Sign in

Mike McQuaid

@mikemcquaid.com
5.5K followers 0 following 99 posts

I'm CTPO at Administrate, Homebrew Project Leader, ex-GitHub Principal Engineer, author of Git in Practice and an OSS and developer productivity leader. Posting mostly automated from mikemcquaid.com. If you want me to read your reply: email me instead.

PostsRepliesMedia
Mike McQuaid @mikemcquaid.com · 27/09/2026
Agentic coding has let me replace everyday tools with software that works how I want.
mikemcquaid.com
Vibe Coding Developer Productivity Tools
Agentic coding has let me replace everyday tools with software that works how I want.
2100
Mike McQuaid @mikemcquaid.com · 23/09/2026
Proud my my mate Joe releasing his third excellent book. Funny, touching and hilarious.
edinburghlive.co.uk
Edinburgh author 'liberated' after growing up during 'dark time' for gay people
"It’s weird what years of conditioning by society can do to you"
010
Mike McQuaid @mikemcquaid.com · 21/09/2026
Combine pager duty with incoming team requests to protect roadmap work and let engineers fix what woke them up
mikemcquaid.com
On-Call and First Responder: One Rotation to Rule Them All
Combine pager duty with incoming team requests to protect roadmap work and let engineers fix what woke them up
020
Mike McQuaid @mikemcquaid.com · 14/09/2026
my bad if not, apologies
020
Mike McQuaid @mikemcquaid.com · 14/09/2026
don't think so yet sorry
110
Mike McQuaid @mikemcquaid.com · 13/09/2026
Some linked in release notes. There were a lot.
010
Mike McQuaid @mikemcquaid.com · 13/09/2026
Today, I’m proud to announce Homebrew 7.0.0. The most significant changes since 6.0.0 are faster installations, stronger sandboxing, native macOS app, vulnerability checks, advisory database, end of macOS 10.15 support and Intel Macs to Tier 3.
brew.sh
7.0.0
Today, I’m proud to announce Homebrew 7.0.0. The most significant changes since 6.0.0 are faster installations and upgrades, stronger sandboxing, a native macOS app, built-in vulnerability checks and an advisory database, the end of macOS 10.15 support and Intel Macs moving to Tier 3.
523226
Mike McQuaid @mikemcquaid.com · 20/08/2026
Inside Modern Software Engineering with Homebrew’s Mike McQuaid Interviewed by Giant Robots Smashing Into Other Giant Robots. Sami is back this week with Mike McQuaid as they take a deep dive into the importance of open source maintainers.
podcast.thoughtbot.com
Inside Modern Software Engineering with Homebrew’s Mike McQuaid
Sami is back this week with Mike McQuaid as they take a deep dive into the importance of open source maintainers.
020
Mike McQuaid @mikemcquaid.com · 07/08/2026
Some great people here doing some really interesting stuff.
0132
Mike McQuaid @mikemcquaid.com · 27/07/2026
Homebrew is thriving while other open source projects struggle. Its scarcest resource isn't money: it's maintainer motivation.
mikemcquaid.com
Open Source Must Be Fun (Or It Will Die)
Homebrew is thriving while other open source projects struggle. Its scarcest resource isn't money: it's maintainer motivation.
0126
Mike McQuaid @mikemcquaid.com · 17/07/2026
Memories of my friend and former GitHub coworker Jason Rudolph, who died in May 2026.
mikemcquaid.com
In Memory of Jason Rudolph
Memories of my friend and former GitHub coworker Jason Rudolph, who died in May 2026.
020
Mike McQuaid @mikemcquaid.com · 24/06/2026
Why is Windows 11 so disliked by programmers – and can Microsoft do anything to change things? Interviewed by Keumars Afifi-Sabet on ITPro. “Stop trying to overrule my preferences on how to use my computer.”
itpro.com
Why is Windows 11 so disliked by programmers – and can Microsoft do anything to change things?
“Stop trying to overrule my preferences on how to use my computer.”
