Found 49366 bookmarks
Newest
GitHub ActionsでAI to Humanになるようレビューフローをコントロールする - プププなテクブ
GitHub ActionsでAI to Humanになるようレビューフローをコントロールする - プププなテクブ
GitHub After Dark Osakaでの登壇資料です。オリジナルの資料はこちらです。 このエントリはGitHub After Dark Osakaでお話しした内容を文字起こししているものです。 AIレビューと人間のレビューが同時に走る問題 CodeRabbit や GitHub Copilot などの AI …
·blog.inorinrinrin.com·
GitHub ActionsでAI to Humanになるようレビューフローをコントロールする - プププなテクブ
Experimenting with random() in CSS | Polypane
Experimenting with random() in CSS | Polypane
CSS is getting a random() function that lets you set properties with a random value, letting you make interesting and creative new designs. It's available in…
·polypane.app·
Experimenting with random() in CSS | Polypane
The post-quantum EO is an important milestone. Now it’s time to get to work
The post-quantum EO is an important milestone. Now it’s time to get to work
The new post-quantum executive order sets a 2030 migration deadline and establishes a powerful foundation for post-quantum resilience. We look at what it gets right, where it can go further, and our migration playbook for government and industry.
·blog.cloudflare.com·
The post-quantum EO is an important milestone. Now it’s time to get to work
codfish/semantic-release-action GitHub Action has been compromised - StepSecurity
codfish/semantic-release-action GitHub Action has been compromised - StepSecurity
On June 24, 2026, an attacker compromised the codfish/semantic-release-action GitHub repository. At 15:39:06 UTC they force-pushed a malicious commit and repointed several version tags to that commit. As a result, any workflow running against those tags after that time executed the attacker's code inside its GitHub Actions runner.
·stepsecurity.io·
codfish/semantic-release-action GitHub Action has been compromised - StepSecurity
「OSS開発者は今何をするべきか?ソフトウェアサプライチェーン侵害対策を考える」で「Hardening npm Publishing」という発表をしました
「OSS開発者は今何をするべきか?ソフトウェアサプライチェーン侵害対策を考える」で「Hardening npm Publishing」という発表をしました
2026年6月23日に、GMO Flatt Security主催の「OSS開発者は今何をするべきか?ソフトウェアサプライチェーン侵害対策を考える」で「Hardening npm Publishing」というタイトルで、npmパッケージの公開フローをどう守るかについて話しました。
·efcl.info·
「OSS開発者は今何をするべきか?ソフトウェアサプライチェーン侵害対策を考える」で「Hardening npm Publishing」という発表をしました
Desktop apps
Desktop apps
Build self-contained desktop applications from a Deno project, with framework auto-detection, hot reload, native windowing, auto-update, and cross-platform distribution.
·docs.deno.com·
Desktop apps
相次ぐGitHub Actions 侵害から学ぶ、初期アクセス手法と開発者が知っておきたい対策 - GMO Flatt Security Blog
相次ぐGitHub Actions 侵害から学ぶ、初期アクセス手法と開発者が知っておきたい対策 - GMO Flatt Security Blog
はじめに:なぜ今、GitHub Actionsのセキュリティなのか GitHub Actionsが侵害されると何が起きるか GitHub Actionsに対する攻撃の事例分析 脆弱なトリガー構成を悪用したインジェクション Ultralytics(2024年12月) nx(2025年8月) タグ汚染によるサプライチェーン…
·blog.flatt.tech·
相次ぐGitHub Actions 侵害から学ぶ、初期アクセス手法と開発者が知っておきたい対策 - GMO Flatt Security Blog
Vercel で Feature Flags を管理する
Vercel で Feature Flags を管理する
今日のアプリケーション開発において、Feature Flags(機能フラグ)は欠かせないツールとなっています。Vercel Flags を使用することで、Vercel 上でホストされているアプリケーションに Feature Flags を簡単に導入することができます。この記事では、Vercel Flags を使用して Vercel 上でホストされているアプリケーションに Feature Flags を導入する方法を試してみます。
·azukiazusa.dev·
Vercel で Feature Flags を管理する
The Coming Loop
The Coming Loop
Loops, harnesses, and why even loop skeptics may end up with them.
·lucumr.pocoo.org·
The Coming Loop
Matt Pocock on X: "There are a class of AI Coding assets that IMO don't really belong checked into git: - PRD's - Research files - Decision maps - Implementation plans Folks who agree with me, what are you using instead?" / Twitter
Matt Pocock on X: "There are a class of AI Coding assets that IMO don't really belong checked into git: - PRD's - Research files - Decision maps - Implementation plans Folks who agree with me, what are you using instead?" / Twitter
- PRD's - Research files - Decision maps - Implementation plans Folks who agree with me, what are you using instead?
·x.com·
Matt Pocock on X: "There are a class of AI Coding assets that IMO don't really belong checked into git: - PRD's - Research files - Decision maps - Implementation plans Folks who agree with me, what are you using instead?" / Twitter
HumanLayer - Token Smarter, not Harder
HumanLayer - Token Smarter, not Harder
An AI IDE, collaboration platform, and building blocks for your software factory. Ship 2-3x faster across the entire SDLC while maintaining rigorous standards for code quality and architecture.
·humanlayer.com·
HumanLayer - Token Smarter, not Harder
Evan You on X: "To answer a common question - why not make React Compiler a plugin? It all comes down to practical trade-offs. Making it a rust-based plugin is already significantly faster than the Babel version (up to 15x), but still 50% slower than direct-in-oxc due to the data passing / AST" / Twitter
Evan You on X: "To answer a common question - why not make React Compiler a plugin? It all comes down to practical trade-offs. Making it a rust-based plugin is already significantly faster than the Babel version (up to 15x), but still 50% slower than direct-in-oxc due to the data passing / AST" / Twitter
It all comes down to practical trade-offs. Making it a rust-based plugin is already significantly faster than the Babel version (up to 15x), but still 50% slower than direct-in-oxc due to the data passing / AST
·x.com·
Evan You on X: "To answer a common question - why not make React Compiler a plugin? It all comes down to practical trade-offs. Making it a rust-based plugin is already significantly faster than the Babel version (up to 15x), but still 50% slower than direct-in-oxc due to the data passing / AST" / Twitter