Karl Horky @karlhorky.com · 07/10/2026Had a great time delivering my Full Stack Guardrails for AI Agents masterclass at The Geek Gathering 2026 (Osijek, Croatia) 🙌 Topics - ways AI can fail in software development - deterministic guardrails to help AI make fewer mistakes - exercise to build app feature with guardrails 360
Karl Horky @karlhorky.com · 05/10/2026@lirantal.com @notwes.bsky.social circling back around to this after a while in the AI agentic era, there have been new tools that also follow a similar pattern to using TS as a security tool if you ask your agent, i'm sure you'll find a lot more precedent of this eg github.com/rauchg/gdp-ts 120
Karl Horky @karlhorky.com · 26/08/2026introducing the `code-comments` skill: clearer, more deterministic code comments why: AI mostly writes in horrible, unclear, twisted ways (esp Claude) and that slop is saved in your codebase code comments, w. human + AI comprehension costs npx skills add karlhorky/agent-skills 230
Karl Horky @karlhorky.com · 19/08/2026still trying to get Claude Code (Opus 5, but all Anthropic models are like this) to be more grounded in reality and less persuasive / rhetoric-heavy the responses are by default so unstructured and void of proof / verification push a little bit against the rhetoric and "You're absolutely right!" 131
Karl Horky @karlhorky.com · 12/08/2026ahh @github.com is removing "Close" notifications?? 😬 notifications are already bad enough, making them worse? submit your feedback here: github.com/orgs/communi... 300
Karl Horky @karlhorky.com · 12/08/2026new proof of concept script: diagnostics from Next.js TypeScript language service plugin on the command line 😍 (also in CI) like `astro check` or `vue-tsc` or `mdx-tsc` 220
Karl Horky @karlhorky.com · 10/08/2026another of my weird code review habits check PR changes (even for your PRs) - if not self-explanatory in PR context, make line comments on what/why benefits: 1. finds many logic errors + overengineering 2. returning to PRs later offers extra context both for AI and people 110
Karl Horky @karlhorky.com · 07/08/2026that kind of day ... where a React key warning in your app leads you to discover a bug in React 🤯 github.com/react/react/... 020
Karl Horky @karlhorky.com · 07/08/2026Even with all of these new code review tools lately, we still have diffs like this on GitHub (even SemanticDiff can't ignore the {' '} diff) Wonder if these belong in Git as semantic diff drivers per language/framework 👀 so diffs everywhere can ignore these 🤔 450
Karl Horky @karlhorky.com · 05/08/2026Naming is hard So try to avoid naming things as much as possible - use existing names, from the language, framework, external APIs, etc One of my latest additions to AGENTS . md github.com/karlhorky/do... 000
Karl Horky @karlhorky.com · 30/07/2026Lightweight AI planning (avoiding a "plan" or "spec" which easily gets out of date): Start PRs with an empty commit + include all of the planned tasks in PR title and description (using checkboxes) Then keep this up to date and check off the points as you / AI implement github.com/karlhorky/do... 231
Karl Horky @karlhorky.com · 17/06/2026Security: VS Code 1.125 finally has a delay for auto-updates of extensions 👍 // Delay extension updates for 7 days "extensions.autoUpdateDelay": 168, Prompted by the recent security breaches and over 300 upvotes on my feature suggestion code.visualstudio.com/updates/v1_1... 111
Karl Horky @karlhorky.com · 17/06/2026Had a great time MCing at @jsnation.gitnation.org 2026 in Amsterdam! Great to see all the friends and make new connections Thanks to the organizers at @gitnation.bsky.social , and everyone else who helped organize, spoke and otherwise joined the event! #JSNation 100
Karl Horky @karlhorky.com · 02/06/2026Looking forward to MCing at JSNation Conf 2026 in Amsterdam next week 🚀 As a preview, here's multiple badly-generated AI photos of me on stage, which don't look like me at all hint: I like talking about AI slop / AI fails ✨ and how we can do better See you all there! 120
