Chad @chadfennell.com · 14hIf you're looking to level-up on container security: www.oreilly.com/library/view... An accessible and thorough intro on the fundamentals.oreilly.com 000
Chad @chadfennell.com · 27/09/2026Whatever benefit types confer to agents they are negated by the verbosity of TS. Holy hell. 000
Reposted by ChadBrittany Ellich @brittanyellich.com · 23/09/2026Me spinning up a quick lil Astra session to resolve some merge conflicts on an old PR 41629
Reposted by ChadAndree Toonk @atoonk.bsky.social · 27/08/2026We've come a long way over the last few months. Today we're offically launching Tailscale PAM (beta). I'm super happy with this beautiful integration, amazing team work! 🧡 0193
Chad @chadfennell.com · 26/08/2026Something I recently suggested to a client who was looking for ways to ease team AI fatigue: Trad Day Reserve at least day a week to write everything by hand - add tackle technical debt for extra therapy Slow is smooth, smooth is fast. 000
Chad @chadfennell.com · 26/08/2026Tailscale's forthcoming Aperture+ looks very promising. Everybody and their mother seems to be launching their own agent sandbox/runner platform. A+ = BYO infra (includes your laptop) and make it as simple as logging into an app for access. Cheap, secure, sovereign. youtu.be/j3CNNXUc4KE?...youtu.beTailscaleUp Keynote Live StreamYouTube video by Tailscale 161
Chad @chadfennell.com · 26/08/2026Incus continues to slay discuss.linuxcontainers.org/t/incus-7-3-...discuss.linuxcontainers.orgIncus 7.3 has been releasedThe Incus team is pleased to announce the release of Incus 7.3! Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix ... 000
Chad @chadfennell.com · 24/08/2026Been enjoying dbt - I chose it for a client project that required ongoing analytics work. It gave us a nice balance of features w/out having to rewrite our brains to a totally new paradigm: a light DSL over SQL with composable primitives, build time data validation, and a lot more. www.getdbt.comgetdbt.comDeliver trusted data with dbt | dbt Labsdbt Labs empowers data teams to build reliable, governed data pipelines—accelerating analytics and AI initiatives with speed and confidence. 000
Chad @chadfennell.com · 24/08/2026Feeling the need for some maker inspiration, I picked up this the other day www.penguinrandomhouse.com/books/313546... It's excellent, plus one, would recommend.penguinrandomhouse.comJony Ive by Leander Kahney: 9781591847069 | PenguinRandomHouse.com: Books“An adulating biography of Apple’s left-brained wunderkind, whose work continues to revolutionize modern technology.” —Kirkus Reviews In 1997, Steve Jobs... 000
Chad @chadfennell.com · 22/08/2026Playing with Kimi-K3 (via DeepInfra) on Hermes Agent today - extremely good experience so far (doing some business planning). deepinfra.com/moonshotai/K...deepinfra.comKimi K3 API - Demo - DeepInfraKimi K3 is Moonshot AI's 2.8T-parameter open-weight multimodal reasoning model. Built for complex coding, knowledge work, and long-horizon agentic workflows, it excels at navigating large repositories... 010
Reposted by ChadMike Zornek, looking for work. @mikezornek.com · 13/08/2026I'm looking for more Elixir consulting work, so I built a low-risk offer to reach new faces. Two weeks. One problem. $6,000 (discounted). One nagging thing: flaky tests, a stalled upgrade, a Sentry backlog. Know a team it'd suit? A share or intro would mean a lot. 🙏 #ElixirLangmikezornek.comElixir ConsultingElixir and Phoenix consulting. Fixed-price two-week sprints at $6,000, or ongoing hourly work, for teams that need upgrades, stability, and senior review. 041
Reposted by ChadZach Daniel @zachdaniel.dev · 12/08/2026We have a serious CVE for #AshFramework. If you are using #AshFramework please update to the latest version as soon as you can. cna.erlef.org/cves/CVE-202...cna.erlef.org CVE-2026-67579 0129
Reposted by Chadjohanna @jola.dev · 06/08/2026Wrote a little quickstart and background for how to my Elixir atproto OAuth library to build apps. Definitely planning to write more content like this! Atproto enables building really interesting apps and experiences, and #ElixirLang is a great language for it jola.dev/posts/latch-...jola.devLatch - an Elixir atproto OAuth libraryIntroducing Latch, an idiomatic elixir atproto OAuth library and client, built for flexibility and correctness. 2336
