
Hosted by Changelog Media · EN

Bitwarden’s CLI got hit by the Checkmarx supply-chain campaign, TypeScript 7.0 beta lands with the Go-rewritten compiler running ~10x faster than 6.0, and pgBackRest lost its maintainer of thirteen years leaving anyone running production Postgres with a real dependency-trust task this week. We’ve also got Ubuntu 26.04 LTS shipping with TPM-backed full-disk encryption, and Matz dropping Spinel as an AOT path that takes Ruby to native binaries. This week was a good reminder that the tools we depend on are all moving at once. Security, performance, and maintenance aren’t isolated threads. View the newsletterJoin the discussionChangelog++ members save 2 minutes on this episode because they made the ads disappear. Join today!Sponsors:Coder.com – Secure environments where devs and agents work in parallel. Open by design. Secure by default. Featuring:Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X

Astral is joining OpenAI, which says a lot about where the center of gravity is moving for developer tools, LiteLLM got hit by a nasty supply-chain attack, and OpenCode blew up as the latest serious open source swing at the coding-agent stack. We’ve also got Rust doing a very public reality check on its own pain points, WorkOS pushing AuthKit into CLI auth, Ryan Lizza using AI to build an open source TurboTax alternative, and a fresh httpx fork that turns open source maintenance drama into a real dependency story. If nothing else, this week was a good reminder that tools, trust, and control all move together. View the newsletterJoin the discussionChangelog++ members save 1 minute on this episode because they made the ads disappear. Join today!Sponsors:WorkOS – Auth for CLI with AuthKit from WorkOS — Bring secure browser-based login to your terminal apps using the OAuth Device Flow, with the same polished AuthKit experience plus SSO, MFA, and passkeys. Learn more at WorkOS.com and AuthKit.com Featuring:Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X

This week’s been wild — Iran bombed AWS data centers to take down Claude, OpenAI dropped GPT-5.4 (and it’s seriously good for coding), and living brain cells are literally playing DOOM. We’ve also got a heartfelt take on what it feels like to be a 10x engineer in the age of AI, plus some cool new tools like Handy for speech-to-text and web haptics. Oh, and new MacBook Pros with M5 Pro and M5 Max are up for pre-order. Try not to impulse buy (or do). View the newsletterJoin the discussionChangelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!Sponsors:Sonatype – Develop software fearlessly. Find out how at sonatype.com. Featuring:Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X

Wes McKinney on the mythical agent-month, install Peon Ping to employ a Peon today, Andreas Kling explains why Ladybird is adopting Rust, Cloudflare has a new MCP server that’s quite efficient, and Elliot Bonneville thinks the only moat left is money. View the newsletterJoin the discussionChangelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!Sponsors:Augment Code – Adam loves “Auggie” – Augment Code’s CLI that brings Augment’s context engine and powerful AI reasoning anywhere your code goes. From building alongside you in the terminal to any part of your development workflow. Featuring:Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X

Peter Steinberger joins OpenAI, ZeroClaw is “claw done right”, MimiClaw runs on a $5 chip, Steve Yegge on managing the AI Vampire, and the day the telnet died. View the newsletterJoin the discussionChangelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!Sponsors:Tiger Data – Postgres for Developers, devices, and agents The data platform trusted by hundreds of thousands from IoT to Web3 to AI and more. Featuring:Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X

Mitchell Hashimoto’s trust management system for open source, Nicholas Carlini has a team of Claudes build a C compiler, Stephan Schwab recounts the history of attempted developer replacement, NanClaw is an alternative to OpenClaw, and Sophie Koonin can’t wrap her head around so many people going so hard on LLM-generated code. View the newsletterJoin the discussionChangelog++ members save 1 minute on this episode because they made the ads disappear. Join today!Sponsors:Sonatype – Develop software fearlessly. Find out how at sonatype.com. Featuring:Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X

Jason Willems believes the tech monoculture is finally breaking, Don Ho shares some bad Notepad++ news, Tailscale’s Avery Pennarun pens a great downtime apology, Milan Milanović explains why you can only code 4 hours per day, and Addy Osmani on managing comprehension debt when leaning on AI to code. View the newsletterJoin the discussionChangelog++ members save 1 minute on this episode because they made the ads disappear. Join today!Sponsors:Tiger Data – Postgres for Developers, devices, and agents The data platform trusted by hundreds of thousands from IoT to Web3 to AI and more. Featuring:Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X

Clawdbot drives Mac Mini sales, Swizec Teller on the future of software engineering being SRE, Daniel Stenberg decided to end curl’s bug bounty program, zerobrew takes some of the best ideas from uv and applies them to Homebrew, and Phil Eaton on LLMs and your career. View the newsletterJoin the discussionChangelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!Sponsors:Tiger Data – Postgres for Developers, devices, and agents The data platform trusted by hundreds of thousands from IoT to Web3 to AI and more. Featuring:Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X

Armin Ronacher thinks AI agent psychosis might be driving us insane, Dan Abramov explains how AT Protocol is a social filesystem, RepoBar keeps your GitHub work in view without opening a browser, Ethan McCue shares some life altering Postgres patterns, and Lea Verou says web dependencies are broken and we need to fix them. View the newsletterJoin the discussionChangelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!Sponsors:Sonatype – Develop software fearlessly. Find out how at sonatype.com. Featuring:Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X

Linus Torvalds pushes AI generated code, Jordan Fulghum thinks this is the year of self-hosting, FracturedJson formats for compact / human readability, Scott Werner believes a flood of adequate software is coming, and Sean Goedecke explains why generic software design advice is useless. View the newsletterJoin the discussionChangelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!Featuring:Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X