Karl Horky @karlhorky.com · 17/05/2026VS Code extension Security: I proposed a setting in VS Code to limit extension installs to versions older than X days This is to mitigate supply chain attacks, similar to pnpm's minimumReleaseAge github.com/microsoft/vs... 1291
Karl Horky @karlhorky.com · 16/04/2026VS Code: I suggested an "edit mode" for the integrated browser, for WYSWYG-style workflows of changing text copy If you also want this: it is a backlog candidate now, needs 20 👍 reactions to move it to backlog github.com/microsoft/vs... 140
Karl Horky @karlhorky.com · 13/01/2026🔒Node.js v22.22.0, v24.13.0, v25.3.0 fix 3 high, 4 med, 1 low severity security vulnerabilities (+ dependencies) Upgrade now: Windows: choco upgrade nodejs # or nodejs-lts macOS: brew upgrade node # or node@24 Ubuntu: sudo apt-get --only-upgrade install nodejs 220
Karl Horky @karlhorky.com · 29/11/2025Petition in Germany recognizing open source as volunteering for the common good 🤩 Seems like a good step towards recognition and a healthier open source ecosystem www.openpetition.de/petition/onl... 0184
Karl Horky @karlhorky.com · 16/10/2025npx-safe by @rafaelgss.dev : Use the Node.js permissions model to make running npx on untrusted packages safer 🔥 github.com/RafaelGSS/do... 010
Karl Horky @karlhorky.com · 25/09/2025Why? Dependabot security alert appears and update generated -> fails because the update is for a pnpm transitive dependency with the error: Dependabot doesn't support the 'updating transitive dependencies' feature for pnpm package_manager 010
Karl Horky @karlhorky.com · 25/09/2025My request for Dependabot: Full support for @pnpm.io (updates to transitive deps fail currently) Voice support in the issue 🙌 github.com/dependabot/d... 140
Karl Horky @karlhorky.com · 30/08/2025Codemods for Node.js 😍 Looking great, thanks to all contributors! 1111
Karl Horky @karlhorky.com · 11/08/2025@netlify.com multiple users reporting Netlify edge functions being down, in case you didn't know yet Maybe you can update the status page with the outage? answers.netlify.com/t/the-site-s... 110
Karl Horky @karlhorky.com · 09/08/2025VS Code 1.103 (Jul 2025) finally has expandable hovers in JavaScript and TypeScript 😍 for when the hover info is showing the type name instead of the object / array / etc code.visualstudio.com/updates/v1_1... 3294
Karl Horky @karlhorky.com · 17/07/2025Looks like `experimental.typedRoutes` is coming to Next.js Turbopack, thanks to Ben Gubler 🚀 🎉 github.com/vercel/next.... 080
Karl Horky @karlhorky.com · 21/05/2025My work in open source, from fixing papercuts to support students to discussing standards 🚀 Thanks so much to the Open Source Initiative @opensource.org for featuring me as a maintainer for Maintainer Month 2025! opensource.org/maintainers/... 1151
Karl Horky @karlhorky.com · 09/05/2025AI-generated image alt text in HTML and Markdown in VS Code April 2025 (1.100) 😍 code.visualstudio.com/updates/v1_1... 050
Karl Horky @karlhorky.com · 08/05/2025Oh nice, looks like the 2019 idea I had to "skip parameters in function parameter lists" may come to life in @chronicles.org's proposal "void Discard Bindings for ECMAScript" 😍 110
Karl Horky @karlhorky.com · 24/03/2025GritQL Biome plugins looking great 🔥 More options for simpler linting plugins 👍 ESLint `no-restricted-syntax` is almost there, but esquery can get pretty verbose... 070
Karl Horky @karlhorky.com · 11/02/2025`Cannot find matching keyid` error with latest pnpm? Upgrade to Node.js v22.14.0, which updates to the fixed Corepack 0.31.0 version: Windows: choco upgrade nodejs # or nodejs-lts macOS: brew upgrade node # or node@22 Ubuntu: sudo apt-get --only-upgrade install nodejs 2110
Karl Horky @karlhorky.com · 24/01/2025Thanks for the great talk at React Amsterdam @mickey.studio 🎉 Great to see more about this topic in design systems creation: - Drawbacks of rigid, highly-coupled components - Patterns of fine-grained component factoring and composition to counter these drawbacks 0111
Karl Horky @karlhorky.com · 13/01/2025> if you use the demo code and print `.get('a[]')` you get the value, right? you get a string - that was the point there is no way to receive an array value, which was the vulnerability forked sandbox: codesandbox.io/p/devbox/pen... 100