14150
Mike McQuaid @mikemcquaid.com · 22/06/2026
Merge-queue deploys, robust releases and chores you keep forgetting
mikemcquaid.com
Make GitHub Actions Do More For You
Merge-queue deploys, robust releases and chores you keep forgetting
161
Mike McQuaid @mikemcquaid.com · 18/06/2026
Homebrew tightens tap security, begins work on its interface Interviewed by Anamarija Pogorelec on Help Net Security. “It’s probably aimed a little more at newcomers than experienced Homebrew users.”
helpnetsecurity.com
Homebrew tightens tap security, begins work on its interface
“It’s probably aimed a little more at newcomers than experienced Homebrew users.”
021
Mike McQuaid @mikemcquaid.com · 14/06/2026
We Nerds love helping beginners (as long as they RTFM and fill in the issue templates). Watch out for those "False Nerds", folks (2/4).
Most Computer Nerds Love to Help Beginners
It's sad, but almost all computer nerds spend most of their waking hours in front of a computer. They know that's kind of an oddball thing to do, but they can't help it.
Their guilty consciences are what usually make them happy to help begin-ners. By passing on knowledge, they can legitimize the hours they whiled away on their computer stools. Plus, it gives them a chance to brush up on a social skill that's slowly slipping away: the art of actually talking to a person.
v Always be grateful when given help.
Beware of False Nerds. These are people who don't love computers but who went to some sort of school to learn a few by-rote tricks. They may not be helpful nor know anything about computers other than what they're told. You can tell False Nerds because they lack the enthusiasm of the True Nerd, the one who will help you.
070
Mike McQuaid @mikemcquaid.com · 11/06/2026
Discuss on Hacker News, if that's your thing: news.ycombinator.com/item?id=4849...
news.ycombinator.com
031
Mike McQuaid @mikemcquaid.com · 11/06/2026
Today, I’m proud to announce Homebrew 6.0.0. Since 5.1.0: secure tap trusting, faster JSON API, Linux sandboxing, better defaults, brew bundle improvements, improved performance, initial macOS Golden Gate support.
brew.sh
Homebrew 6.0.0
Homebrew 6.0.0 has been released.
2235
Mike McQuaid @mikemcquaid.com · 11/06/2026
I gave a talk: The impact of AI on open source software development Five experienced open source practitioners cut through the hype to ask what AI is actually doing to the communities, projects, and humans that keep open source alive.
mikemcquaid.com
The impact of AI on open source software development
Five experienced open source practitioners cut through the hype to ask what AI is actually doing to the communities, projects, and humans that keep open source alive.
010
Mike McQuaid @mikemcquaid.com · 05/06/2026
Flood of AI ‘garbage’ is pushing open-source developers to the limit Interviewed by Matthew Sparkes on New Scientist. “The skill right now is being able to skim and spot nonsense while investing as little of your own time as you possibly can.”
newscientist.com
Flood of AI ‘garbage’ is pushing open-source developers to the limit
“The skill right now is being able to skim and spot nonsense while investing as little of your own time as you possibly can.”
131
Mike McQuaid @mikemcquaid.com · 25/05/2026
I think the main thing they need to do is be much more willing to break backwards compatibility for security. In NPM's case: it's also owned by one of the biggest companies in the world who just chooses to neglect it. My sympathies are much more with RubyGems, PyPi etc.
110
Mike McQuaid @mikemcquaid.com · 25/05/2026
You're welcome! I'd strongly recommend using a `Brewfile` if you haven't seen them already!
010
Mike McQuaid @mikemcquaid.com · 21/05/2026
I've been doing this for 17 years. We've had at least 10+ ecosystem wide bad 0-days (e.g. OpenSSL heartbleed for maybe the most notable) where we've coordinated to ship things very soon after disclosure. We've applied an ecosystem cooldown to NPM/Pip/RubyGems. This shouldn't apply to OpenSSL folks.
110
Mike McQuaid @mikemcquaid.com · 21/05/2026
Glad to hear people speaking about this. It's tremendously frustrating as a Homebrew maintainer to see NPM refuse to make the changes necessary, cooldowns being a reasonable compromise and now people demand cooldowns on Homebrew with a completely different security model.
