it would be kinda cool if we had built-in support for Node.js env file reader and also from the most popular env variables library (dotenv) to support this syntax for exec() as part of env-variables and resolving it
yes, I get the security concern but still
06.03.2026 19:00
π 1
π 0
π¬ 3
π 0
look at the last column and your favorite LLM for how likely they are to produce correct code (which for you seems fine), yet insecure code (which is great for attackers), that's from #baxbench project
06.03.2026 16:00
π 1
π 1
π¬ 0
π 0
David Cramer's write-up on Sentry's Warden code review agent is very on point. I resonate with this in particular with regards to security review.
Feeding a ton of context into a /security-review skill and expecting it to just magically secure your code is... insane. because that's just way too wi
06.03.2026 10:00
π 0
π 0
π¬ 0
π 0
If you haven't watched Pantheon yet on Netflix I highly recommend, more so even these days given the AI relationship...
05.03.2026 19:00
π 0
π 0
π¬ 0
π 0
In these times when LLMs are a quick gateway for quick and sometimes shallow answers, it is nice to see an engineer proactively investing in their knowledge - buying my 3 books bundle on Node.js Secure Coding
thank you kind (and now - more secure), developer β€οΈ
05.03.2026 10:01
π 2
π 0
π¬ 0
π 0
In these times when LLMs are a quick gateway for quick and sometimes shallow answers, it is nice to see an engineer proactively investing in their knowledge - buying my 3 books bundle on Node.js Secure Coding
thank you kind (and now - more secure), developer β€οΈ
05.03.2026 07:00
π 0
π 0
π¬ 0
π 0
Boris Cherny confirms he prominently uses Plan mode in Claude Code. I confirm. I've done the same with Cursor and the AskUserQuestionTool and it's been so good in a sort of interview style session the spec all the requirements out.
That's pretty much AI-native.
04.03.2026 19:00
π 1
π 0
π¬ 1
π 0
2016: rise of the specialist - frontend architect, Go systems engineer, kubernetes DevOps engineer.
2026: rise of the generalist - rewarded for expertise in AI-native capabilities, driving AI agents.
04.03.2026 16:01
π 1
π 0
π¬ 0
π 0
"productivity per engineer increase 200%" - Boris Cherny on Lenny's podcast. Totally relatable. Coding is solved, largely. I agree. But remember that software engineering wasn't just coding.
04.03.2026 10:00
π 2
π 0
π¬ 1
π 0
Anthropic 4x 'ed the engineering team for Claude Code over the last year, based on Boris Cherny's commentary.
so, humans are still required to accelerate work but at the same time, they're also the bottleneck. fun times.
04.03.2026 07:00
π 4
π 0
π¬ 0
π 0
hah, first time I see this page trending on my blog, funny :-)
03.03.2026 10:01
π 2
π 0
π¬ 0
π 0
Did you know you can do object detection with Gemini models ?
cool use of multimodal aspects of online LLMs over using offline YOLO models
02.03.2026 10:00
π 2
π 0
π¬ 0
π 0
friends on an interview hunt, please be careful. shared on TLDR infosec of an ongoing malware campaign targeting devs
27.02.2026 19:00
π 2
π 0
π¬ 0
π 0
who wants to play? reply with your thoughts and I'll show you how it fits my MCP security framework
26.02.2026 16:00
π 1
π 0
π¬ 1
π 0
oooo cursor, I thought you'd never ask!
26.02.2026 07:00
π 0
π 0
π¬ 0
π 0
ahh yes, the Claude Code Security saga that kills cybersecurity startups. So you're saying LLMs are good at writing code? industry benchmark like BaxBench shows something else
I guess we're lucky to have a new Opus model because 4.5 was only marginally better than a coin toss at secure code π
25.02.2026 19:00
π 2
π 0
π¬ 0
π 0
Nice refreshing update of the Qodo AI code review tool, I like how cleaner it is now
25.02.2026 10:00
π 1
π 0
π¬ 0
π 0
if you're wondering why Brian Clark is so confused it's because the newest Compose 1.5 model on Cursor confabulated a non-existent npm package version...
if you don't want that happening to you, that's what @Snyk fixes for the agent with the Snyk MCP Server integration
24.02.2026 16:01
π 0
π 0
π¬ 0
π 0
looks like I need to fine-tune YOLO to detect the yoda hat π
24.02.2026 10:00
π 4
π 0
π¬ 0
π 0
what do you do when you find out about unapproved or old AI models in your code projects... ? that's kinda shadow AI but we can forgo the fancy security acronym :-)
24.02.2026 07:00
π 0
π 0
π¬ 0
π 0
if you know you know
23.02.2026 20:45
π 0
π 0
π¬ 0
π 0
a handy tip with GitHub is that on failing CIs I can just fire off the GitHub Copilot agent to fix it
23.02.2026 19:00
π 0
π 0
π¬ 0
π 0
Your goal is that all agenting coding sessions will bake a @Snyk security scan in the task list
why is this helpful?
- it audits the AI generated code
- it audits the package health of hallucinated npm packages
- it prevents malicious packages from getting installed
- it provides security context
23.02.2026 16:01
π 0
π 0
π¬ 0
π 0
Your goal is that all agenting coding sessions will bake a @Snyk security scan in the task list
why is this helpful?
- it audits the AI generated code
- it audits the package health of hallucinated npm packages
- it prevents malicious packages from getting installed
- it provides security context
23.02.2026 10:00
π 0
π 0
π¬ 0
π 0
I kinda miss the whole hands-on live hacking presentations. We should have more of this.
20.02.2026 19:00
π 0
π 0
π¬ 0
π 0
the claude code cli flag we really want
20.02.2026 16:02
π 0
π 0
π¬ 0
π 0
the security concerns of YOLO with your coding agents (or any AI to be honest)
20.02.2026 10:00
π 3
π 0
π¬ 1
π 0
kinda cool seeing @snyksec powering AI agents ecosystem by flagging security issues in skill .md files :-)
20.02.2026 07:00
π 0
π 0
π¬ 0
π 0