Karl Horky @karlhorky.com · 13/01/2025This is what we teach to students in the first lecture about TypeScript, that narrowing with runtime code is sometimes required 110
Karl Horky @karlhorky.com · 06/01/2025PostgreSQL: Ever wanted to insert test data with explicit `id`s into a table with an identity column eg. `GENERATED ALWAYS AS IDENTITY`? Added a new trick to PostgreSQL Tricks with a seeder script which achieves this (short version: detect + drop + re-add the identity) github.com/karlhorky/po... 190
Karl Horky @karlhorky.com · 06/12/2024one last edge case where I can imagine TS has only partial errors: overlapping identically-named APIs between different types (Array.prototype.concat and String.prototype.concat) but more uncommon, and I guess could be caught by types in other parts of program or other tooling like linters 110
Karl Horky @karlhorky.com · 06/12/2024In case this is still not clear, here's a demo In this demo, tsc (with @types/node and @types/sanitize-html) will not allow building type-unsafe, insecure JS, because of the type error on line 25 (see tsc error in alt text, or just run `pnpm tsc` in the sandbox) codesandbox.io/p/devbox/l7w... 310
Karl Horky @karlhorky.com · 05/12/2024Or in Next.js use, you can't even pass in an array without special handling - everything is strings (I think that's my favorite - secure by default, make the insecure thing harder) codesandbox.io/p/devbox/sto... 120
Karl Horky @karlhorky.com · 05/12/2024Yeah, I guess I'm used to TypeScript param types catching these things for me already, eg. Express query param types: www.typescriptlang.org/play/#code/J... 110
Karl Horky @karlhorky.com · 05/12/2024Ah interesting, and in the case of Dust, it seems like it was to avoid XSS vulnerabilities caused by missing encoding github.com/linkedin/dus... 120
Karl Horky @karlhorky.com · 28/11/2024it's crazy how often a new typescript-eslint rule ends up teaching JavaScript and TypeScript fundamentals 😮 🚀 typescript-eslint.io/rules/return... 5101
Karl Horky @karlhorky.com · 26/11/2024Playwright 1.49's new `.toMatchAriaSnapshot()` 😍 Nice and compact YAML syntax to test multiple elements in an accessibility tree 🎉 Thanks Pavel Feldman, @max.sh , @skn0tt.bsky.social , Dmitry Gozman and everyone else involved! playwright.dev/docs/release... 2183
Karl Horky @karlhorky.com · 24/11/2024nice! some before and after code shots from the video (with alt text) 010
Karl Horky @karlhorky.com · 17/11/2024I like the overall idea behind privacy protections for users 👍 But cookie banners / similar are a bad technical implementation, imposing bad UX on millions of users This makes a noticeable impact on user frustration, not to mention Europe's productivity and economy legiscope.com/blog/hidden-... 161
Karl Horky @karlhorky.com · 16/11/2024React Scan by @aidenybai.bsky.social 🤩 latest iteration of tooling visualizing React re-renders, looks great! 3180
Karl Horky @karlhorky.com · 13/11/2024@esft.bsky.social now that Bluesky is #1 app in the U.S. , recently with 700k followers in a week, what do you think of also posting over here? (or just leaving Twitter behind, like many are doing) Would be great to get your content over here too! 130
Karl Horky @karlhorky.com · 11/11/2024@tailwindcss.com @adamwathan.com thanks for `--spacing: 1px` in Tailwind CSS v4 🙌 still torn whether it's a good idea or not because consistency 🤔 but seems it could be the correct tradeoff for some projects! 130
Karl Horky @karlhorky.com · 11/11/2024check out SafeQL - I guess this may just work out of the box with the client safeql.dev/guide/introd... 120
Karl Horky @karlhorky.com · 10/11/2024Thanks for thinking of these types of security details when designing bcrypt for Bun @jarredsumner.com @bun.sh 👏 From screenshotted post: > Bun.password.hash’s “bcrypt” option automatically SHA512 hashes input longer than 72 bytes to prevent bcrypt from silently truncating passwords 010
Karl Horky @karlhorky.com · 20/05/2024We recently migrated to ESLint v9 with Flat Config (somewhat painful migration) some things that we found out that may be helpful for you 👇 111