Bare names and expressions in ORDER BY go through two different parsers in PostgreSQL. The boundary between them is one if-statement old enough to vote, and it shows up in places you would not expect.
jahala/tilth: Smart(er) code reading for humans and AI agents. Reduces cost per correct answer by ~40% on average. Install: cargo install tilth -or- npx tilth
Smart(er) code reading for humans and AI agents. Reduces cost per correct answer by ~40% on average. Install: cargo install tilth -or- npx tilth - jahala/tilth
Structural sharing, selectAtom, and why your jotai atoms re-render too much | Peter Piekarczyk
When Object.is isn't enough, when selectAtom is a trap, and how to recreate React Query's structural sharing in plain jotai so plain derived atoms keep working.
The Flight Protocol Made Your DoS My Problem | Sascha Becker
On May 6, 2026, React and Next.js patched twelve vulnerabilities. One of them, CVE-2026-23870, is a single HTTP request that pins your Node process. The bug isn't the bug. The bug is that the framework boundary was a network boundary all along.
@pierre/trees is an open source file tree rendering library. It's built for performance and flexibility, is super customizable, and comes packed with features.
In this post, we'll learn how you can safely drop important columns from a table without breaking production, using the ignored_columns feature in Rails.
DeadBro — Rails APM with straightforward, request-based pricing
Real-time Rails APM: tracing, slow queries, N+1 detection, and errors. Start on a free tier that stays free — pay only for tracked requests on paid plans.
floatpane/matcha: A beautiful and functional email client for your terminal, built with Go and the charming Bubble Tea TUI library. Never leave your command line to check your inbox or send an email again!
A beautiful and functional email client for your terminal, built with Go and the charming Bubble Tea TUI library. Never leave your command line to check your inbox or send an email again! - floatpa...
5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough - StepSecurity
A poisoned VS Code extension breached GitHub. A trojanized PyPI package hit Microsoft. Compromised GitHub Actions and a self-spreading npm worm targeted thousands more. In just 48 hours, attackers hit every layer of the software development pipeline. Traditional security tools did not stop any of it.
Toto 2.0: Time series forecasting enters the scaling era | Datadog
For the first time, a time series foundation model gets reliably better with scale—five open-weights sizes from 4m to 2.5B parameters, trained from a single recipe.