to Jian-Yang Anthropic Blackboard Blog
Electrobun 2.0 introduces Cottontail, Hutch, a polyglot Zig core, and Warren—a new foundation for tiny, fast desktop apps across TypeScript, Zig, Rust, Go, and Odin.
7日前

ESLint v10.9.0 released
ESLint Blog
HighlightsNew option checkConditionalExpressions in no-unmodified-loop-conditionThe no-unmodified-loop-condition rule now supports a checkConditionalExpressions option.When enabled, each branch in a ternary expression is checked independently.For example, with { "checkConditionalExpressions": true }, the rule reports the done variable as not modified in the loop:let chunk = getInitialChunk();let done = false;while (chunk ? !done : false) { chunk = nextOrNull();}123456Copy code to clipboard Featu
7日前

GPT-5.6 Sol is now 50% off a lower price
Vercel News
OpenAI lowered list pricing for , and the 50% AI Gateway now applies to the new, lower price through September 18. Input drops 20%, output drops a third. GPT-5.6 SoldiscountThe discount applies on every OpenAI service tier:Rates are per million tokens for requests up to 272K tokens. Cached tokens, cache writes, long-context requests above 272K, and the US regional rates all move by the same proportion. See the for all model rates.pricing pageThe model ID is unchanged, so requests you already sen
7日前

DeepSeek V4 Flash Vision Experimental now available on AI Gateway
Vercel News
is now available on AI Gateway.DeepSeek V4 Flash with visionThis model is an experimental version that accepts images alongside text. You can ask it to describe a picture, read text out of a screenshot, or work through a chart in the same request as your prompt. DeepSeek V4 Flash Vision Experimental now available on AI Gateway. Tool use, reasoning, and caching all work the same as before.Use to get started:deepseek/deepseek-v4-flash-vision-expImages can be JPEG, PNG, GIF, or WebP. The format is
7日前

Always-on tracing for production and preview traffic
Vercel News
With always-on tracing, you can now debug your real user requests without reproducing them.Always-on tracing continuously collects traces from your production and preview traffic. Unlike , which only captures requests from your own browser, it samples your live traffic. session tracingYou control what's collected with sampling rules. Each rule sets a trace rate for an environment (All, Production, or Preview), optionally scoped to a path prefix like . Nothing is collected until you add a rule, s
7日前

Microfrontends previews now link across repositories
Vercel News
Microfrontends can now link Preview Deployments across repositories when their Git branch names match exactly.In a monorepo, projects share the same Git repository, commits, and branches, so Vercel can automatically link their previews. Cross-repository projects have separate commit histories and branches in separate repositories. With this update, Vercel matches Git-connected projects by branch name and links their corresponding previews.For example, when you preview the branch of one project,
7日前

ChatGPT search now uses the site:operator at scale Simon Willison's Weblog
<p><strong><a href="https://promptwatch.com/data/chatgpt-site-operator-fanouts">ChatGPT search now uses the site:operator at scale</a></strong></p>Promptwatch is part of the emerging "GEO" space, for Generative Engine Optimization - the chatbot version of SEO, where companies offer tools and consulting to help your site increase its presence in replies to prompts inside tools like ChatGPT.</p><p>The Promptwatch product uses automation to track res...
7日前

Socket Now Protects the Firefox Extension Ecosystem
Socket
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.
7日前

The August 17 outage, and the work ahead
19
The GitHub Blog
An update on the August 17 outage and the steps we're taking to improve reliability.The post The August 17 outage, and the work ahead appeared first on The GitHub Blog.
7日前

Manage Vercel Toolbar comments from the CLI
Vercel News
You can now use the to manage comments. covers the full triage loop:Vercel CLIVercel Toolbarvercel commentsStart by listing all of the unresolved comments in the current branch:Dig deeper into a specific thread:Reply, resolve, edit:Update to the latest Vercel CLI version and run . Or just prompt your coding agent: vercel commentsLearn more in the .comments CLI docsRead moreList and filter unresolved comments for the linked project, scoped to your current Git branchInspect a full thread with ever
7日前

CSS Infinity Use Cases Master.dev Blog RSS Feed
It’s kinda cool there is Infinity in CSS. You just always need to use it within a calc(), like border-radius: calc(infinity * 1px);. Adam has lots of ideas in that post, and I remember Will was messing with similar ideas a few years ago. I’d say just use it when you’re trying to use an […]
7日前

From all-or-nothing to task-based OAuth consent
1
Cloudflare Blog
Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.
7日前

Custom metrics are now supported in Vercel Observability
Vercel News
You can now emit your own metrics directly from your Vercel Functions and analyze them alongside Vercel's built-in observability data.Use the function from the package to record any value you care about, like request latency or business events, and attach attributes to filter and group by:metric()@vercel/functionsOnce emitted, your custom metrics are available across Observability:• slice and aggregate metrics on the fly.• build and share dashboards.• query using the command.Query builder:Notebo
7日前










