Sign in

Steffen Deusch

@steffend.me
323 followers 75 following 167 posts

Software Developer (mostly Elixir). Mainly here to read. Fediverse social.deusch.me/@steffen

PostsRepliesMedia
Reposted by Steffen Deusch
Peter Ullrich @peterullrich.com · 26/09/2026
Maybe a bit surprising, but the article ends with a shoutout to Phoenix and Tidewave 😬
The web framework Phoenix, written in Elixir, can serve as a model for Rails. The developers of Elixir and Phoenix jumped on the Agentic Coding bandwagon very early on and offer ideal opportunities to combine both worlds, for example, with their own agents.md file optimized for Elixir in every new Phoenix project and the Tidewave tool.
2101
Steffen Deusch @steffend.me · 25/09/2026
Very nice, I wish you all the best and hope that it succeeds. Happy to pay for a personal plan once they are available 💰
141
Steffen Deusch @steffend.me · 14/09/2026
The thing looks awesome btw! Sorry I’m just a bit sad that such content gets exclusively posted over there 😅
130
Steffen Deusch @steffend.me · 14/09/2026
Maybe I should tell him to not only post on the Nazi-site (or even better not post there at all) and instead do it somewhere people can actually see it, without needing a Nazi-account…
150
Steffen Deusch @steffend.me · 11/09/2026
You need it assuming you don’t use sticky sessions at your load balancer, otherwise individual longpoll requests might get router to different nodes and if they cannot communicate via clustering, LiveViews would frequently do full remounts when you don’t expect them to.
000
Steffen Deusch @steffend.me · 11/09/2026
I heard in the podcast that you’re not planning to use clustering. That means that you also can’t use longpoll for users where websocket is broken, which could lead to bad UX. If you decide to do clustering, you could also route git through the cluster instead of deciding at the reverse proxy 😄
110
Steffen Deusch @steffend.me · 11/09/2026
Nice, happy to help test or contribute :)
120
Steffen Deusch @steffend.me · 11/09/2026
@peterullrich.com For the firecracker runners, do you plan to make those open source? I like self hosting runners, but I don't feel good using them on public repos if the jobs are not isolated. So a way to run KVM based ephemeral runners for each job would be awesome for non-hosted ones too #pushin
131
Steffen Deusch @steffend.me · 11/09/2026
But the existing code is still completely fine even on latest 1.8. There is one very good reason to always update to latest, even while older versions still get security patches: they don’t get bug fixes. So you might run into known issues on older versions that won’t get fixed.
011
Steffen Deusch @steffend.me · 11/09/2026
But that’s not a reason not to update, since generally old patterns are at most deprecated and your existing code will still work (just add phoenix_view as a dependency for that example). So people sometimes feel like they need to update to the latest and greatest idioms to use latest Phoenix.
110
Steffen Deusch @steffend.me · 11/09/2026
I know I’m late to hear the latest episode, but since it looks like that last post was not fully clear: what I’m trying to say is that I’ve seen people saying something similar to “oh we’re still on 1.6 because we use Phoenix.View and didn’t have time to update to Phoenix.Component“ or similar.
110
Reposted by Steffen Deusch
Peter Ullrich @peterullrich.com · 10/09/2026
Apparently there is money for open source if you are racist enough
1769
Reposted by Steffen Deusch
Peter Ullrich @peterullrich.com · 08/09/2026
🚨 Announcing Pushin 🚨 Now officially: I'm announcing Pushin.eu, a git hosting platform built and run entirely in Europe. Think GitHub/GitLab but European, better, and faster. Built with #ElixirLang and #RustLang. peterullrich.com/announcing-p...
peterullrich.com
Announcing Pushin
I'm launching Pushin.eu, a git hosting platform built and run entirely in Europe.
1114449
Steffen Deusch @steffend.me · 07/09/2026
Just CLONE the repo. There’s no fucking need to render commits and blames to HTML for your stupid scraping. And they call it artificial INTELLIGENCE.
100
Steffen Deusch @steffend.me · 07/09/2026
And that’s still the reasonable part. Add those to robots.txt and you’ll get tons of requests from residential proxies claiming to be chrome on windows etc.; I had to shut my forgejo hosted Linux repo down and move it to GitHub due to those stupid crawlers.
101
Steffen Deusch @steffend.me · 07/09/2026
btw nice to see a privacy policy on the site now, note that it does not render nicely on mobile at the moment
100
Steffen Deusch @steffend.me · 07/09/2026
@peterullrich.com if you need a stresstest for pushin.eu, host a fork of the Linux kernel or another repository with 100000+ commits. I just had to make another repository on my Foregjo instance private because AI crawlers pinned my CPU at 100% for hours, trying to crawl git blames of a mesa fork…
pushin.eu
Pushin.eu — Git hosting that never leaves Europe
Sovereign, GDPR-native git hosting — code, issues, and CI, all on European soil.
250
Reposted by Steffen Deusch
Andrew 🇵🇸 @src.rip · 23/08/2026
Should I make a Phoenix component kit + Starter Kit? Would people buy a paid one?