Chad @chadfennell.com · 29/07/2026A fantastic white paper on code sandbox security with a really important vector that I hand't considered: patch cadence arxiv.org/pdf/2606.08433arxiv.org 010
Reposted by ChadMike Dalessio @flavorjon.es · 29/07/2026Upgrade Rails immediately, kids, this is a big one. github.com/rails/rails/...github.comPossible arbitrary file read and remote code execution in Active Storage variant processing### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process envi... 14930
Chad @chadfennell.com · 29/07/2026Over the past couple of years, I noticed a lot of devs (myself included) were pretty fuzzy about what people mean by "sandboxes" for agents and dev spaces. Recently, I had the idea to turn some of that research into a website for fun if not profit: sandboxicon.comsandboxicon.comsandboxicon.com, shared kernel, or its own?A field guide to container and VM isolation, and what your AI coding agent actually runs with by default. Every claim is labeled by how well it's sourced. 210
Chad @chadfennell.com · 15/07/2026Nothing new under the sun and all that www.preprints.org/manuscript/2... Cognitive Offloading Is a Cognitive Universal We show how ecological niche construction...& the ability of LLMs to demonstrate fluent language use in the absence of extra-linguistic input all exemplify this offloading processpreprints.org 000
Chad @chadfennell.com · 12/07/2026For better or worse, the kind of things I think about while hiking. Conversations, projects, and ideas rattle around in my head and I try to take a step back and think hard about funamentals. I enjoy nature and stuff too. chadfennell.com/lab/5-heavin...chadfennell.comThe Unbearable Lightness of SoftwareDevelopers often reject systems on the basis of 'heaviness.' But is heaviness the right criterion for selection? 000
Chad @chadfennell.com · 12/07/2026Bumped into BEAR INFO up in the Muir Wilderness area this week😂 "If you see a bear, chase it like you are trying to catch it and eat it, Get mad. Be mean. They will run away in terror - Charlotte Lake Ranger" RIDE IT LIKE A WILD STALION. DRIVE IT INSANE BY INSCESSANTLY TALKING ABOUT THE WORLD CUP 010
Chad @chadfennell.com · 03/07/2026Whether it's AI use, politics, or business - the opinions of people in the arena will always carry more weight for me than those on the sidelines. 000
Reposted by Chadmean things I say to myself @meantomyself.bsky.social · 29/06/2026Old enough to recognize this as a data center 976259583481
Chad @chadfennell.com · 01/07/2026ARIatHOME never fails to put me in a good mood. NYC is a such a gift. www.youtube.com/watch?v=GGUl...youtube.comIs SHREDDING in PUBLIC Like This Even LEGAL??YouTube video by ARIatHOME 000
Reposted by ChadShahryar Tavakkoli @shahryar-tbiz.bsky.social · 29/06/2026🚀 Dear Elixir developers! 💜 Please help test Mishka Chelekom Headless Components! Your feedback will help us find bugs and get ready for release. 🐛✨ Our biggest release yet is almost here, with even more features on the way! 🎉🔥 Thanks for your support! 🙌 #ElixirLang 193
Reposted by ChadJosh Price @joshprice.com · 24/06/2026💥 Elixir PSA: update Plug *immediately* to the latest possible (1.20.1) The latest CVE makes it trivially easy to DOS a plug based server. cna.erlef.org/cves/CVE-202... This one is a doozy stay safe out there and keep your deps updated! #elixir-langcna.erlef.orgPlug: quadratic-time decoding of nested query/body parameters enables denial of serviceThis project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF). 42930
Chad @chadfennell.com · 23/06/2026Some brain droppings on Complexity and Polyglot Programming chadfennell.com/lab/4-polygl...chadfennell.comOn Polyglot ProgrammingBuild a toolbox and fill it full of tools. 000
Chad @chadfennell.com · 22/06/2026firecracker level isolation w/out firecracker hassles - very promising microsandbox.dev Plus, secrets stay on the host (like Deno's new offering). More of this plz.microsandbox.devmicrosandbox - Every agent deserves its own machinemicrosandbox runs lightweight microVMs locally on your machine. Programmable networking, custom filesystems, secrets that never leak. 100
Reposted by ChadSam Rose @samwho.dev · 18/06/2026I've made a Kubernetes that runs in the browser, and today we're open sourcing it. The hope here is to make super interactive and visual web content about Kubernetes much easier to write, and we have a whole bunch planned this year. Repo: github.com/ngrok/webern... Demo: webernetes-demo.ngrok.app 1317436
