Week Notes 25#50 (3 mins read).
What happened in the week of 2025-12-08?
Week Notes 25#50 (3 mins read).
What happened in the week of 2025-12-08?
This post requires authentication to view.
blur the hands as a bit, no one will ever know
Alex Kretzschmar joins Adam for a trip down the Linux rabbit hole -- Docker vs Podman, building a Kubernetes cluster, ZFS backups with zfs.rent, bootc, favorite Linux distros, new homelab tools built with AI, self-hosting Immich, content creation, Plex and Jellyfin, the future of piracy and more.
Between and I took 5784 steps.
SummaryIn this episode of the Overcommitted Podcast, Erika and Brittany discuss the evolving landscape of AI agents and their implications for security and identity management. Joined by expert Dan Moore, they explore the challenges posed by non-deterministic agents, the importance of granular permissions, and the need for developers to be aware of security practices as AI technology advances. The conversation also touches on industry standards, the role of developers in navigating these changes, and personal reflections on the future of AI.TakeawaysAI agents are changing the landscape of software development.Non-deterministic agents present new security challenges.Granular permissions are essential for securing AI agents.Developers must be aware of security practices in AI.Industry standards for AI security are still evolving.Separation of concerns can enhance security for agents.The role of identity and authorization is critical in AI.Business implications of AI agents are significant.Developers should stay close to business needs and problem-solving.The future of AI will require new skills and awareness. LinksDan Moore on LinkedIn: www.linkedin.com/in/mooreds/ Dan Moore on Bluesky: https://bsky.app/profile/mooreds.comSimon Willison - The Lethal Trifecta: https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ FusionAuth: https://fusionauth.io/ AGNTCY: https://agntcy.org/Amazon Bedrock AgentCore: https://aws.amazon.com/bedrock/agentcore/ FusionAuth Guide to OAuth: https://fusionauth.io/articles/oauth/modern-guide-to-oauth MCP and OAuth: https://aaronparecki.com/2025/04/03/15/oauth-for-model-context-protocol MCP Specification: https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization HostsOvercommitted: https://overcommitted.devBrittany Ellich: https://brittanyellich.com Eggyhead: https://github.com/eggyhead

Welcome back to Break, a Fallthrough aftershow! In this episode, the panel continues their conversation from Fallthrough #49.Enjoying the aftershow? Let us know on social media! If you prefer to watch instead of just listen, head over to YouTube where you watch this episode of Break!Thanks for...

Another Cloudflare outage. A CVSS 10.0 React RCE vulnerability. We've been dealing with quite a lot these last few weeks. In this week's episode, Kris and Matt discuss the outage and vulnerability and have a deeper discussion about project management and how all of these things relate to each...

This may be the version 45 release of Breaking Change, but when you factor in its Hotfixes and Feature Release entries, this is somehow the 50th episode of the…

Between and I took 4872 steps.
pastrami fries, bitch
Between and I took 5640 steps.
I’ve started using the term HTML tools to refer to HTML applications that I’ve been building which combine HTML, JavaScript, and CSS in a single file and use them to …

Code review heuristics for reviewing AI-generated code.

Just got to present at AI Dev Days! What a cool event, I've seen a few of the other presentations now leading up to mine and it has been such a great learning opportunity 😄
Attached: 1 image me blowing dust off my unposted lifenotes from nearly a year ago

introducing .🥺, the world’s first bottom-level domain
Attached: 1 image are you...you know...tramsgender?

Strengths: works well under pressure Weaknesses: doesn’t work otherwise
you’re very popular on linkedin (DEROGATORY)
Attached: 1 image Windows erasing your Linux bootloader

Visit https://cupogo.dev/ for all the links. Seriously, we have the entire internet there!... with enough click depth, that is🪪 Go 1.25.5 and Go 1.24.11 are released with x509-related security fixes👉 spec: allow type parameter as the RHS in an alias type declaration🐾 DingoLightning roundGoWest...

Between and I took 4544 steps.
I'm experiencing what breathing out of my nose properly feels like for the first time. Everything is new and wondrous and I've never felt so optimistic. This…

This week, Ruby on Rails creator David Heinemeier Hansson and WordPress founding developer Matt Mullenweg started fighting about what "open source" means. I've spent twenty years working on open …
I will say I didn't disagree with DHH's use of "open source" as I will generally let it slide as its not "Open Source", the version that I attribute to following the Open Source Definition as set out by the Open Source Initiative
I agree that there are many who don't understand the distinction and assume that "Open Source" == "open source", and so I do agree that avoiding the use of "open source" where it instead means "non-OSD" makes sense
Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious supply chain risks as attackers increasingly compromise popular libraries to spread malware at scale. Feross Aboukhadijeh is the founder and CEO of Socket which is a security

The trouble of being such a prolific maintainer, well done 😹
Between and I took 5572 steps.
It has been a busy year 👀
I may be attending
Between and I took 5545 steps.
This post requires authentication to view.
Josh discusses updating open source dependencies with Jamie Tanna. Jamie works on Renovate which gives them a lot of insight into the challenges of keeping your open source updated. We discuss the challenges of semantic versioning, supply chain security, and AI-generated code. If you're new or old to the world of open source dependencies, there's something to learn from this chat. The show notes and blog post for this episode can be found at
I'm on Open Source Security: Updating open source dependencies (1 mins read).

Announcing my appearance as a guest on the Open Source Security podcast, talking about Renovate and dependency updates more generally.
Between and I took 10730 steps.
Who has made this 🤣
Week Notes 25#49 (2 mins read).
What happened in the week of 2025-12-01?
In Shawn "swyx" Wang's third appearance on the podcast, we talk about his recent interview with Mark Zuckerberg and Priscilla Chan about AI in biomedical resear...

I stumbled onto webrings and, for a moment, accidentally fell back into the OG internet
Stumbled across webrings this weekend; it was a little nostalgia trip into the weird, human-scale web I used to love <3 https://darylcecile.net/notes/rediscovering-the-internet
Nick Nisi joins us to dig into the latest trends from this year and how they're impacting his day-to-day coding and Vision Pro wearing. Anthropic's acquisition of Bun, the evolving JavaScript and AI landscape, GitHub's challenges and the AMP/Sourcegraph split. They dive into AI development practices, context management...
Does anyone know if there's a Charm BubbleTea UI prototyper? I'm trying to find something to have a play with some of the components to test out a UI I'm building, and ideally something drag-and-drop to play around with it would be convenient

Between and I took 6399 steps.
Welcome back to Break, a Fallthrough aftershow! In this episode, the panel continues their conversation from Fallthrough #48.Enjoying the aftershow? Let us know on social media! If you prefer to watch instead of just listen, head over to YouTube where you watch this episode of Break!Thanks for...

Checking out sidetrail and sharing some wisdom that may be helpful to you 👀 https://sidetrail.app/@brittanyellich.com/trail/3m7db273dmc2u
We've had Mitchell Hashimoto on a couple episodes, and each time we've discussed his vision for libghostty. In this episode, Kris and Matt talk about what the vision for libghostty actually means for the industry as a whole and the power of platforms. The duo also covers the new models that have...

I've done a couple of virtual conferences with it which was fun, but mainly for the novelty - not sure how many events it would work for / for a regular workplace
You're currently viewing page 1 of 877, of 43831 posts.