Blog
Insights on software development, security, and technology from our team.

Node.js is dropping odd-versus-even. Here's how to plan your upgrades now.
Node.js is retiring the odd-versus-even release model that backend teams have leaned on for a decade. Starting with version 27, there's one major a year, every release becomes LTS, and a new six-month Alpha channel opens this October. Here's what that changes if you run Node in production, and the one CI job to add now.
Redis 8.8 finally has native arrays and a built-in rate limiter. Here's what to do with them.
Redis 8.8 just shipped with a native array data type and INCREX, a built-in rate-limiting command that replaces the hand-rolled Lua most teams run today. The features are genuinely useful, but the smart move isn't to upgrade on Friday. Here's how we'd approach it for a client, and the one audit worth doing this week regardless.

Android is officially Compose-first. Your View-based app is now legacy code.
At Google I/O 2026, Google made Jetpack Compose the official way to build Android UI and moved the View toolkit into maintenance mode. For the many production apps still built on Views, that turns a long-running question into a real decision. Here is how mobile teams should respond, without rewriting everything at once.

Apple and Google just made phones less sticky. Mobile teams need a new playbook.
iOS 26.5 shipped this week with wireless Transfer to Android, RCS end-to-end encryption, and a new App Store subscription tier. Hours later, Google's Android Show I/O Edition 2026 confirmed the cooperation runs both ways. Platform lock-in just got weaker, and that changes how mobile teams should think about retention and pricing.

Next.js just patched 13 security advisories. Self-hosted teams have the most work.
Vercel shipped a coordinated security release on May 7: 13 Next.js and React Server Components advisories covering DoS, SSRF, cache poisoning, and middleware bypasses in App Router. Self-hosted teams running Node are hit hardest. The deeper takeaway: middleware was never an authorization boundary.

An AI agent nuked a production database in 9 seconds. Here's what went wrong.
A Cursor agent running Claude Opus 4.6 autonomously deleted a startup's entire production database and backups through a single API call. The incident exposes real gaps in how teams hand AI agents the keys to production infrastructure.

4 million developers on AI coding agents. Is anyone checking the output?
OpenAI's Codex hit 4 million weekly developers this month, up from 3 million just two weeks earlier. GPT-5.5 dropped the same week. Meanwhile, security research keeps showing that AI-generated code leaks secrets at double the human rate and nearly half of it contains known flaws. We break down what development teams should actually do about this.

Three Windows zero-days are in the wild. One is patched. Here's what to do about the other two.
A frustrated researcher leaked three Windows privilege escalation exploits, attackers are already using them against enterprise targets, and only one has a patch. We break down what development teams should do right now.

AI is finding your bugs faster than you can patch them
Anthropic's Mythos model found thousands of zero-days in major software this week. A critical Python notebook flaw got exploited in 10 hours. The vulnerability window has collapsed, and most teams aren't ready.

The LiteLLM supply chain attack is a wake-up call for every team running AI tooling
A 40-minute window on PyPI compromised thousands of environments. The Trivy/LiteLLM supply chain attack is the biggest development security story of the week, and it has practical lessons for any team with unpinned Python dependencies.

Apple is pulling vibe-coding apps, and honestly, we get it
Apple removed the AI app-builder "Anything" from the App Store last week, citing code execution rules. It's the third vibe-coding tool Apple has targeted this month. Here's why this matters for every team building on iOS, and what to do about it.

AI agents are touching your keyboard now. What could go wrong?
Claude can now control your Mac, OpenClaw is going viral, and every AI lab wants their model clicking buttons on your behalf. Here's what development teams should actually worry about, and what to do about it.