POSTS (125)
2026
- The Agent Harness: What to Build Around the Model and What to Rip Out
- Giving AI Agents a Shared Vocabulary with OWL and SHACL
- What's Actually Inside an AI Agent
- Hermes Agent: How a Self-Improving AI Agent Remembers What It Learns
- Hermes Agent v0.2.0 Is Out. Here's What I'd Actually Use It For
- A Python Machine Learning Setup You Can Safely Hand to an AI Agent
2025
- Machine Learning for Lead Scoring: A Technical Deep Dive
- Build a Regression Test for Your AI Support Bot
- Run an AI Text Classifier in the Browser
- Why Your AI Prompt Cache Keeps Missing
- MCP or Just Your API? What the Protocol Actually Adds
- Does Fine Tuning Help a Small Model Route Support Tickets?
- Your RAG Search Keeps Missing the Part Number
- Data Imputation Best Practices
2024
2023
2022
- Securing Passwords for Storage with Hashing
- Responsive Images with AWS Serverless Image Handler (S3) for VueJS/React
- Securely using dangerouslySetInnerHTML in a React application
- Software Security Testing: Static Code Analysis for React
- Okay Google, fetch a pizza - Google Home Action with NightwatchJS and AWS Lambda
- AWS EventBridge as a Crontab for Lambda
- Understanding and using Web Components
2021
- Python 3.10 Gets match and case: A Working Guide to Structural Pattern Matching
- DST Root CA X3 Expires September 30, and Old OpenSSL Is the Real Risk
- GitHub Stops Taking Your Password for Git This Friday
- GitHub Copilot's Technical Preview: Read the FAQ Before You Hit Tab
- The Codecov Bash Uploader Breach and the Problem With Curl to Bash in CI
- Docker Desktop on Apple Silicon Is GA, So Now Your Images Have an Architecture
- Setting up Drupal as a GraphQL Backend for Gridsome or Gatsby
- Patching On-Prem Exchange After ProxyLogon Is Only the First Step
2020
2019
- Python 2 Sunsets on January 1: What It Means and How to Get Off It
- PHP 7.4 Arrow Functions and Typed Properties
- GitHub Actions Hits GA: Free CI for Side Projects
- IMDSv2 and SSRF: Putting a Session in Front of EC2 Metadata
- Chrome 80 Plans to Make Cookies SameSite=Lax by Default: What Breaks and How to Prepare
- DNS over HTTPS Is Coming to Firefox and Chrome
- After Capital One: SSRF and the Metadata Endpoint
- BlueKeep (CVE-2019-0708): Patch RDP Before Somebody Writes the Worm
- Why PHP Can't Talk to Your New MySQL 8
- The Docker Hub Breach Is a Good Reason to Audit Your Build Credentials
- WebAuthn Is a W3C Standard. Passwords Get a Real Rival
- Chicago CTA Bus Tracking Dashboard in React/Gatsby
- runc CVE-2019-5736: Containers Are Not a Security Boundary
- React 16.8 Is Out, and Hooks Are Finally Stable
2018
- CVE-2018-1002105: The Kubernetes API Server Flaw and What to Check on Your Cluster
- event-stream and flatmap-stream: What a New Maintainer Can Ship
- Safeguarding Digital Assets: The Importance of Data Loss Prevention
- TLS 1.3 Is Now RFC 8446: What It Cuts, What It Speeds Up, and When Your Server Gets It
- npm audit in npm 6: Read the Report Before You Reach for audit fix
- GDPR for Web Developers: What the Regulation Means in Code
- VPNFilter: Why the FBI Wants You to Reboot Your Router
- Let's Encrypt Wildcards Are Here, and They Run Through Your DNS
- The CIA Triad is a foundation of Cybersecurity
- Meltdown and Spectre: What Patching Looks Like One Week In
2017
- Chrome 62 Says Not Secure When You Type: Moving Your Site to HTTPS
- KRACK and WPA2: What It Means for Your Home Wi-Fi and Smart Devices
- Equifax and Apache Struts: Know Your Dependencies and Patch Fast
- WannaCry Is Your Reason to Patch MS17-010 and Turn Off SMBv1
- Secure HTTP Headers - Hardening Security with Headers
- CSS Grid Ships in Firefox 52 and Chrome 57: The Basics and a Safe Fallback
- After the S3 Outage: Designing for a Region That Goes Away
- The First SHA-1 Collision: What It Means for Certificates and Git
2016
- After the Dyn Attack: Keeping Your Cameras, DVRs and Routers Out of a Botnet
- Dirty COW: Patch the Kernel, Then Make Sure You're Running It
- Yarn and yarn.lock: JavaScript Installs You Can Repeat
- Useful Git Commands and Configuration
- AWS's New Application Load Balancer and How Path-Based Routing Works
- Create React App: Starting React Projects With No Build Configuration
- HTTPoxy: Strip the Proxy Header Before It Becomes HTTP_PROXY
- ImageTragick: Treat Every Uploaded Image as Untrusted Input
- Bash on Ubuntu on Windows: What Shell People Should Know
- After left-pad: Keeping Your Builds Alive When an npm Package Disappears
2015
- Let's Encrypt Is in Public Beta: Free Certificates for Anyone Who Automates
- Python 3.5 Gets async and await: How Native Coroutines Work
- Node.js 4.0: io.js Comes Home, and How to Upgrade From 0.10 or 0.12
- Kubernetes 1.0 for People Who Just Learned Docker
- API Gateway Meets Lambda: Following One Request Through
- ES2015 Is Official: The Parts Worth Using Every Day
- WebAssembly Was Just Announced: What It Is and What It Isn't
- Logjam: Kill Export Diffie-Hellman and Bring Your Own Group
- HTTP/2 Is Now RFC 7540: What It Changes for Front End Performance
- FREAK and the Export Ciphers Still Hiding in Your Server Config
2014
2013
- Adobe's Breach: Encrypted Passwords Are Not Hashed Passwords
- GitHub Two-Factor Authentication: Turn It On, Then Clean Up Your SSH Keys
- Forward Secrecy for Everyday HTTPS: Put ECDHE and DHE First
- OWASP Top 10 2013: What Changed and One Habit for Each Risk
- React Is Open Source: A First Look at Facebook's UI Library
- jQuery 2.0 Drops Old IE: How to Pick 1.x or 2.x
- Blink Forks WebKit: What Changes for Web Developers
- Lucky Thirteen or RC4? Picking a TLS Cipher Order
- Node 0.10 Streams2: Processing Huge Files Without Running Out of Memory
2012
2011
2010
- After Gawker, Please Hash Passwords with bcrypt
- Firesheep Is Out. Lock Down Your PHP Sessions
- Stop Gluing SQL Strings Together with PDO Prepared Statements
- PHP-FPM Just Shipped in PHP 5.3.3
- Pretty URLs with mod_rewrite, Minus the Headache
- A LAMP Server on Ubuntu 10.04 in One Coffee
- APC Is the Easiest PHP Speedup You're Not Using
- Oracle Owns MySQL Now