111
Mike McQuaid @mikemcquaid.com · 16/05/2026
I love the idea of an organisation run by maintainers for maintainers!
140
Mike McQuaid @mikemcquaid.com · 14/05/2026
“It’s the duty of all Free Software developers to steal as much time as they can from their employers for software freedom.” Jeremy Allison, co-creator of Samba and, at the time, a Google employee. 🫡
0100
Mike McQuaid @mikemcquaid.com · 13/05/2026
Weird, thanks. Have emailed to ask about this.
010
Mike McQuaid @mikemcquaid.com · 13/05/2026
Posted on Hacker News, if that's your thing: news.ycombinator.com/item?id=4812...
news.ycombinator.com
Open Source Resistance: keep OSS alive on company time | Hacker News
170
Mike McQuaid @mikemcquaid.com · 13/05/2026
Open source maintainers at profitable companies: stop asking permission to fix what your employer already depends on. No paperwork. No programme. No manager’s blessing. Just maintain it on the clock.
ossresistance.com
Open Source Resistance
A direct-action manifesto for maintainers keeping open source alive on company time.
319343
Mike McQuaid @mikemcquaid.com · 08/05/2026
Your regular reminder that shitting on OSS on social media is a selfish thing to do. Good job sapping volunteer maintainers’ motivation in exchange for your “internet points”. Next time: try rolling up your sleeves and contribute a fix to the problem you’ve identified.
0192
Mike McQuaid @mikemcquaid.com · 04/05/2026
I wonder how much of people loving or hating meetings is down to how well they can type or multitask.
120
Mike McQuaid @mikemcquaid.com · 23/04/2026
This AI Tool Rips Off Open Source Software Without Violating Copyright Interviewed by Emanuel Maiberg on 404 Media. “The ethics fucking suck. Open source isn’t just source code you download once. It’s an ongoing relationship.”
404media.co
This AI Tool Rips Off Open Source Software Without Violating Copyright
“The ethics fucking suck. Open source isn’t just source code you download once. It’s an ongoing relationship.”
000
Mike McQuaid @mikemcquaid.com · 21/04/2026
“I’m excited to work with you, the company seems great. I’m a little unwhelmed with the salary, though, is there any chance you can do better?” This sentence gets most who try a 0-10% new job pay increase with zero resentments. Paraphrase it and use it (even on me).
150
Mike McQuaid @mikemcquaid.com · 17/04/2026
Stop babysitting one AI at a time. Sandboxing lets them run wild safely, Git worktrees let them run in parallel. Use more tokens, get more velocity.
mikemcquaid.com
Sandboxes and Worktrees: My secure Agentic AI Setup in 2026
Stop babysitting one AI at a time. Sandboxing lets them run wild safely, Git worktrees let them run in parallel. Use more tokens, get more velocity.
271
Mike McQuaid @mikemcquaid.com · 14/04/2026
This was a good read and reflects my experiences. It also made me think the answer to “what do we do with juniors/students and AI” is “actually teach them software engineering best practices, not just CS fundamentals”.
christophermeiklejohn.com
Software Engineering Is Becoming Civil Engineering
Software engineering is undergoing a transformation similar to when structural design separated from craft construction to become civil engineering, with AI handling feature development while platform engineers focus on building safe, resilient systems.
270
Mike McQuaid @mikemcquaid.com · 07/04/2026
Recreating office-style pranks in a remote AI-loving world
mikemcquaid.com
Prompts Pranking Peers
Recreating office-style pranks in a remote AI-loving world
021
Mike McQuaid @mikemcquaid.com · 02/04/2026
At work, you have two jobs: being good at your job, being pleasant to work with. You can sometimes get by for a while not doing them both but it’s hard to survive doing neither.
0191
Mike McQuaid @mikemcquaid.com · 02/04/2026
Ruby Central report reopens wounds over RubyGems repo takeover Interviewed by The Register. “If your project hasn’t argued about governance or money yet, it will one day. Be prepared and try to do this before it becomes a problem.”
theregister.com
Ruby Central report reopens wounds over RubyGems repo takeover
“If your project hasn’t argued about governance or money yet, it will one day. Be prepared and try to do this before it becomes a problem.”
