Sign in

Adam

@u11g.com
87 followers 45 following 1.1K posts

I build software. Frontend. Backend. Irrelevant. • weeklyfoo.com • boringdevtools.com • flethy.com • linker1.com • ethme.at • diypunks.xyz

PostsRepliesMedia
Adam @u11g.com · 3h
Low-level Postgres internals piece that instantly makes row locks more concrete. boringsql.com/posts/row-locks-on-th…
boringsql.com
Where PostgreSQL stores row locks
What SELECT FOR UPDATE, FOR SHARE, and a foreign key check actually write into the tuple header. t_xmax as a locker, the infomask bits that say so, MultiXactIds when two sessions lock the same row, and the pg_multixact files that grow behind them.
000
Adam @u11g.com · 9h
Sharp CI hardening item with a clear defense against cache poisoning. socket.dev/blog/github-actions-cach…
socket.dev
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
010
Adam @u11g.com · 30/09/2026
Browser capability jump that quietly makes real local SQL viable. duckdb.org/2026/09/18/opfs-wasm
duckdb.org
Persistent Databases in the Browser with DuckDB-Wasm and OPFS
DuckDB-Wasm can open a persistent database file in the browser's Origin Private File System (OPFS). This post shows how, and when data reaches disk.
000
Adam @u11g.com · 30/09/2026
Big security story with real supply-chain fallout, not just another warning. arstechnica.com/security/2026/09/an…
000
Adam @u11g.com · 29/09/2026
Concrete agent-era ops story: CI, not the model, became the bottleneck. linear.app/now/ci-bottleneck-rework…
linear.app
AI coding has made CI a bottleneck, so we reworked ours to keep up
We cut PR wait time and running costs by rethinking CI as a system, from the infrastructure underneath it to how work gets scheduled and tests get parallelized.
021
Adam @u11g.com · 29/09/2026
Best survey here of how real coding agents actually patch files. kondasamy.com/blog/2026/how-ai-codi…
kondasamy.com
How Coding Agents Edit Files: Diffs, Snapshots, and Fast Apply | Kondasamy Jayaraman (Samy)
Applying diffs to disk breaks more agent workflows than reasoning errors. Here is how Aider, Claude Code, Cursor, OMP, DeepSeek Harness, OpenCode, and Morph modify code.
010
Adam @u11g.com · 27/09/2026
Physical-WAL replication into ClickHouse is a sharp, instantly understandable Postgres tool. clickhouse.com/blog/introducing-wal…
clickhouse.com
Introducing WalShadow: Sub-second Postgres replication to ClickHouse from physical WAL | ClickHouse
WalShadow replicates Postgres data directly from physical WAL into ClickHouse, delivering around 200 ms latency and 289,000 rows per second in benchmarks.
010
Adam @u11g.com · 26/09/2026
Zero-config dead-code and hotspot detection is immediately useful in almost any JS or TS repo. docs.fallow.tools
docs.fallow.tools
Fallow documentation
Find the code you can delete, merge, or refactor in a TypeScript or JavaScript project. Fallow analyzes code and styles statically for free, and optional runtime intelligence shows what ran in production.
010
Adam @u11g.com · 26/09/2026
Fills a real TypeScript gap by shipping types for browser features before lib.dom catches up. philipwalton.com/articles/modern-we…
philipwalton.com
Modern Web Types
If you
010
Adam @u11g.com · 25/09/2026
Narrow, legible tool: lint the exact Tailwind and design-system issues agents tend to create. github.com/shadcn-ui/lint
github.com
GitHub - shadcn-ui/lint: An agent-first linter for Tailwind design systems. Write design system rules that agents can verify.