Chad @chadfennell.com · 10/06/2026It's easy to get tunnel vision as an adult, particularly in a busy chaotic environment. We start hammering things into the shapes of previous problems we solved out of convenience and sometimes...despiration.static.klipy.comAdmiral Ackbar: It's A Trap MemeAlt: Admiral Ackbar: It's A Trap Meme 100
Chad @chadfennell.com · 04/06/2026An educational frozen dessert called "Popcyclical" that comes in the shape of Pope Leo with a wrapper that has the MAGNIFICA HUMANITAS Encyclical written in Dr. Bronner's font. Papa paparum est, poppa of poppas, Pope of Popes. #free_product_ideas 000
Chad @chadfennell.com · 04/06/2026A Zoom plugin called "FATALITY" that allows you to murder one avatar a day. #free_product_ideas_thursday 000
Chad @chadfennell.com · 30/05/2026TIL Firewalla's Wake on LAN implementation just works with my home dev box. I can wake it up remotely with a click on the Firewalla app.static.klipy.comWill Ferrell Enjoys Hot CoffeeALT: Will Ferrell Enjoys Hot Coffee 000
Reposted by ChadTyler A. Young ⚗️🧑🏻💻 @tylerayoung.com · 28/05/2026At work, we got our app compiling without warnings on #ElixirLang 1.20-rc.6. The new type system discovered ~500 issues that 1.19 did not. - Most were just dead code (handling patterns that could never actually match in practice) - A handful were outright bugs. (See below) 1282
Reposted by ChadLauren Deschain @thatnerdchick.bsky.social · 25/05/2026Thanks, Vonnegut. 💜 277189335173
Reposted by ChadPeter Ullrich @peterullrich.com · 25/05/2026🚨 Update hackney 🚨 A **bunch** of vulnerabilities I reported in hackney were just disclosed. Please upgrade to 4.0.1 ASAP. I know this is gonna start dependency hell so please take some time for this. Please RT for reach. #ElixirLang cna.erlef.org/cves/cna.erlef.orgList of Issued CVE’sThis project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF). 43023
Chad @chadfennell.com · 23/05/2026Been on Kagi for a while now and I'll give up a lot of other services before I give up this one. No going back. arstechnica.com/gadgets/2025...arstechnica.comDumping Google’s enshittified search for KagiEnough is enough: I’ve jettisoned Google in favor of a search engine that doesn’t treat me like a product. 020
Reposted by ChadBart Blast @bartblast.com · 13/05/2026Hey Elixir friends, funny how getting a feature down to a simple one-line call takes two weeks of design work. Sharing what that looked like for Hologram realtime. 771
Reposted by ChadPeter Ullrich @peterullrich.com · 12/05/2026🚨 New Blog Post 🚨 I wrote about how I got into finding CVEs and what's the plan going forward. Also, I open-sourced the prompts I've been using. peterullrich.com/what-the-cvepeterullrich.comWhat the CVE?How I'm using Claude Opus 4.7 to find and report CVEs in popular Hex packages to make the BEAM ecosystem safer. 43814
Chad @chadfennell.com · 12/05/2026PSA www.stepsecurity.io/blog/mini-sh... Tips and tricks: * Pin/Lag slightly behind new releases * Containerize your dev env * Use few & scoped env vars (e.g. 1Pass service account w/select vault access) * Build in team rotation & visibility (e.g. 1Pass hydration script vs static .env file)stepsecurity.ioTeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages - StepSecurityThe Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed first detected the attac... 020
Chad @chadfennell.com · 10/05/2026rtk is an excellent way to reduce token spend for agents running shell commands like "find" github.com/rtk-ai/rtk Love it.github.comGitHub - rtk-ai/rtk: CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependenciesCLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies - rtk-ai/rtk 000
Reposted by ChadPeter Ullrich @peterullrich.com · 09/05/2026🚨 Update absinthe 🚨 Yesterday 2 CVEs for "absinthe" were released. The vulnerabilities can exhaust your CPU and atom tables. Update ASAP Thank you Curtis Schiewek and team for the quick fix and to @maennchen.dev for managing the release cna.erlef.org/cves/CVE-202... cna.erlef.org/cves/CVE-202...cna.erlef.orgQuadratic fragment-name uniqueness check causes denial of service in absintheThis project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF). 0155