061
Mike McQuaid @mikemcquaid.com · 01/04/2026
"fix"
010
Mike McQuaid @mikemcquaid.com · 01/04/2026
There's a bunch of shit in my public dotfiles to make this work better in case any of it is useful: github.com/mikemcquaid/...
github.com
GitHub - MikeMcQuaid/dotfiles: 💻 My dot files shared between machines.
💻 My dot files shared between machines. Contribute to MikeMcQuaid/dotfiles development by creating an account on GitHub.
000
Mike McQuaid @mikemcquaid.com · 01/04/2026
Yes, I've used it, packaged it for Homebrew (`brew install sandvault`) and really like how relatively minimal it is compared to e.g. a Docker container in a VM. With a bit of work (I have a wrapper) you can hook it up to any tool that lets you change the commands for claude/codex e.g. Superset.
110
Mike McQuaid @mikemcquaid.com · 01/04/2026
Every time you open an issue or pull request with “No description provided”, an open source maintainer dies.
140
Mike McQuaid @mikemcquaid.com · 31/03/2026
One of the strengths of Homebrew, despite it being unpopular, is being willing to break backwards compatibility when necessary. NPM’s unwillingness to do so reflects GitHub’s: both show excessive caution that harm both security and usability.
nesbitt.io
npm's Defaults Are Bad
The npm client's default settings are a root cause of JavaScript's recurring supply chain security problems.
0144
Mike McQuaid @mikemcquaid.com · 25/03/2026
My talk “Ruby on Guard (Rails)” from Haggis Ruby 2024 is now on YouTube. Weird watching in hindsight when I was very much pre-AI. If anything, AI only makes the guardrails more important and valuable.
youtube.com
Ruby on Guard (Rails)
Ruby is powerful, and you want to move fast. So having guardrails can be useful?
121
Mike McQuaid @mikemcquaid.com · 19/03/2026
Job security for engineers is dead. Career security is what matters. You build it by learning, changing, taking risks, being reliable and stepping outside your lane. Your employer won’t prioritise your long-term career. You should.
031
Mike McQuaid @mikemcquaid.com · 18/03/2026
This was a good read. Review is good but it does slow things down. With async PR review, I prefer the “✅ with comments” review. Unblock the person from merging with trust they will read and resolve your comments first.
apenwarr.ca
Every layer of review makes you 10x slower
We've all heard of those network effect laws: the value of a network goes up with the square of the number of members.
061
Mike McQuaid @mikemcquaid.com · 13/03/2026
In case you missed it in Homebrew 5.1.0 release notes: we’re doing a short user survey to inform future development.
docs.google.com
Homebrew User Survey
Questions for current users to inform future Homebrew development
013
Mike McQuaid @mikemcquaid.com · 11/03/2026
Today I’m proud to announce the release of Homebrew 5.1.0. The most significant changes since 5.0.0 are expanded brew bundle support, brew version-install, new -full formula handling and installer updates.
brew.sh
5.1.0
Homebrew 5.1.0 has been released.
052
Mike McQuaid @mikemcquaid.com · 05/03/2026
Great post here from Andrew, particularly on why Homebrew doesn’t need a NPM-style cooldown.
nesbitt.io
Package Managers Need to Cool Down
A survey of dependency cooldown support across package managers and update tools.
010
Mike McQuaid @mikemcquaid.com · 05/03/2026
Should be obvious but seems it’s not: don’t spam OSS maintainers or coworkers with AI code you’ve not reviewed yourself. For coworkers only, sometimes fine explaining your testing and why reviewed isn’t necessary e.g. a one-time script.
simonwillison.net
Anti-patterns: things to avoid
Agentic Engineering Patterns
001
Mike McQuaid @mikemcquaid.com · 03/03/2026
It’s hard to understate just how much more productive coding agents are at some tasks in YOLO mode. Essential to have a good sandbox for this, though. My favourite so far is sandvault: no Docker nonsense needed.
github.com
GitHub - webcoyote/sandvault
Run AI agents isolated in a sandboxed macOS user account
160