Blog
Insights on software development, security, and technology from our team.
SQLite carried a corruption bug for 16 years. Here's why yours is probably fine, and what to check anyway.
Tailscale spent six months chasing database corruption that turned out to be a 16-year-old data race in SQLite's WAL mode. The fix landed in SQLite 3.51.3, but the real work for most teams is finding out which SQLite version they actually run and proving their backups restore clean. Here's what we'd do about it.

TypeScript 7.0 is 10x faster and written in Go. Here's how to adopt it without breaking CI.
Microsoft shipped the TypeScript 7.0 Release Candidate on June 18, 2026, and the big change is the compiler itself, now written in Go and roughly 10x faster than 6.0. It's a port rather than a rewrite, so the type rules stay the same. The smart move is to run it as a shadow CI job now and adopt it on your own schedule.

Node.js is dropping odd-versus-even. Here's how to plan your upgrades now.
Node.js is retiring the odd-versus-even release model that backend teams have leaned on for a decade. Starting with version 27, there's one major a year, every release becomes LTS, and a new six-month Alpha channel opens this October. Here's what that changes if you run Node in production, and the one CI job to add now.
Redis 8.8 finally has native arrays and a built-in rate limiter. Here's what to do with them.
Redis 8.8 just shipped with a native array data type and INCREX, a built-in rate-limiting command that replaces the hand-rolled Lua most teams run today. The features are genuinely useful, but the smart move isn't to upgrade on Friday. Here's how we'd approach it for a client, and the one audit worth doing this week regardless.

An AI agent nuked a production database in 9 seconds. Here's what went wrong.
A Cursor agent running Claude Opus 4.6 autonomously deleted a startup's entire production database and backups through a single API call. The incident exposes real gaps in how teams hand AI agents the keys to production infrastructure.

4 million developers on AI coding agents. Is anyone checking the output?
OpenAI's Codex hit 4 million weekly developers this month, up from 3 million just two weeks earlier. GPT-5.5 dropped the same week. Meanwhile, security research keeps showing that AI-generated code leaks secrets at double the human rate and nearly half of it contains known flaws. We break down what development teams should actually do about this.

AI is finding your bugs faster than you can patch them
Anthropic's Mythos model found thousands of zero-days in major software this week. A critical Python notebook flaw got exploited in 10 hours. The vulnerability window has collapsed, and most teams aren't ready.

AI agents are touching your keyboard now. What could go wrong?
Claude can now control your Mac, OpenClaw is going viral, and every AI lab wants their model clicking buttons on your behalf. Here's what development teams should actually worry about, and what to do about it.

Your AI coding tools are fast. Your pipeline isn't. That's the real problem.
This week's Harness DevOps report and Anthropic's new Code Review tool tell the same story: teams are generating code faster than ever, but testing, security, and deployment can't keep up. Here's what we think you should actually do about it.

Cursor's always-on coding agents are here. Are your teams ready?
Cursor launched Automations this week, letting AI coding agents run continuously without human prompting. We break down what this means for dev teams, code quality, and security posture.