021
Reposted by Steffen Deusch
Andrew 🇵🇸 @src.rip · 22/08/2026
Has anyone ever seen: Failed to push hook event: failed with reason: {"reason":"unmatched topic"} In any of their Production LiveView apps? Please get in touch with me if so...
222
Steffen Deusch @steffend.me · 19/08/2026
As a general note: a common misconception is also that people think they have to copy whatever changes we did to the generators. That's not the case. You can of course do that, but it's in no way a requirement to update to later Phoenix versions. It's 1.x, so updates are generally non-breaking.
220
Steffen Deusch @steffend.me · 19/08/2026
There are no major CVEs for latest Phoenix 1.5+. We provide security patches for the last 4 minor versions, which include 1.5, 1.6, 1.7 and 1.8 at the moment. Apps using old Phoenix should still update, for sure, but not necessarily for security reasons. See github.com/phoenixframe....
152
Reposted by Steffen Deusch
Peter Ullrich @peterullrich.com · 17/08/2026
I guess no more work today then!
GitHub has a full outage ... again
2323
Steffen Deusch @steffend.me · 12/08/2026
Nice!
110
Reposted by Steffen Deusch
Tyler A. Young ⚗️🧑🏻‍💻 @tylerayoung.com · 07/08/2026
This is cool. Also, if you're running an old version of Phoenix, you should really update. 😆 Keeping up has been very low pain on our 750k LoC LiveView codebase at work. #ElixirLang www.praialabs.com/phoenix-vers...
praialabs.com
Phoenix version adoption & security - Praia Labs
An empirical analysis of Phoenix Framework version adoption cadence, patch responsiveness across minor series, and security risks of legacy deployments.
1102
Steffen Deusch @steffend.me · 29/07/2026
Feels like a good time to set up Time Machine (or restic, or some other automatic backup that runs at least daily)
010
Reposted by Steffen Deusch
Peter Ullrich @peterullrich.com · 28/07/2026
🚨 Announcing our new Podcast 🚨 Gus (@gworkman.bsky.social) and I have started a new #ElixirLang Podcast Macro Mayhem - @macromayhem.fm We cover Elixir news and general industry topics every 2 weeks. Our first episode is out now, available on all podcast players or on our website: macromayhem.fm
macromayhem.fm
Macro Mayhem
The latest Elixir news and general software industry topics
35922
Reposted by Steffen Deusch
David Bernheisel @david.bernheisel.com · 24/07/2026
Next time you're upgrading Phoenix and you're using AI assistance, try pointing it to elixirstream.dev/gendiff/api and tell me how it goes. cc @steffend.me #ElixirLang
elixirstream.dev
https://elixirstream.dev/gendiff/api
# gendiff — Markdown API for coding agents Generate a diff of a project generator's output between two versions, rendered as Markdown built for LLMs. Fetch one URL, get the diff — no UI needed. ## E...
0164
Reposted by Steffen Deusch
Leandro Pereira @leandrocp.bsky.social · 13/07/2026
Announcing Lumis: Syntax Highlighter powered by Tree-sitter and Neovim themes. 110+ languages 250+ themes Unified API: CLI, Web, JavaScript, Rust, Elixir, Java. lumis.sh ↓
4535
Reposted by Steffen Deusch
Bart Blast @bartblast.com · 30/06/2026
Hey Elixir friends! :) Hologram v0.10 is out, now with a real event system. To show it off, I rebuilt Space Invaders in pure Elixir, running in the browser with no game engine. There's a new server-side middleware layer too. hologram.page/blog/hologra...
3279
Reposted by Steffen Deusch
Lars Wikman @lawik.bsky.social · 23/06/2026
In a pending PR he added a Linux kernel recompile feature. It totally worked for replacing the Linux kernel and packaging up the stuff needed to run the nerves containers demo example. github.com/lawik/docker...
github.com
111
Reposted by Steffen Deusch
Lars Wikman @lawik.bsky.social · 23/06/2026
James Harton is doing something interesting. NBPR is a tool for removing a lot of the annoying bits of customizing a Nerves system. Namely buildroot and kernel builds. github.com/jimsynz/nbpr #elixirlang
github.com
GitHub - jimsynz/nbpr: Nerves Binary Package Repository
Nerves Binary Package Repository. Contribute to jimsynz/nbpr development by creating an account on GitHub.
2133
Steffen Deusch @steffend.me · 16/06/2026
Yeah that’s what I figured as well. I mostly wondered why Peter reposted it. FWIW, just for anyone reading: LiveView 1.2 does not contain any code to make reconnects or latency significantly faster.
081
Steffen Deusch @steffend.me · 16/06/2026
What?
200
Reposted by Steffen Deusch
Christopher Grainger @cigrainger.bsky.social · 12/06/2026
Trans children are being denied gender affirming healthcare, so we’re stepping in to support them. Will you join us? goodlawproject.org/s/37c8ea
goodlawproject.org
Help fund healthcare for trans kids | Good Law Project
This week, the families of trans kids receiving gender-affirming care at a Brighton medical practice were notified that their children’s treatment would be withdrawn in a matter of weeks.