An agent-first linter for Tailwind design systems. Write design system rules that agents can verify. - shadcn-ui/lint
020
Adam @u11g.com · 25/09/2026
Good migration story because the interesting parts are the semantic edge cases, not just the Rust headline. github.blog/ai-and-ml/generative-ai…
110
Adam @u11g.com · 24/09/2026
Rare planner internals feature that could change how teams stabilize tricky Postgres queries. tapoueh.org/blog/2026/09/plan-advic…
tapoueh.org
Plan Advice in PostgreSQL 19
There is a conversation that happens in every PostgreSQL shop eventually. A query that has been fine for a year gets slow overnight. Nothing was deployed. The …
000
Adam @u11g.com · 24/09/2026
Broadly useful upgrade: a simple API addition with measurable validation wins. zod.dev/blog/zod-4-6
zod.dev
Zod 4.6
Zod 4.6 is now available, with .validate() for boolean validation, .properties() on z.instanceof(), and six more JSON Schema keywords.
010
Adam @u11g.com · 23/09/2026
Actionable incident write-up with patched versions and a clear attack path. www.f5.com/labs/articles/cloud-take…
000
Adam @u11g.com · 23/09/2026
Concrete answer to what breaks first when agent volume spikes: CI architecture, not model speed. claude.com/blog/agentic-coding-is-s…
claude.com
Agentic coding is straining CI. Here’s how we scaled test impact analysis at Anthropic | Claude by Anthropic
000
Adam @u11g.com · 22/09/2026
Biggest security story of the week - agent-driven supply-chain abuse with real ecosystem fallout. www.rubyhack.ai
rubyhack.ai
OpenAI agents carried out an undisclosed cyber-attack on RubyGems
On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents performing web-lookup tasks with significant overlap with the German Wiki Incident.
000
Adam @u11g.com · 22/09/2026
Long-overdue engine cleanup with concrete module-loader internals, not just a bugfix changelog. webkit.org/blog/18227/fixing-top-le…
000
Adam @u11g.com · 20/09/2026
Narrow tool, clear job: an agent that edits KiCad files and reruns the real electrical checks until they pass. copperhead.sh
copperhead.sh
copperhead. Cursor for circuit boards.
An open-source AI agent that designs, documents and validates real PCBs from a prompt.
010
Adam @u11g.com · 19/09/2026
Wildly specific and instantly understandable: Kafka clients talking straight to Postgres through a background worker. rynr.dev/blog/kafgres
rynr.dev
Kafgres: Embedding a Kafka Broker into Postgres — rynr.dev blog
000
Adam @u11g.com · 19/09/2026
Nicely legible tool idea: WebGPU shaders in, PNG or MP4 out, in browser or headless Node. vgpu.sh
vgpu.sh
vgpu
The WebGPU library, designed for agents.
010
Adam @u11g.com · 18/09/2026
Big practical win: faster runs plus a trace view that makes browser-test failures much easier to replay. vitest.dev/blog/vitest-5
vitest.dev
Announcing Vitest 5.0
Vitest 5.0 Release Announcement
000
Adam @u11g.com · 18/09/2026
Immediate-action security item, plus the blunt reminder that sandbox libraries are not hard boundaries. about.gitlab.com/blog/critical-remo…
about.gitlab.com
Critical remote code execution in vm2, a widely used Node.js sandbox library
GitLab
010
Adam @u11g.com · 17/09/2026
Counter-intuitive Postgres internals gotcha: planning work can hurt just because a table owns too many indexes. thebuild.com/blog/sixteen-locks-oug…
thebuild.com
Sixteen Locks Ought to Be Enough for Anybody
Every query locks every index on a table, even ones it doesn't use.
120
Adam @u11g.com · 17/09/2026
Great security archaeology: broken 90s roots turned back into working certificates on period-correct TLS. mcpherrin.ca/2026/09/07/rsa.html
mcpherrin.ca
I’ve factored the RSA keys of a Certificate Authority…
… from the 90s.
000
Adam @u11g.com · 16/09/2026
Excellent reality check on autonomous-agent hype: lots of spam and fake invoices, zero actual business. www.bottlenecklabs.com/blog/benchma…
bottlenecklabs.com
7 AI models ran real businesses: $12,431 fake invoices, $0 revenue
$12,431 in fake invoices, 2,797 spam emails, $0 revenue.
000
Adam @u11g.com · 16/09/2026
Rare look below Core ML into the undocumented compiler, driver and firmware layers that usually stay invisible. smolnero.com/posts/between-the-grap…
smolnero.com
Between the Graph and the Silicon: Inside the Apple Neural Engine Compiler - smolnero
As I continue my journey into the abyss of the compiler, one idea has finally started to settle in for me, a compiler is not just a translator that takes...
120
Adam @u11g.com · 15/09/2026
Useful pattern shift: route the cheap, predictable work elsewhere and save frontier tokens for the messy decisions. engineering.atspotify.com/2026/9/po…
engineering.atspotify.com
Portal by Spotify cut my Claude Code token usage by 90% | Spotify Engineering
Most of what an AI coding agent does for me isn't thinking. It's I/O.
010
Adam @u11g.com · 11/09/2026
Great companion to this week's Postgres performance pieces, with concrete latency intuition. www.youtube.com/watch?v=h7by8IKtJG0
000
Adam @u11g.com · 11/09/2026
Practical supply-chain check that maps exactly to what npm consumers actually install. drydock.org
drydock.org
Drydock Package Review: pre-publish package security
Review the exact npm, PyPI, or VS Code artifact before publication. Drydock diffs built package bytes and pins supply-chain risks to changed lines.
011
Adam @u11g.com · 10/09/2026
Clear signal that agent jobs are becoming first-class CI primitives, not side scripts. github.github.com/gh-aw
github.github.com
Home | GitHub Agentic Workflows
Write repository automation workflows in natural language using markdown files and run them as GitHub Actions. Use AI agents with strong guardrails to automate your development workflow.
050
Adam @u11g.com · 10/09/2026
Puts hard numbers on context overhead instead of hand-wavy complaints. okaneland.com/study/the-mcp-context…
okaneland.com
MCP servers: the context-token cost, measured per server · Okane Land
We measured the tool-definition token cost of ten popular MCP servers, and when that cost hits in current Claude Code. Per-server table, keep-or-cut verdicts.
030
Adam @u11g.com · 09/09/2026
Rarely explained consistency trade-off quantified end-to-end with practical SQL. boringsql.com/posts/read-your-own-w…
boringsql.com
Read your own writes, off the primary
WAIT FOR in PostgreSQL 19 lets a reader block until the replica has replayed a specific LSN. Measured against sticky routing, sleeps, and synchronous commit, on a replica that misses the write 99% of the time.
000
Adam @u11g.com · 09/09/2026
Excellent empirical reminder - convenience modes are not security controls. embracethered.com/blog/posts/2026/b…
embracethered.com
Breaking Claude Code Opus 5 Auto Mode · Embrace The Red
In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success …
010
Adam @u11g.com · 08/09/2026
Measurable runtime win from a tiny API-level change most teams can adopt quickly. zod.dev/blog/reducing-memory-footpr…
zod.dev
Reducing Zod's memory footprint by an order of magnitude with method memoization
A bare z.string() retained 7.5kb of heap in Zod 4.4. In Zod 4.5 it retains 784 bytes. One change to where a schema's methods live accounts for nearly all of it.
010
Adam @u11g.com · 08/09/2026
Major ecosystem tool rewrite done without forcing teams to relearn workflows. pnpm.io/blog/releases/12.0
000
Adam @u11g.com · 07/09/2026
Real-world privilege escalation from a default setup, with a concrete fixed version to act on. 0xcc.io/posts/omarchy-root-creds
0xcc.io
Omarchy: Any User Process Can Escalate to Root
021
Adam @u11g.com · 07/09/2026
Replaces fuzzy memory with formal reasoning and shows exactly why that matters for security work. pwning.systems/posts/llm-memory-pro…
pwning.systems
I accidentally turned LLM memory into program analysis :: pwning.systems
Why I stopped trying to give LLM agents a better memory and instead built Lemmalog, a Datalog engine that maintains an agent's knowledge as analysis state, with provenance, retractions and incremental evaluation, plus what happened when I benchmarked it on LongMemEval and LoCoMo.
000
Adam @u11g.com · 04/09/2026
Practical bridge between agent automation and real authenticated browser workflows. github.com/Tencent/BrowserSkill
github.com
GitHub - Tencent/BrowserSkill: Let AI agents use your real, logged-in browser without interrupting your work. CLI + extension for browser automation across any shell-capable AI agent.