052
Reposted by Steffen Deusch
Tyler A. Young ⚗️🧑🏻‍💻 @tylerayoung.com · 10/06/2026
LiveView 1.2 is out now! phoenixframework.org/blog/phoenix... The highlights for me: - Colocated CSS - Support for formatters for <script> and <style> tags - New JS client docs 🎉 #ElixirLang
phoenixframework.org
Phoenix LiveView 1.2 released! - Phoenix Blog
LiveView 1.2 is a small release that adds support for colocating CSS.
05111
Reposted by Steffen Deusch
Peter Ullrich @peterullrich.com · 29/05/2026
The Beam There, Done That podcast episode with me and @maennchen.dev is out! www.youtube.com/watch?v=FulS...
youtube.com
AI Found 5 CVEs in One Afternoon — The BEAM Security Wake-Up Call | Peter Ullrich & Jonathan Machen
YouTube video by BEAM There, Done That
0104
Steffen Deusch @steffend.me · 26/05/2026
"Hot" take: in Germany landlords are required to ensure proper heating, but I‘d say proper cooling should be mandatory as well. One problem is that many Germans are too stubborn to accept air conditioning.
Screenshot of HomeAssistant temperature readings. All rooms are 28°C+.
120
Steffen Deusch @steffend.me · 25/05/2026
I use a Hetzner Storagebox and a local NAS with restic for backups restic.net
restic.net
restic · Backups done right!
120
Steffen Deusch @steffend.me · 24/05/2026
For personal projects? You have a Hetzner server now, so you could self-host Forgejo! I have my personal, mostly private code at git.deusch.me
git.deusch.me
Gitea: Git with a cup of tea
Forgejo is a self-hosted lightweight software forge. Easy to install and low maintenance, it just does the job.
120
Reposted by Steffen Deusch
Ryan Winchester @winchester.dev · 22/05/2026
btw Ecto version 3.14 is out and has UUIDv7 support! #elixirlang
examples of Ecto.UUID with UUIDv7 suport
2339
Steffen Deusch @steffend.me · 20/05/2026
lol
010
Reposted by Steffen Deusch
Hauleth @hauleth.dev · 14/05/2026
Anyone is looking for Senior Elixir Developer based in the EU? My CV available at hauleth.dev/cv #elixirlang #job
21821
Reposted by Steffen Deusch
Peter Ullrich @peterullrich.com · 07/05/2026
🚨 Please update "decimal" 🚨 A *single* calculation like: Decimal.new("1e1_000_000_000") |> Decimal.add(1) will OOM your application. Poof. Adios. Auf Wiedersehen. cna.erlef.org/cves/CVE-202...
cna.erlef.org
Unbounded exponent in decimal enables unauthenticated DoS
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
5249
Steffen Deusch @steffend.me · 06/05/2026
Not needed, fix released in 1.7.23. Sorry for the inconvenience!
000
Steffen Deusch @steffend.me · 06/05/2026
Argh, that’s indeed an error in the backport. There‘s going to be a 1.7.23 soon.
100
Steffen Deusch @steffend.me · 05/05/2026
Now also published on @theerlef.bsky.social‘s CNA website: cna.erlef.org/cves/CVE-202... Big thank you to @maennchen.dev for guiding us through the disclosure process!
cna.erlef.org
Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
041
Steffen Deusch @steffend.me · 05/05/2026
If you’re running #Phoenix Channels (or LiveView) and have the LongPoll option enabled in your endpoint (default since 1.7.11), it’s time to do an update: github.com/phoenixframe... Thank you @peterullrich.com for finding and disclosing this issue!
github.com
Long-poll NDJSON body splitting causes large memory allocation in Phoenix
### Summary An unauthenticated denial-of-service vulnerability in Phoenix's long-poll transport allows a remote client to allocate a large amount of memory with a HTTP request. A handful of conc...
22410
Steffen Deusch @steffend.me · 05/05/2026
It was! For some reason it is actually one of the first talks that are already public: youtube.com/watch?v=-FRz...
youtube.com
Update from the Phoenix Team - Steffen Deusch | ElixirConf EU 2026
YouTube video by Code Sync
010
Reposted by Steffen Deusch
Tony Dang @tonydang.com · 03/05/2026
Watching an @elixirconf.bsky.social talk by @steffend.me and saw my name as a contributor to Phoenix! That's what I love about open source. You can contribute to tools you actually use and love, and become part of something bigger than yourself :) #ElixirLang
Screenshot of an ElixirConfEU talk by Steffen Deusch showing a slide listing Phoenix contributors.
2162
Reposted by Steffen Deusch
Peter Ullrich @peterullrich.com · 01/05/2026
The 5 vulnerabilities I found in Bandit were fixed and released today. Please go upgrade bandit ASAP. Thanks to @mtrudel.bsky.social for fixing them so quickly and to @maennchen.dev for managing the process 🙏 #ElixirLang cna.erlef.org/cves/
cna.erlef.org
List of Issued CVE’s
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
1347