Let AI agents use your real, logged-in browser without interrupting your work. CLI + extension for browser automation across any shell-capable AI agent. - Tencent/BrowserSkill
010
Adam @u11g.com · 04/09/2026
Focused auth release with concrete standards support teams can adopt immediately. better-auth.com/blog/1-7
better-auth.com
Better Auth 1.7
A major OAuth and OpenID Connect expansion, updated MCP authorization, SCIM Groups and role projections, unified identity, device authorization, and more.
000
Adam @u11g.com · 03/09/2026
Clean capability boundary for executing untrusted code with minimal host exposure. vercel.com/blog/introducing-run
vercel.com
Introducing Run SDK: secure eval for your agents
Execute untrusted JavaScript and TypeScript without giving it access to your application, and pause mid-run for human approval.
010
Adam @u11g.com · 03/09/2026
Narrow, practical harness tooling for orchestrating multi-agent coding workflows. github.com/context-labs/whip
github.com
GitHub - context-labs/whip: A fast coding-agent harness in Go. Tool-use loop, bubbletea TUI, provider-routable models with live catalog discovery, MCP support, background subagents. One binary, no runtime, built for open-source models.
A fast coding-agent harness in Go. Tool-use loop, bubbletea TUI, provider-routable models with live catalog discovery, MCP support, background subagents. One binary, no runtime, built for open-sour...
120
Adam @u11g.com · 02/09/2026
Critical unauthenticated RCE patch with immediate upgrade guidance—high-impact and actionable. nextjs.org/blog/august-2026-securit…
nextjs.org
August 2026 Security Release
The August 2026 security release for Next.js is now available
010
Adam @u11g.com · 02/09/2026
Unusual systems idea with real implementation detail: binaries as queryable SQLite artifacts. fzakaria.com/2026/08/23/your-execut…
fzakaria.com
Your executable is a SQLite database
I have been probably obsessed with two things in the last few years: Nix as a tool to explore innovative ideas that require the capability to rebuild the world and replacing ELF with SQLite as an executable format. You might have noticed that these two ideas are well suited to each other.
020
Adam @u11g.com · 01/09/2026
Great bridge between classic transaction theory and multi-agent system design. www.trychroma.com/engineering/trans…
trychroma.com
Agent Swarms are a Distributed Systems Problem
Fission trades atomicity to conserve reasoning.
010
Adam @u11g.com · 01/09/2026
Concrete large-scale optimization writeup with measurable wins and implementation detail. blog.cloudflare.com/dns-cache-memor…
blog.cloudflare.com
How we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache
010
Adam @u11g.com · 31/08/2026
Core protocol direction for agent tooling, straight from the spec maintainers. blog.modelcontextprotocol.io/posts/…
blog.modelcontextprotocol.io
The New MCP Roadmap
An update on the Model Context Protocol roadmap and focus areas for upcoming specification releases.
130
Adam @u11g.com · 31/08/2026
Strong framing shift: optimization work moved from expensive heroics to routine engineering. danluu.com/perf-opt
danluu.com
There's no reason for software to be slow anymore
010
Adam @u11g.com · 30/08/2026
Surfaces which shells, tests and agents are waiting on your input — addresses a real multi-pane workflow pain. saggar.marginalutility.dev
saggar.marginalutility.dev
Saggar: know which terminal needs you
A native Mac terminal that keeps projects, sessions, and attention organized. Saggar tracks what is working, waiting, finished, and failed, then brings the sessions that need you to the front.
000
Adam @u11g.com · 30/08/2026
AI-found exploits now arrive faster than the vulnerability market can absorb; the arms race just changed pace. margin.re/2026/08/introducing-the-h…
margin.re
Introducing the Half-Day: 0-Day in the Age of AI
010
Adam @u11g.com · 29/08/2026
Deep dive into building a WAL on object storage — 60-year-old System R ideas suddenly relevant at agent scale. www.trychroma.com/engineering/wal3
trychroma.com
wal3: A Write-Ahead Log for Chroma, Build on Object Storage
wal3, Chroma's write-ahead log, combining a 30-year-old lock-free algorithm with S3's newest conditional writes feature.
010